Lead AI Security Engineer
Brak informacji o wynagrodzeniu
SeniorFull-time
#441157·Dodano 3 dni temu·0
Źródło: justjoin.itTech Stack / Keywords
Application Securitythreat modelingsecure codingAI securitySASTDASTCI/CDPrompt Engineering
Firma i stanowisko
EPAM is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, they empower clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
Wymagania
- Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience
- Hands-on application security experience across the software development lifecycle
- Strong understanding of common application vulnerability classes and mitigations including the OWASP Top 10 and secure coding principles
- Practical experience with application security tooling such as SAST, DAST, SCA, and secrets scanning integrated into CI/CD
- Working knowledge of at least one programming language (e.g., Python, Java, C#, JavaScript/TypeScript, or Go) sufficient to read code and assess vulnerabilities
- Experience with threat modeling and secure design review methodologies
- Understanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design principles
- Familiarity with cloud application security concepts across at least one major cloud platform such as Azure, AWS, or GCP
- Experience participating in production projects or engineering teams
- Ability to collaborate with developers, architects, QA engineers, DevOps, product, and security teams
- Ability to follow, maintain, and improve defined security processes
- Practical understanding of AI-assisted productivity and automation, including building or configuring AI agents, integrating LLMs with tools, prompt engineering, secure AI tool usage, and AI-driven documentation
- Good communication skills to explain security risks, technical decisions, and remediation plans to technical and non-technical stakeholders
Nice to have:
- Experience with application security platforms like Snyk, Checkmarx, Veracode, SonarQube, Semgrep, GitHub Advanced Security, Burp Suite, OWASP ZAP
- Experience with software supply chain security including SBOM, SLSA, Sigstore, dependency and artifact integrity controls
- Experience with Infrastructure as Code and policy-as-code security tools such as Terraform, Bicep, ARM templates, OPA, Checkov, or Trivy
- Experience with container and Kubernetes security including image scanning, registries, runtime protection, and network policies
- Experience with API security, secrets management (e.g., HashiCorp Vault, Azure Key Vault), and microservice security patterns
- Understanding of compliance or security frameworks such as ISO 27001, NIST, CIS Benchmarks, PCI DSS, HIPAA, SOC 2, or SOX
- Experience integrating security findings with SIEM/SOAR, ticketing, and vulnerability management workflows
- Experience with AI/LLM platforms or frameworks such as Azure OpenAI, Azure AI Foundry, Amazon Bedrock, Microsoft Copilot Studio, LangChain, or AutoGen
- Understanding of AI and LLM application security risks including prompt injection, insecure output handling, data leakage, model governance, and AI supply chain risks
- Security certifications including CSSLP, GIAC certifications, OSCP, OSWE, CISSP, CISM, CCSP, and AI-related certifications like AI-900 and AI-102
Obowiązki
- Embed security into the full software development lifecycle and drive shift-left and secure-by-design practices across engineering teams
- Perform and facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs
- Conduct secure code reviews (manual and AI-assisted) and advise developers on secure coding patterns and remediation
- Implement, configure, tune, and operate application security tooling, including SAST, DAST, IAST, SCA, secrets scanning, and IaC scanning, integrated into CI/CD pipelines
- Triage, validate, prioritize, and reduce false positives in security findings, and partner with development teams to track issues through remediation
- Define, implement, and maintain security gates and policies in CI/CD pipelines
- Secure the software supply chain, including dependency and open-source risk management, SBOM generation, artifact integrity and signing, and build pipeline hardening
- Support application penetration testing and validate vulnerability fixes
- Drive secrets management, secure configuration, API security, container and image security, and microservice security practices
- Establish and run a security champions program, and develop and deliver secure-coding training, guidelines, and reusable security patterns
- Define and maintain application security standards, baselines, and policy-as-code
- Build, deploy, and maintain AI-assisted automations and agentic workflows to reduce manual effort across daily application security activities
- Build and integrate AI agents and LLM-backed automations into the SDLC and CI/CD pipelines using function calling, REST, and webhooks
- Develop, test, and maintain reusable prompts, structured-prompting patterns, and prompt templates for recurring AppSec tasks
- Implement retrieval over codebases, security standards, and remediation guidance so AI assistants answer from current internal context
- Build evaluation, validation, and human-in-the-loop checkpoints into AI-assisted AppSec workflows
- Implement security and privacy controls for AppSec AI usage, including least-privilege access, prompt-injection resistance, and auditability
- Design, implement, and operate security controls for AI- and LLM-powered application features aligned with the OWASP Top 10 for LLM Applications
- Define and enforce guardrails for secure AI adoption in product engineering, advising teams on building AI features securely
Benefity
- Top tech minds driving innovation in AI, cloud, and digital platform modernization
- Supportive team and agile, startup-like culture
- Hybrid by design mode and opportunity to work remotely within Poland
- Chance to work abroad for up to 60 days annually
- Business-driven relocation opportunities
- Career development programs
- Thought leadership, mentoring, soft skills, and well-being programs
- Certification opportunities (Anthropic, Gemini, GCP, Azure, AWS)
- English classes
- Stable pay
- Participation in the Employee Stock Purchase Plan with a 15% discount
- Benefits package including health insurance, multisport, shopping vouchers
- Referral bonuses up to $2,000
- Offices with entertainment and relaxation zones, table tennis, football, free snacks, coffee
- Corporate, social, and well-being events
Elastyczne godziny
Płatny urlop
Spotkania integracyjne
Kursy językowe
Opieka zdrowotna
Karta sportowa
Premie
Udziały pracownicze
Darmowe przekąski
Inne informacje
Benefits listed are available to employees only. Open to working with Contractors; B2B cooperation terms agreed individually. Selected candidates will be contacted exclusively. By applying, candidates agree to data processing by EPAM Systems (Poland) for recruitment purposes under the Privacy Policy.
EPAM Systems
931 aktywnych ofert