Senior Application Security Testing Engineer
Tech Stack / Keywords
Firma i stanowisko
EPAM is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, they empower clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
Wymagania
- Bachelor's Degree, preferably in a technical discipline such as Information Systems, Computer Science, or a related field
- A minimum of 3 years' demonstrated experience in manual security testing
- Understanding of security protocols, cryptography, authentication, and authorization, along with general application security requirements
- Knowledge of at least one object-oriented programming language, such as Node.js or TypeScript
- Experience implementing and operating security technologies and processes within a hybrid cloud environment, particularly AWS
- Expertise in OWASP concepts and their practical application across varied solutions
- Understanding of IT operations and service support processes
- Excellent communication skills, with the ability to translate technical security concepts for non-technical stakeholders
Nice to have:
- Relevant security certifications, such as CISSP, GIAC, CEH, Security+, or CSSLP
- Prior experience working within a fast-paced, product-led, or e-commerce technology environment
- Familiarity with automated security scanning and CI/CD pipeline integration
Obowiązki
- Conduct regular scanning and manual security testing of web applications to identify vulnerabilities
- Track identified issues through to remediation, working closely with development teams to ensure timely fixes
- Perform code-level reviews to identify insecure coding practices and recommend improvements
- Support and strengthen IaaS security across cloud environments, with a particular focus on AWS
- Assess cloud configurations against security best practice and industry benchmarks
- Work within a hybrid cloud environment to implement and operate appropriate security technologies and controls
- Research emerging security threats, vulnerabilities, and exploit techniques relevant to the technology stack
- Respond promptly to newly identified threats and support the implementation of new security requirements
- Contribute to incident response activities as required, maintaining the confidentiality of all investigation information
- Provide technical guidance and oversight to developers on secure coding practices and application security standards
- Champion OWASP principles across the organization, embedding them into the design and development of new solutions
- Collaborate closely with cross-functional teams, contributing a security-first mindset to product and engineering discussions
Benefity
- Hybrid work mode with opportunity to work remotely within Poland
- Chance to work abroad for up to 60 days annually
- Business-driven relocation opportunities
- Career development programs
- Thought leadership, mentoring, soft skills and well-being programs
- Certification opportunities (Anthropic, Gemini, GCP, Azure, AWS)
- English classes
- Stable pay
- Participation in the Employee Stock Purchase Plan with a 15% discount
- Benefits package (health insurance, multisport, shopping vouchers)
- Referral bonuses up to $2,000
- Offices with entertainment and relaxation zones, table tennis and football, free snacks, coffee and more
- Corporate, social and well-being events
Inne informacje
Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności dostępną na stronie: https://www.epam.com/applicant-privacy-notice
EPAM Systems
938 aktywnych ofert