Senior Application Security Testing Engineer

Brak informacji o wynagrodzeniu
SeniorFull-time
#447470·Dodano 3 dni temu·0
Źródło: EPAM Systems
Aplikuj teraz

Tech Stack / Keywords

Security TestingAmazon Web ServicesAuthentication ServicesCryptographyNode.jsTypeScriptIaaSOWASP Application Security Verification Standard

Wymagania

  • Bachelor's Degree, preferably in Information Systems, Computer Science, or a related technical discipline
  • Minimum of 3 years' experience in manual security testing
  • Understanding of security protocols, cryptography, authentication, authorization, and general application security requirements
  • Knowledge of at least one object-oriented programming language, such as Node.js or TypeScript
  • Experience implementing and operating security technologies and processes within a hybrid cloud environment, particularly AWS
  • Expertise in OWASP concepts and practical application
  • Understanding of IT operations and service support processes
  • Excellent communication skills with ability to translate technical security concepts for non-technical stakeholders
  • English proficiency at B2 level or higher

Nice to have:

  • Relevant security certifications such as CISSP, GIAC, CEH, Security+, or CSSLP
  • Prior experience in fast-paced, product-led, or e-commerce technology environments
  • Familiarity with automated security scanning and CI/CD pipeline integration

Obowiązki

  • Conduct regular scanning and manual security testing of web applications to identify vulnerabilities
  • Track identified issues through to remediation, working closely with development teams to ensure timely fixes
  • Perform code-level reviews to identify insecure coding practices and recommend improvements
  • Support and strengthen IaaS security across cloud environments, with a particular focus on AWS
  • Assess cloud configurations against security best practice and industry benchmarks
  • Work within a hybrid cloud environment to implement and operate appropriate security technologies and controls
  • Research emerging security threats, vulnerabilities, and exploit techniques relevant to the technology stack
  • Respond promptly to newly identified threats and support the implementation of new security requirements
  • Contribute to incident response activities as required, maintaining the confidentiality of all investigation information
  • Provide technical guidance and oversight to developers on secure coding practices and application security standards
  • Champion OWASP principles across the organization, embedding them into the design and development of new solutions
  • Collaborate closely with cross-functional teams, contributing a security-first mindset to product and engineering discussions

Benefity

  • Opportunity to work remotely within Poland with hybrid mode design
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs including certification in Anthropic, Gemini, GCP, Azure, AWS
  • English classes
  • Stable pay
  • Participation in Employee Stock Purchase Plan with 15% discount
  • Benefits package including health insurance, multisport, shopping vouchers
  • Referral bonuses up to $2,000
  • Offices with entertainment and relaxation zones, free snacks, coffee
  • Corporate, social, and well-being events
Elastyczne godziny
Opieka zdrowotna
Karta sportowa
Płatny urlop
Udziały pracownicze
Premie
Darmowe przekąski
Napoje w biurze
Spotkania integracyjne
Kursy językowe
Budżet konferencyjny
Szkolenia wewnętrzne

Inne informacje

EPAM is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and startups. This position is open for candidates located in Poland. Benefits listed are available to employees only. Contractors are considered with B2B agreements negotiated individually. Only selected candidates will be contacted.

EPAM Systems

EPAM Systems

1205 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz