Lead AI Security Engineer

Brak informacji o wynagrodzeniu
SeniorFull-time
#447538·Dodano 6 dni temu·1
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

Application Securitythreat modelingSecure Code ReviewSASTDASTCI/CDDevSecOps

Firma i stanowisko

EPAM Systems is a global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and startups. With over thirty years of expertise in custom software, product and platform engineering, EPAM empowers clients to become AI-Native enterprises.

Wymagania

  • Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience
  • Hands-on application security experience across the software development lifecycle
  • Strong understanding of common application vulnerability classes and mitigations including OWASP Top 10, and secure coding principles
  • Practical experience with application security tooling such as SAST, DAST, SCA, secrets scanning, integrated into CI/CD
  • Working knowledge of at least one programming language (e.g., Python, Java, C#, JavaScript, TypeScript, Go) to read code and assess vulnerabilities
  • Experience with threat modeling and secure design review methodologies
  • Understanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design principles
  • Familiarity with cloud application security concepts across at least one major cloud platform (Azure, AWS, GCP)
  • Experience participating in multiple production projects or engineering teams
  • Ability to collaborate with developers, architects, QA, DevOps, product, and security teams without owning codebase
  • Ability to follow, maintain, and improve defined security processes
  • Practical understanding of AI-assisted productivity and automation beyond basic chatbots, including AI agents, LLM integration, prompt engineering, runbook automation, and secure AI tool usage
  • Good communication skills to explain security risks, technical decisions, and remediation plans to technical and non-technical stakeholders

Nice to have:

  • Experience with application security tools like Snyk, Checkmarx, Veracode, SonarQube, Semgrep, GitHub Advanced Security, Burp Suite, OWASP ZAP
  • Experience with software supply chain security including SBOM, SLSA, Sigstore, dependency and artifact integrity controls
  • Experience with Infrastructure as Code and policy-as-code tools such as Terraform, Bicep, ARM templates, OPA, Checkov, Trivy
  • Experience with container and Kubernetes security including image scanning, registries, runtime protection, network policies
  • Experience with API security, secrets management (e.g., HashiCorp Vault, Azure Key Vault), and microservice security patterns
  • Understanding of compliance or security frameworks like ISO 27001, NIST, CIS Benchmarks, PCI DSS, HIPAA, SOC 2, SOX
  • Experience integrating security findings with SIEM/SOAR, ticketing, vulnerability management workflows
  • Experience with AI/LLM platforms/frameworks like Azure OpenAI, Azure AI Foundry, Amazon Bedrock, Microsoft Copilot Studio, LangChain, AutoGen
  • Understanding AI and LLM application security risks including prompt injection, insecure output handling, data leakage, model governance, AI supply chain risks, OWASP Top 10 for LLM Applications
  • Security certifications such as CSSLP, GWAPT / GWEB, OSCP / OSWE, CISSP, CISM, CCSP, AI-related certifications like AI-900, AI-102

Obowiązki

  • Embed security into the full software development lifecycle and drive shift-left and secure-by-design practices across engineering teams
  • Perform and facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs
  • Conduct secure code reviews (manual and AI-assisted) and advise developers on secure coding patterns and remediation
  • Implement, configure, tune, and operate application security tooling, including SAST, DAST, IAST, SCA, secrets scanning, and IaC scanning, integrated into CI/CD pipelines
  • Triage, validate, prioritize, and reduce false positives in security findings, partnering with development teams to track issues through remediation
  • Define, implement, and maintain security gates and policies in CI/CD pipelines
  • Secure the software supply chain, including SBOM generation, artifact integrity, signing, and build pipeline hardening
  • Support and coordinate application penetration testing and validate vulnerability fixes
  • Drive secrets management, secure configuration, API security, container and image security, and microservice security practices
  • Establish and run a security champions program, develop and deliver secure-coding training, guidelines, and reusable security patterns
  • Define and maintain application security standards, baselines, and policy-as-code, and contribute to vulnerability management and risk-acceptance processes
  • Build, deploy, and maintain AI-assisted automations and agentic workflows for vulnerability triage, deduplication, prioritization, code reviews, threat modeling, and compliance
  • Integrate AI agents and LLM-backed automations into SDLC and CI/CD via function calling, REST, and webhooks
  • Develop, test, and maintain prompts, structured-prompting patterns, and templates for recurring AppSec tasks
  • Implement retrieval over codebases, security standards, and remediation guidance for accurate AI assistant responses
  • Build evaluation, validation, and human-in-the-loop checkpoints into AI-assisted workflows
  • Implement security and privacy controls for AppSec AI usage, including least-privilege access and prompt-injection resistance
  • Design, implement, and operate security controls for AI- and LLM-powered application features aligned with OWASP Top 10 for LLM Applications
  • Define and enforce guardrails for secure AI adoption in product engineering, advising teams on secure AI feature builds

Benefity

  • Work with top tech minds in AI, cloud, and digital platform modernization
  • Supportive, agile, startup-like culture with hybrid and remote work options within Poland
  • Opportunity to work abroad up to 60 days annually
  • Business-driven relocation opportunities
  • Career development programs including mentoring, soft skills, and well-being
  • Certification opportunities (Anthropic, Gemini, GCP, Azure, AWS)
  • English classes
  • Stable pay
  • Participation in Employee Stock Purchase Plan with 15% discount
  • Benefits package including health insurance, multisport, shopping vouchers
  • Referral bonuses up to $2,000
  • Offices with entertainment zones, table tennis, football, free snacks, coffee
  • Corporate, social, and well-being events
Elastyczne godziny
Pakiet relokacyjny
Szkolenia wewnętrzne
Budżet konferencyjny
Dofinansowanie szkoleń
Kursy językowe
Karta sportowa
Opieka zdrowotna
Ubezpieczenie
Darmowe przekąski
Napoje w biurze
Premie
Udziały pracownicze
Płatny urlop
Spotkania integracyjne

Inne informacje

Klikając w przycisk „Aplikuj” lub w inny sposób wysyłając zgłoszenie rekrutacyjne, zgadzasz się na przetwarzanie Twoich danych osobowych przez EPAM Systems (Poland) sp. z o.o. z siedzibą w: Fabryczna 1A, 31-553 Kraków (Pracodawca), jako administratora danych osobowych w celu przeprowadzenia rekrutacji na stanowisko wskazane w ogłoszeniu zgodnie Polityką Prywatności.

EPAM Systems

EPAM Systems

1229 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz