[Hiring] Lead Security Testing Engineer @EPAM
Lead Security Testing Engineer @EPAM
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 5d ago

[Hiring] Lead Security Testing Engineer @EPAM

5d ago - EPAM is hiring a remote Lead Security Testing Engineer. πŸ’Έ Salary: unspecified πŸ“Location: Poland

Role Description

We are looking for a Lead Security Testing Engineer to drive security assessments, penetration testing, and vulnerability management efforts across SaaS services and on-prem solutions focused on DNS/DHCP protocols. The ideal candidate will bring deep technical expertise in application security, threat modeling, and secure development practices, while guiding teams toward building more resilient and secure systems.

  • Perform security assessments, application security reviews, and penetration testing for SaaS services and on-prem solutions centered on DNS/DHCP protocol.
  • Review vulnerability findings from SAST, DAST, SCA, container, secrets, and infrastructure security scanning tools, and define appropriate validation approaches.
  • Validate security remediations across applications, platforms, cloud services, infrastructure components, and development toolchains to ensure vulnerabilities are effectively addressed and root causes eliminated.
  • Plan, execute, and analyze application security testing, including penetration testing, vulnerability scanning, and code reviews.
  • Interpret penetration test results and recommend remediation measures based on identified threats.
  • Collaborate with development teams to enforce secure coding practices, guidelines, and standards.
  • Integrate security requirements and threat modeling considerations into the software development lifecycle.
  • Provide guidance on secure design principles and support security-related discussions and decision-making processes.
  • Work closely with development teams to design and implement effective security controls, such as access controls, authentication mechanisms, encryption, and secure communication protocols.
  • Utilize threat modeling outputs to guide security control selection and implementation.
  • Educate development teams on secure coding practices, common vulnerabilities, and security best practices through training sessions and workshops.
  • Analyze security test results, document findings, and provide clear evidence supporting vulnerability closure, risk acceptance, or remediation gaps.

Qualifications

  • 5+ years of experience in vulnerability management and penetration testing.
  • Knowledge of application security principles, threat modeling methodologies, and best practices.
  • Proficiency in secure coding practices, vulnerability assessment, and penetration testing methodologies.
  • Background in Shell Scripts, Python, or Golang development.
  • Familiarity with cloud environments such as AWS, GCP, Azure, and technologies like Kubernetes and Containers.
  • Familiarity with common web application vulnerabilities (e.g., OWASP Web/API Top 10) and corresponding mitigation techniques.
  • Experience implementing and managing security testing tools, such as static analysis tools, dynamic application scanners, and penetration testing frameworks.
  • Understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into agile development processes with SAST and DAST tools (Coverity, CodeQL, SonarQube, Contrast).
  • Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols.
  • Familiarity with industry standards and frameworks such as ISO 27001, NIST, PCI DSS, and GDPR.
  • Excellent communication and collaboration skills, with the ability to effectively communicate technical concepts to non-technical stakeholders.
  • MS/M.Tech or BS/B.Tech in Computer Science or related field, or equivalent work experience required.
  • English proficiency at B2 level or higher.

Requirements

  • Nice to have CISSP, CSSLP, CEH, OSCP, OSWE certifications.
  • Understanding of cyber security frameworks like OWASP, SANS, NIST, CIS.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Poland
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Lead Security Testing Engineer @EPAM
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 5d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Poland
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later