Lead Security Testing Engineer
EPAM Systems · Remote, Poland
You apply off-site, with the employer or the job board. I never handle applications.
We are looking for a Lead Security Testing Engineer to drive security assessments, penetration testing, and vulnerability management efforts across SaaS services and on-prem solutions focused on DNS/DHCP protocols. The ideal candidate will bring deep technical expertise in application security, threat modeling, and secure development practices, while guiding teams toward building more resilient and secure systems.
Responsibilities
- Perform security assessments, application security reviews, and penetration testing for SaaS services and on-prem solutions centered on DNS/DHCP protocol
- Review vulnerability findings from SAST, DAST, SCA, container, secrets, and infrastructure security scanning tools, and define appropriate validation approaches
- Validate security remediations across applications, platforms, cloud services, infrastructure components, and development toolchains to ensure vulnerabilities are effectively addressed and root causes eliminated
- Plan, execute, and analyze application security testing, including penetration testing, vulnerability scanning, and code reviews
- Interpret penetration test results and recommend remediation measures based on identified threats
- Collaborate with development teams to enforce secure coding practices, guidelines, and standards
- Integrate security requirements and threat modeling considerations into the software development lifecycle
- Provide guidance on secure design principles and support security-related discussions and decision-making processes
- Work closely with development teams to design and implement effective security controls, such as access controls, authentication mechanisms, encryption, and secure communication protocols
- Utilize threat modeling outputs to guide security control selection and implementation
- Educate development teams on secure coding practices, common vulnerabilities, and security best practices through training sessions and workshops
- Analyze security test results, document findings, and provide clear evidence supporting vulnerability closure, risk acceptance, or remediation gaps
Requirements
- 5+ years of experience in vulnerability management and penetration testing
- Knowledge of application security principles, threat modeling methodologies, and best practices
- Proficiency in secure coding practices, vulnerability assessment, and penetration testing methodologies
- Background in Shell Scripts, Python, or Golang development
- Familiarity with cloud environments such as AWS, GCP, Azure, and technologies like Kubernetes and Containers
- Familiarity with common web application vulnerabilities (e.g., OWASP Web/API Top 10) and corresponding mitigation techniques
- Experience implementing and managing security testing tools, such as static analysis tools, dynamic application scanners, and penetration testing frameworks
- Understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into agile development processes with SAST and DAST tools (Coverity, CodeQL, SonarQube, Contrast)
- Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols
- Familiarity with industry standards and frameworks such as ISO 27001, NIST, PCI DSS, and GDPR
- Excellent communication and collaboration skills, with the ability to effectively communicate technical concepts to non-technical stakeholders
- MS/M.Tech or BS/B.Tech in Computer Science or related field, or equivalent work experience required
- English proficiency at B2 level or higher
Nice to have
- CISSP, CSSLP, CEH, OSCP, OSWE certifications
- Understanding of cyber security frameworks like OWASP, SANS, NIST, CIS
We offer
- We gather like-minded people:
-
- Top tech minds driving innovation in AI, cloud and digital platform modernization
- Supportive team and agile, startup-like culture
- Hybrid by design mode and opportunity to work remotely within Poland
- Chance to work abroad for up to 60 days annually
- Business-driven relocation opportunities
- Top tech minds driving innovation in AI, cloud and digital platform modernization
- We provide growth opportunities:
-
- Career development programs
- Thought leadership, mentoring, soft skills and well-being programs
- Certification (Anthropic, Gemini, GCP, Azure, AWS)
- English classes
- Career development programs
- We cover it all:
-
- Stable pay
- Participation in the Employee Stock Purchase Plan with a 15% discount
- Benefits package (health insurance, multisport, shopping vouchers)
- Referral bonuses up to $2,000
- Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and more
- Corporate, social and well-being events
- Stable pay
- Please, note:
-
- Benefits listed above are available to employees only
- We are open for working with Contractors. Terms of B2B cooperation agreements are agreed individually
- We will reach out to selected candidates exclusively
- Benefits listed above are available to employees only
EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
Keep looking
100+ English-friendly jobs in Remote
Every one checked for language requirements, updated daily.