We are looking for a Lead Application Security Engineer to lead application vulnerability remediation across teams, starting with HackerOne findings and API and GraphQL issues. You will own the end-to-end workflow from intake and validation to remediation tracking and closure across Cybersecurity, Engineering, Product, and vendors.ResponsibilitiesOwn the daily operational execution of the HackerOne programRun vulnerability intake, triage, validation, assignment, tracking, and closure end to endLead weekly operating reviews with HackerOne and internal stakeholdersTrack remediation commitments and reinforce accountability for deliveryManage coordinated disclosure and related communicationsReproduce and validate reported vulnerabilities, evaluating exploitability and business impactUse Postman, browser tooling, and security testing tools to verify findingsSupport vulnerability prioritization based on customer and business riskCoordinate remediation work across multiple engineering organizationsIdentify service ownership and route findings correctly while maintaining Jira and ServiceNow trackingEscalate critical items and drive resolution for overdue workDeliver executive-ready reporting and dashboards on backlog trends, SLA compliance, remediation progress, and risk reductionPresent status and outcomes to cybersecurity and engineering leadershipLeverage GenAI and workflow automation to enhance triage, remediation tracking, reporting, and service ownership identificationRequirementsProven background with 5+ years of experience in Software Engineering or Application SecuritySolid understanding of REST APIs, GraphQL, and Authentication & Authorization mechanismsWorking knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10Hands-on experience reproducing security findingsProficiency with PostmanPractical experience using Jira and ServiceNow for tracking and workflowStrong stakeholder management skills across technical and non-technical teamsEnglish proficiency at B2 (Upper-Intermediate) level or higherNice to haveExperience with HackerOne or other Bug Bounty programsBackground in AppSec and penetration testingFull-stack software development experienceFamiliarity with Burp SuiteExperience building or using GenAI automationWe offerInternational projects with top brandsWork with global teams of highly skilled, diverse peersHealthcare benefitsEmployee financial programsPaid time off and sick leaveUpskilling, reskilling and certification coursesUnlimited access to the LinkedIn Learning library and 22,000+ coursesGlobal career opportunitiesVolunteer and community involvement opportunitiesEPAM Employee GroupsAward-winning culture recognized by Glassdoor, Newsweek and LinkedInEPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.