We are seeking a Senior Application Security Engineer to own and drive application security vulnerability remediation programs, with an initial focus on HackerOne bug bounty findings, API security vulnerabilities, GraphQL authorization issues, and cross-functional remediation tracking. This role serves as the operational owner of the vulnerability remediation lifecycle, coordinating across Cybersecurity, Engineering, Product, and external vendors to ensure timely identification, validation, assignment, remediation, and closure of security findings.ResponsibilitiesOwn day-to-day management of the HackerOne programManage vulnerability intake, triage, validation, routing, tracking, and closureCoordinate weekly operating reviews with HackerOne and internal stakeholdersTrack remediation commitments and drive accountabilityManage disclosure and communication processesReproduce and validate reported vulnerabilities, assessing exploitability and business impactUtilize Postman, browser tooling, and security testing tools to validate findingsSupport vulnerability prioritization based on customer and business riskCoordinate remediation efforts across multiple engineering organizationsIdentify service ownership and route findings appropriately, maintaining Jira and ServiceNow trackingEscalate critical and overdue itemsProduce executive-level reporting and dashboards, tracking backlog trends, SLA compliance, remediation progress, and risk reductionPresent status updates to cybersecurity and engineering leadershipLeverage GenAI and workflow automation to improve triage, remediation tracking, reporting, and service ownership identificationRequirements3+ years of experience in Software Engineering or Application SecurityUnderstanding of REST APIs, GraphQL, and Authentication & Authorization mechanismsKnowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10Experience reproducing security findingsProficiency in PostmanExperience with Jira and ServiceNowStrong stakeholder management skillsEnglish proficiency at B2 level or higherNice to haveBackground in HackerOne or Bug Bounty programsExperience in AppSec and penetration testingFull-stack software development backgroundFamiliarity with Burp SuiteExperience with GenAI automationWe offerInternational projects with top brandsWork with global teams of highly skilled, diverse peersHealthcare benefitsEmployee financial programsPaid time off and sick leaveUpskilling, reskilling and certification coursesUnlimited access to the LinkedIn Learning library and 22,000+ coursesGlobal career opportunitiesVolunteer and community involvement opportunitiesEPAM Employee GroupsAward-winning culture recognized by Glassdoor, Newsweek and LinkedInEPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.