Senior/Lead Security Engineer - AI

EPAM Systems Inc

India

On-site

INR 3,000,000 - 4,500,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

EPAM Systems Inc. seeks an experienced Penetration Tester to establish and operate a robust security-testing capability for products and supporting infrastructure.

The role will design the penetration-testing framework, toolset, processes, and test environments needed to conduct regular assessments across web applications, APIs, cloud configurations, and related infrastructure. A key objective is to validate defenses against modern attack techniques and maintain high security coverage across the

Qualifications

  • 8+ years hands-on penetration testing experience across web apps, APIs, cloud, and networks.
  • Strong knowledge of OWASP Top 10 and API security practices.
  • Experience with major cloud platforms (AWS/Azure/GCP) and secure development.
  • Scripting or programming ability (Python, Bash, PowerShell, or similar).

Responsibilities

  • Design, implement, and maintain a scalable penetration-testing framework and CI/CD integration.
  • Perform manual and automated testing of web apps, APIs, cloud environments, and networks.
  • Identify vulnerabilities, assess risk, and provide prioritized remediation guidance.
  • Develop attack scenarios and validate fixes through retesting.
  • Collaborate with engineering, DevOps, and security teams to drive secure delivery.

Skills

Penetration testing
Web applications
APIs
Cloud security
Scripting
Communication

Education

OSCP
OSWE
OSEP
CISSP
GPEN
GWAPT
PNPT

Tools

Burp Suite
Nmap
Wireshark
Metasploit
Nessus/OpenVAS
sqlmap
Cloud-security tools

Job description

We are seeking an experienced Penetration Tester to establish and operate a robust, repeatable security-testing capability for our products and supporting infrastructure. The role will design the penetration-testing framework, toolset, processes, and test environments needed to conduct regular assessments across web applications, APIs, virtual machines, cloud configurations, and related infrastructure. A key objective is to validate defenses against modern attack techniques and maintain high security coverage across the business product offering.

Responsibilities
  • Design, implement, and maintain a penetration-testing framework covering methodology, scope definition, test frequency, evidence collection, reporting, retesting, and risk tracking
  • Build, configure, and maintain the tools, scripts, environments, and automation required for recurring security assessments
  • Perform manual and automated penetration testing of web applications, customer-facing portals, APIs, virtual machines, operating systems, networks, and cloud environments (IAM, storage, networking, logging, secrets, containers)
  • Identify vulnerabilities, validate exploitability, assess business impact, and provide practical, prioritized remediation recommendations
  • Design attack scenarios reflecting modern attacker behavior, including automated reconnaissance, vulnerability discovery, credential attacks, and attack chaining
  • Collaborate with software engineering, DevOps, cloud, infrastructure, product, and security teams to explain findings, support remediation, and confirm fixes through retesting
  • Integrate appropriate security testing and scanning into CI/CD pipelines and engineering workflows
  • Stay current on vulnerabilities, offensive-security techniques, cloud-security threats, OWASP guidance, and emerging attack trends
Requirements
  • 8+ years of hands-on experience in penetration testing, application security, offensive security, red teaming, or a similar role
  • Proven experience testing web applications, APIs, cloud infrastructure, virtual machines, operating systems, and network services
  • Strong knowledge of OWASP Top 10, OWASP API Security Top 10, common web and API attack techniques, and secure-development practices
  • Practical experience assessing one or more major cloud platforms: AWS, Microsoft Azure, or Google Cloud Platform
  • Strong understanding of identity and access management, authentication, authorization, session security, networking, encryption, secrets management, and common cloud misconfigurations
  • Hands-on experience with tools such as Burp Suite, Nmap, Wireshark, Metasploit, Nessus/OpenVAS, sqlmap, and cloud-security tools
  • Proficiency in scripting or programming using Python, Bash, PowerShell, JavaScript, or similar languages
  • Ability to independently plan and execute tests, document evidence, communicate risk, and deliver concise, actionable technical reports
  • Strong communication skills and the ability to work constructively with engineering and business stakeholders
Nice to have
  • Experience building internal penetration-testing frameworks, labs, tools, scripts, or security-test automation
  • Experience integrating security controls or testing activities into CI/CD pipelines
  • Knowledge of Docker, Kubernetes, Terraform, infrastructure as code, and container-security testing
Relevant certifications
  • OSCP, OSWE, OSEP, CRTO, CREST, GPEN, GWAPT, PNPT, CISSP, or cloud-security certifications
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Penetration Tester
Penetration Tester

Michael Page • Hyderabad

Hybrid
INR 2,500,000 - 5,500,000
Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Sr Security Engineer
Sr Security Engineer

Ankercloud GmbH • Bengaluru

On-site
INR 1,400,000 - 2,200,000
Senior Security Consultant
Senior Security Consultant

Wattlecorp Cybersecurity Labs LLP • Kozhikode district

On-site
INR 1,800,000 - 3,000,000
Staff Engineer - Application Security
Staff Engineer - Application Security

UST • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Senior Penetration Tester
Senior Penetration Tester

Target Corporation India Pvt Ltd • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Penetration Tester
Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Security Tester
Security Tester

Disprz • Chennai District

On-site
INR 1,800,000 - 3,600,000