EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.We are seeking an experienced Penetration Tester to establish and operate a robust, repeatable security-testing capability for our products and supporting infrastructure. The role will design the penetration-testing framework, toolset, processes, and test environments needed to conduct regular assessments across web applications, APIs, virtual machines, cloud configurations, and related infrastructure. A key objective is to validate defenses against modern attack techniques and maintain high security coverage across the business product offering.ResponsibilitiesDesign, implement, and maintain a penetration-testing framework covering methodology, scope definition, test frequency, evidence collection, reporting, retesting, and risk trackingBuild, configure, and maintain the tools, scripts, environments, and automation required for recurring security assessmentsPerform manual and automated penetration testing of web applications, customer-facing portals, APIs, virtual machines, operating systems, networks, and cloud environments (IAM, storage, networking, logging, secrets, containers)Identify vulnerabilities, validate exploitability, assess business impact, and provide practical, prioritized remediation recommendationsDesign attack scenarios reflecting modern attacker behavior, including automated reconnaissance, vulnerability discovery, credential attacks, and attack chainingCollaborate with software engineering, DevOps, cloud, infrastructure, product, and security teams to explain findings, support remediation, and confirm fixes through retestingIntegrate appropriate security testing and scanning into CI/CD pipelines and engineering workflowsStay current on vulnerabilities, offensive-security techniques, cloud-security threats, OWASP guidance, and emerging attack trendsRequirements8+ years of hands-on experience in penetration testing, application security, offensive security, red teaming, or a similar roleProven experience testing web applications, APIs, cloud infrastructure, virtual machines, operating systems, and network servicesStrong knowledge of OWASP Top 10, OWASP API Security Top 10, common web and API attack techniques, and secure-development practicesPractical experience assessing one or more major cloud platforms: AWS, Microsoft Azure, or Google Cloud PlatformStrong understanding of identity and access management, authentication, authorization, session security, networking, encryption, secrets management, and common cloud misconfigurationsHands-on experience with tools such as Burp Suite, Nmap, Wireshark, Metasploit, Nessus/OpenVAS, sqlmap, and cloud-security toolsProficiency in scripting or programming using Python, Bash, PowerShell, JavaScript, or similar languagesAbility to independently plan and execute tests, document evidence, communicate risk, and deliver concise, actionable technical reportsStrong communication skills and the ability to work constructively with engineering and business stakeholdersNice to haveExperience building internal penetration-testing frameworks, labs, tools, scripts, or security-test automationExperience integrating security controls or testing activities into CI/CD pipelinesKnowledge of Docker, Kubernetes, Terraform, infrastructure as code, and container-security testingRelevant certifications such as OSCP, OSWE, OSEP, CRTO, CREST, GPEN, GWAPT, PNPT, CISSP, or cloud-security certificationsWe offerOpportunity to work on technical challenges that may impact across geographiesVast opportunities for self-development: online university, knowledge sharing opportunities globally, learning opportunities through external certificationsOpportunity to share your ideas on international platformsSponsored Tech Talks & HackathonsUnlimited access to LinkedIn learning solutionsPossibility to relocate to any EPAM office for short and long-term projectsFocused individual developmentBenefit package:Health benefitsRetirement benefitsPaid time offFlexible benefitsForums to explore beyond work passion (CSR, photography, painting, sports, etc.)