Lead AI Security Engineer

EPAM Systems, Inc.

Polska

Hybrid

PLN 300,000 - 420,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health insurance
Employee stock plan
Relocation opportunities
English classes

Job summary

EPAM Systems, Inc. seeks a Lead AI Security Engineer to secure software across the full development lifecycle.

You will embed security into design, code, build and release; operate application security tooling and pipelines; and partner with engineering to drive remediation, including AI- and LLM-powered applications. You will drive threat modeling, secure code reviews, and SBOM and supply-chain risk management, building AI-assisted automations to reduce manual effort across AppSec tasks and to

Qualifications

  • Hands-on application security across the SDLC.
  • Strong knowledge of OWASP Top 10 and secure design patterns.
  • Experience with CI/CD security gates and SBOMs.

Responsibilities

  • Embed security into full software development lifecycle and drive shift-left practices.
  • Perform threat modeling and architecture/security reviews for apps and APIs.
  • Conduct secure code reviews and advise developers on remediation.
  • Operate security tooling (SAST/DAST/IAST/SCA) integrated into CI/CD pipelines.
  • Triage and reduce false positives; track fixes with dev teams.
  • Build AI-assisted automations to speed AppSec tasks.

Skills

Threat modeling
Secure coding
DevSecOps
AI/LLM security
Cloud security
Code review

Tools

SAST tooling
DAST tooling
SCA tooling
Secrets scanning

Job description

We are seeking a Lead AI Security Engineer to secure software across the full development lifecycle. This role embeds security into design, code, build and release; operates application security tooling and pipelines; partners with engineering to drive remediation; and applies AI both to accelerate AppSec work and to secure AI- and LLM-powered applications.ResponsibilitiesEmbed security into the full software development lifecycle and drive shift-left and secure-by-design practices across engineering teamsPerform and facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIsConduct secure code reviews (manual and AI-assisted) and advise developers on secure coding patterns and remediationImplement, configure, tune, and operate application security tooling, including SAST, DAST, IAST, SCA, secrets scanning, and IaC scanning, integrated into CI/CD pipelinesTriage, validate, prioritize, and reduce false positives in security findings, and partner with development teams to track issues through to remediationDefine, implement, and maintain security gates and policies in CI/CD pipelines that balance risk reduction with developer velocitySecure the software supply chain, including dependency and open-source risk management, SBOM generation, artifact integrity and signing, and build pipeline hardeningSupport and coordinate application penetration testing and validate fixes for identified vulnerabilitiesDrive secrets management, secure configuration, API security, container and image security, and microservice security practicesEstablish and run a security champions program, and develop and deliver secure-coding training, guidelines, and reusable security patterns for developersDefine and maintain application security standards, baselines, and policy-as-code, and contribute to vulnerability management and risk-acceptance processesBuild, deploy, and maintain AI-assisted automations and agentic workflows that reduce manual effort across daily application security activities, such as: vulnerability triage, deduplication, prioritization, and false-positive reduction; automated and assisted code review with concrete remediation guidance and example fixes; threat modeling support and abuse-case and attack-path generation; finding enrichment, root-cause analysis, and remediation-PR drafting; compliance evidence collection; secure-coding documentation, query, and runbook automationBuild and integrate AI agents and LLM-backed automations into the SDLC and CI/CD pipelines, connecting models to scanners, code hosts, ticketing, and security tooling via function calling, REST, and webhooksDevelop, test, and maintain reusable prompts, structured-prompting patterns, and prompt templates for recurring AppSec tasks, and tune them for accuracy, signal quality, and safe behaviorImplement retrieval over codebases, security standards, and remediation guidance (for example RAG) so AI assistants answer from current, authoritative internal context rather than guessworkBuild evaluation, validation, and human-in-the-loop checkpoints into AI-assisted AppSec workflows, including output verification, guardrails, and approval gates before findings, fixes, or pipeline decisions are acted onImplement security and privacy controls for AppSec AI usage, including least-privilege access for agents, source-code and secrets handling, prompt-injection resistance, and auditability of AI-driven actionsDesign, implement, and operate security controls for AI- and LLM-powered application features, including input and output validation, prompt-injection and jailbreak defenses, tool- and function-call authorization, rate limiting, and model and data access governance, aligned to the OWASP Top 10 for LLM ApplicationsDefine and enforce guardrails for secure adoption of AI in product engineering, covering prompt security, model and tool access control, output handling, data protection, auditability, and human-in-the-loop processes, and advise development teams on building AI features securelyRequirementsBachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experienceHands-on application security experience across the software development lifecycleStrong understanding of common application vulnerability classes and mitigations, including the OWASP Top 10, and of secure coding principlesPractical experience with application security tooling, such as SAST, DAST, SCA, and secrets scanning, and integrating it into CI/CDWorking knowledge of at least one programming language (for example Python, Java, C#, JavaScript/TypeScript, or Go) sufficient to read code and assess vulnerabilitiesExperience with threat modeling and secure design review methodologiesUnderstanding of DevOps/DevSecOps practices, CI/CD pipelines, and secure-by-design principlesFamiliarity with cloud application security concepts across at least one major cloud platform such as Azure, AWS, or GCPExperience participating in at least several production projects or engineering teamsAbility to work closely with developers, architects, QA engineers, DevOps, product, and security teams, and to influence without owning the codebaseAbility to follow, maintain, and improve defined security processesPractical understanding of AI-assisted productivity and automation beyond basic chatbot usage, including at least some of the following: building or configuring AI agents; using AI to automate repetitive security or engineering tasks; integrating LLMs with tools, APIs, documents, or workflows; prompt engineering and structured prompting; creating AI-assisted runbooks, scripts, queries, or documentation; using AI tools securely with awareness of sensitive data handling and access controlGood communication skills and the ability to explain security risks, technical decisions, and remediation plans to both technical and non-technical stakeholdersNice to haveExperience with application security platforms and tools such as Snyk, Checkmarx, Veracode, SonarQube, Semgrep, GitHub Advanced Security, Burp Suite, OWASP ZAP, or similarExperience with software supply chain security, including SBOM, SLSA, Sigstore, and dependency and artifact integrity controlsExperience with Infrastructure as Code and policy-as-code security tools such as Terraform, Bicep, ARM templates, OPA, Checkov, or TrivyExperience with container and Kubernetes security, including image scanning, registries, runtime protection, and network policiesExperience with API security, secrets management (for example HashiCorp Vault, Azure Key Vault), and microservice security patternsUnderstanding of at least one compliance or security framework, such as ISO 27001, NIST, CIS Benchmarks, PCI DSS, HIPAA, SOC 2, or SOXExperience integrating security findings with SIEM/SOAR, ticketing, and vulnerability management workflowsExperience with AI/LLM platforms or frameworks such as Azure OpenAI, Azure AI Foundry, Amazon Bedrock, Microsoft Copilot Studio, LangChain, or AutoGenUnderstanding of AI and LLM application security risks, including prompt injection, insecure output handling, data leakage, excessive agency, insecure tool use, model governance, and AI supply chain risks (for example, awareness of the OWASP Top 10 for LLM Applications)Security certifications such as: CSSLP: Certified Secure Software Lifecycle Professional; GWAPT / GWEB: GIAC Web Application Penetration Tester / Web Application Defender; OSCP / OSWE: Offensive Security certifications; CISSP, CISM, CSSLP, CCSP, or similar; AI-related certifications are a plus, for example: AI-900: Microsoft Azure AI Fundamentals; AI-102: Azure AI Engineer AssociateWe offerWe gather like-minded people:Top tech minds driving innovation in AI, cloud and digital platform modernizationSupportive team and agile, startup-like cultureHybrid by design mode and opportunity to work remotely within PolandChance to work abroad for up to 60 days annuallyBusiness-driven relocation opportunitiesWe provide growth opportunities:Career development programsThought leadership, mentoring, soft skills and well-being programsCertification (Anthropic, Gemini, GCP, Azure, AWS)English classesWe cover it all:Stable payParticipation in the Employee Stock Purchase Plan with a 15% discountBenefits package (health insurance, multisport, shopping vouchers)Referral bonuses up to $2,000Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and moreCorporate, social and well-being eventsPlease, note:Benefits listed above are available to employees onlyWe are open for working with Contractors. Terms of B2B cooperation agreements are agreed individuallyWe will reach out to selected candidates exclusivelyEPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM Systems • Łódź

On-site
PLN 250,000 - 400,000
Hybrid by design
Remote within Poland
Relocation opportunities
+2
Lead AI Security Engineer
Lead AI Security Engineer

your Jared • Katowice

Hybrid
PLN 180,000 - 260,000
Comprehensive benefits package (health
Employee Stock Purchase Plan
Relocation opportunities
Senior Cybersecurity Delivery Manager
Senior Cybersecurity Delivery Manager

EPAM Systems, Inc. • Polska

Hybrid
PLN 260,000 - 360,000
Health insurance
English classes
Employee stock purchase plan
+1
Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM Systems • Poland

On-site
PLN 240,000 - 320,000
Hybrid by design remote within Poland
Relocation opportunities
Health insurance
Senior AI/ML Solution Engineer (AI Agentic Security Testing)
Senior AI/ML Solution Engineer (AI Agentic Security Testing)

EPAM Systems, Inc. • Polska

Hybrid
PLN 180,000 - 300,000
Health insurance
Stock purchase plan
Remote within Poland
+2
AI-Augmented IAM Security Engineer
AI-Augmented IAM Security Engineer

EPAM Systems • Poznań

On-site
PLN 180,000 - 240,000
Hybrid by design
Remote within Poland
Health insurance
+4
Senior Site Reliability Engineer
Senior Site Reliability Engineer

EPAM Systems, Inc. • Warszawa

Hybrid
PLN 170,000 - 320,000
Health insurance
Multisport
Shopping vouchers
+1
Senior AI-Native Engineer
Senior AI-Native Engineer

EPAM Systems, Inc. • Kraków

On-site
PLN 240,000 - 360,000
Hybrid work model
Career development programs
Relocation opportunities
+2
Senior AI-Native Engineer
Senior AI-Native Engineer

EPAM Systems, Inc. • Gdańsk

On-site
PLN 180,000 - 260,000
Health insurance
Multisport card
Shopping vouchers
+1
Senior .NET Engineer with AI
Senior .NET Engineer with AI

EPAM Systems, Inc. • Łódź

Hybrid
PLN 180,000 - 260,000
Health insurance
Employee Stock Purchase Plan
Certification programs
+2