We are seeking a Lead APT & Automated Validation Engineer who goes beyond traditional penetration testing. This role is for a developer at heart — someone who can orchestrate, script, and chain network and web application exploits to run autonomously, driving continuous and scalable security validation across complex environments.ResponsibilitiesDesign and sequence exploit chains that combine multiple vulnerabilities to achieve higher-impact outcomes (e.g., pairing information disclosure with SSRF to reach Remote Code Execution)Develop custom exploits and weaponized scripts to automate multi-stage attack scenariosBuild and maintain automated authentication flows handling OAuth, TOTP, and MFA programmaticallyConfigure, scale, and operate continuous automated security validation platformsEngineer exploit scripts capable of safely validating vulnerabilities in live production environments without disrupting services or corrupting dataAnalyze network and web application attack surfaces to identify opportunities for automated exploitationCollaborate with security and engineering teams to translate manual pentesting techniques into repeatable, automated workflowsContinuously improve the organization's offensive automation framework and toolingRequirements5+ years of experience in offensive security, penetration testing, or security engineering rolesAt least 1 year of relevant leadership experienceExpertise in exploit chaining and attack logic, including sequencing low-severity findings into high-impact compromisesProficiency in Python for writing custom exploits and automating complex multi-stage attack scriptsExperience configuring and scaling continuous automated security validation tools such as Pentera, Cymulate, or Picus, including custom Pentest Robots architecturesIn-depth knowledge of the OSI model and core network protocols (DNS, BGP, TCP/IP)Understanding of web application vulnerabilities, including the OWASP Top 10 and API flaws such as IDORProven capability to engineer automated exploit scripts that safely validate vulnerabilities without crashing network infrastructure or corrupting production databasesEnglish proficiency at B1+ level or aboveNice to haveSkills in Bash and/or Go for custom tooling and exploit developmentFamiliarity with OAuth flows and programmatic handling of authenticationBackground in bypassing or automating Multi-Factor Authentication challengesWe offerWe gather like-minded people:Top tech minds driving innovation in AI, cloud and digital platform modernizationSupportive team and agile, startup-like cultureHybrid by design mode and opportunity to work remotely within PolandChance to work abroad for up to 60 days annuallyBusiness-driven relocation opportunitiesWe provide growth opportunities:Career development programsThought leadership, mentoring, soft skills and well-being programsCertification (Anthropic, Gemini, GCP, Azure, AWS)English classesWe cover it all:Stable payParticipation in the Employee Stock Purchase Plan with a 15% discountBenefits package (health insurance, multisport, shopping vouchers)Referral bonuses up to $2,000Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and moreCorporate, social and well-being eventsPlease, note:Benefits listed above are available to employees onlyWe are open for working with Contractors. Terms of B2B cooperation agreements are agreed individuallyWe will reach out to selected candidates exclusivelyEPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.