Lead Security Testing Engineer

EPAM Systems

Łódź

Hybrid

PLN 180,000 - 280,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
Relocation opportunities
Employee stock purchase plan
Health insurance
Multisport
Shopping vouchers
English classes
Career development programs

Job summary

EPAM Systems invites a Lead Security Testing Engineer to drive security assessments, penetration testing, and vulnerability management for SaaS and on-prem solutions. You will guide teams toward resilient systems, enforce secure coding practices, and integrate threat modeling into the software development lifecycle.

The role requires deep expertise in application security, incident remediation, and collaboration with cross-functional teams.

Qualifications

  • Minimum 5+ years in vulnerability management and penetration testing.
  • Solid understanding of application security principles and threat modeling.
  • Experience with secure coding practices and vulnerability assessment.
  • Development background in Shell, Python, or Golang is preferred.
  • Hands-on cloud experience (AWS/GCP/Azure) and container tech (Kubernetes).
  • Familiarity with OWASP Top 10 and mitigation techniques.
  • Knowledge of SDLC integration with security tooling (SAST/DAST).
  • Strong communication to explain technical concepts to non-technical stakeholders.

Responsibilities

  • Perform security assessments, reviews, and penetration testing for SaaS and on-prem systems.
  • Review vulnerabilities from SAST, DAST, SCA, containers, and infrastructure scanners.
  • Validate remediations across apps, clouds, and development toolchains.
  • Plan, execute, and analyze application security testing and code reviews.
  • Interpret test results and propose remediation based on threats.
  • Collaborate with dev teams to enforce secure coding practices and standards.
  • Integrate threat modeling into the SDLC and guide secure design decisions.
  • Provide guidance on secure design principles and security discussions.
  • Work with teams to implement strong access controls, encryption, and secure communication.
  • Educate teams on secure coding and vulnerability trends via trainings.

Skills

Vulnerability management
Application security
Threat modeling
Secure coding
Shell scripting
Python
Golang
OWASP Top 10
Authentication/Authorization
Cryptography
Security standards
Communication

Education

MS/M.Tech or BS/B.Tech in Computer Science or related field

Tools

AWS
GCP
Azure
Kubernetes
Docker
CodeQL
Coverity
SonarQube
Contrast
SAST/DAST tools

Job description

We are looking for a Lead Security Testing Engineer to drive security assessments, penetration testing, and vulnerability management efforts across SaaS services and on-prem solutions focused on DNS/DHCP protocols. The ideal candidate will bring deep technical expertise in application security, threat modeling, and secure development practices, while guiding teams toward building more resilient and secure systems.

Responsibilities
  • Perform security assessments, application security reviews, and penetration testing for SaaS services and on-prem solutions centered on DNS/DHCP protocol
  • Review vulnerability findings from SAST, DAST, SCA, container, secrets, and infrastructure security scanning tools, and define appropriate validation approaches
  • Validate security remediations across applications, platforms, cloud services, infrastructure components, and development toolchains to ensure vulnerabilities are effectively addressed and root causes eliminated
  • Plan, execute, and analyze application security testing, including penetration testing, vulnerability scanning, and code reviews
  • Interpret penetration test results and recommend remediation measures based on identified threats
  • Collaborate with development teams to enforce secure coding practices, guidelines, and standards
  • Integrate security requirements and threat modeling considerations into the software development lifecycle
  • Provide guidance on secure design principles and support security-related discussions and decision-making processes
  • Work closely with development teams to design and implement effective security controls, such as access controls, authentication mechanisms, encryption, and secure communication protocols
  • Utilize threat modeling outputs to guide security control selection and implementation
  • Educate development teams on secure coding practices, common vulnerabilities, and security best practices through training sessions and workshops
  • Analyze security test results, document findings, and provide clear evidence supporting vulnerability closure, risk acceptance, or remediation gaps
Requirements
  • 5+ years of experience in vulnerability management and penetration testing
  • Knowledge of application security principles, threat modeling methodologies, and best practices
  • Proficiency in secure coding practices, vulnerability assessment, and penetration testing methodologies
  • Background in Shell Scripts, Python, or Golang development
  • Familiarity with cloud environments such as AWS, GCP, Azure, and technologies like Kubernetes and Containers
  • Familiarity with common web application vulnerabilities (e.g., OWASP Web/API Top 10) and corresponding mitigation techniques
  • Experience implementing and managing security testing tools, such as static analysis tools, dynamic application scanners, and penetration testing frameworks
  • Understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into agile development processes with SAST and DAST tools (Coverity, CodeQL, SonarQube, Contrast)
  • Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols
  • Familiarity with industry standards and frameworks such as ISO 27001, NIST, PCI DSS, and GDPR
  • Excellent communication and collaboration skills, with the ability to effectively communicate technical concepts to non-technical stakeholders
  • MS/M.Tech or BS/B.Tech in Computer Science or related field, or equivalent work experience required
  • English proficiency at B2 level or higher
Nice to have
  • CISSP, CSSLP, CEH, OSCP, OSWE certifications
  • Understanding of cyber security frameworks like OWASP, SANS, NIST, CIS
We offer
  • We gather like-minded people:
  • Top tech minds driving innovation in AI, cloud and digital platform modernization
  • Supportive team and agile, startup-like culture
  • Hybrid by design mode and opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities
  • We provide growth opportunities:
  • Career development programs
  • Thought leadership, mentoring, soft skills and well-being programs
  • Certification (Anthropic, Gemini, GCP, Azure, AWS)
  • English classes
  • We cover it all:
  • Stable pay
  • Participation in the Employee Stock Purchase Plan with a 15% discount
  • Benefits package (health insurance, multisport, shopping vouchers)
  • Referral bonuses up to $2,000
  • Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and more
  • Corporate, social and well-being events
  • Please, note:
  • Benefits listed above are available to employees only
  • We are open for working with Contractors. Terms of B2B cooperation agreements are agreed individually
  • We will reach out to selected candidates exclusively

EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM Systems • Łódź

Hybrid
PLN 250,000 - 400,000
Hybrid by design
Remote within Poland
Relocation opportunities
+2
Senior Python Automation Engineer - Cyber Security Implementation & Adoption
Senior Python Automation Engineer - Cyber Security Implementation & Adoption

EPAM Systems • Województwo pomorskie

Hybrid
PLN 150,000 - 210,000
Hybrid by design mode
Work remotely within Poland
Work abroad up to 60 days annually
+4
Lead AI Security Engineer
Lead AI Security Engineer

EPAM Systems • Poland

Hybrid
PLN 280,000 - 480,000
Health insurance
Employee stock purchase plan
Hybrid by design (Poland)
+1
Senior .NET Engineer (Full-Stack, Front-End, Cloud & AI)
Senior .NET Engineer (Full-Stack, Front-End, Cloud & AI)

EPAM Systems • Wrocław

Hybrid
PLN 180,000 - 240,000
Hybrid by design
Work remotely within Poland
Relocation opportunities
+2
Senior .NET Engineer (Full-Stack, Front-End, Cloud & AI)
Senior .NET Engineer (Full-Stack, Front-End, Cloud & AI)

EPAM Systems • Poznań

Hybrid
PLN 210,000 - 270,000
Hybrid by design
Remote work within Poland
Work abroad up to 60 days annually
+5
Lead Azure Cloud Engineer
Lead Azure Cloud Engineer

EPAM Systems • Poland

Hybrid
PLN 240,000 - 360,000
Hybrid by design
Remote within Poland
Relocation opportunities
+2
Senior Systems Engineer - Unix/Windows
Senior Systems Engineer - Unix/Windows

EPAM Systems • Województwo pomorskie

Hybrid
PLN 180,000 - 260,000
Hybrid work model
Remote within Poland
Relocation opportunities
+3
Senior AI/ML Solution Engineer (AI Agentic Security Testing)
Senior AI/ML Solution Engineer (AI Agentic Security Testing)

EPAM Systems • Łódź

Hybrid
PLN 250,000 - 390,000
Hybrid work model
Relocation opportunities
English classes
+2
AI-Augmented IAM Security Engineer
AI-Augmented IAM Security Engineer

EPAM Systems • Poznań

Hybrid
PLN 180,000 - 240,000
Hybrid by design
Remote within Poland
Health insurance
+4
Senior Office 365 Engineer
Senior Office 365 Engineer

EPAM Systems • Poland

Hybrid
PLN 180,000 - 240,000
Hybrid by design work model
Remote work within Poland
Relocation assistance
+3