Lead Security Testing Engineer

EPAM Systems

Poland

Hybrid

PLN 180,000 - 280,000

Full time

10 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance
Multisport
Employee Stock Purchase Plan
Relocation assistance

Job summary

EPAM Systems seeks a Lead Security Testing Engineer to drive security assessments, penetration testing, and vulnerability management across SaaS and on‑prem environments focused on DNS/DHCP protocols. You will guide teams on secure coding and threat modeling throughout the SDLC, collaborating with development to implement robust security controls.

You will review findings from SAST/DAST/containers, validate remediations, and educate teams on best practices, aligning with ISO/NIST standards and

Qualifications

  • 5+ years in vulnerability management and penetration testing.
  • Knowledge of application security principles and threat modeling.
  • Proficient in secure coding practices and vulnerability assessment.
  • Background in scripting languages (Shell, Python, Golang).
  • Experience with AWS, GCP, Azure and Kubernetes/container tech.
  • Familiar with OWASP Top 10 and mitigation techniques.
  • Experience with static/dynamic analysis and pentesting frameworks.
  • Understanding of SDLC integration for security in agile teams.

Responsibilities

  • Conduct security assessments, reviews, and pentesting for SaaS and on‑prem solutions.
  • Review and validate vulnerability findings from SAST/DAST/containers and define tests.
  • Validate remediations across apps, platforms, and infra to fix root causes.
  • Plan and execute application security testing, including code reviews.
  • Interpret test results and recommend remediation based on threats.
  • Collaborate with developers to enforce secure coding practices and standards.
  • Integrate threat modeling into the software development lifecycle.
  • Educate teams on secure design principles and conduct security training.
  • Design and implement access controls, encryption, and secure communications.
  • Document findings with evidence supporting closure or remediation gaps.

Skills

Vulnerability management
Penetration testing
Threat modeling
Secure coding practices
Security assessments
SAST/DAST/DAST tools
Cloud security (AWS/GCP/Azure)
Kubernetes and containers

Education

MS/M.Tech or BS/B.Tech in Computer Science or related field

Tools

SAST tools
DAST tools
CodeQL
SonarQube
Coverity
Container security tooling

Job description

We are looking for a Lead Security Testing Engineer to drive security assessments, penetration testing, and vulnerability management efforts across SaaS services and on-prem solutions focused on DNS/DHCP protocols. The ideal candidate will bring deep technical expertise in application security, threat modeling, and secure development practices, while guiding teams toward building more resilient and secure systems.

Responsibilities
  • Perform security assessments, application security reviews, and penetration testing for SaaS services and on-prem solutions centered on DNS/DHCP protocol
  • Review vulnerability findings from SAST, DAST, SCA, container, secrets, and infrastructure security scanning tools, and define appropriate validation approaches
  • Validate security remediations across applications, platforms, cloud services, infrastructure components, and development toolchains to ensure vulnerabilities are effectively addressed and root causes eliminated
  • Plan, execute, and analyze application security testing, including penetration testing, vulnerability scanning, and code reviews
  • Interpret penetration test results and recommend remediation measures based on identified threats
  • Collaborate with development teams to enforce secure coding practices, guidelines, and standards
  • Integrate security requirements and threat modeling considerations into the software development lifecycle
  • Provide guidance on secure design principles and support security-related discussions and decision‑making processes
  • Work closely with development teams to design and implement effective security controls, such as access controls, authentication mechanisms, encryption, and secure communication protocols
  • Utilize threat modeling outputs to guide security control selection and implementation
  • Educate development teams on secure coding practices, common vulnerabilities, and security best practices through training sessions and workshops
  • Analyze security test results, document findings, and provide clear evidence supporting vulnerability closure, risk acceptance, or remediation gaps
Requirements
  • 5+ years of experience in vulnerability management and penetration testing
  • Knowledge of application security principles, threat modeling methodologies, and best practices
  • Proficiency in secure coding practices, vulnerability assessment, and penetration testing methodologies
  • Background in Shell Scripts, Python, or Golang development
  • Familiarity with cloud environments such as AWS, GCP, Azure, and technologies like Kubernetes and Containers
  • Familiarity with common web application vulnerabilities (e.g., OWASP Web/API Top 10) and corresponding mitigation techniques
  • Experience implementing and managing security testing tools, such as static analysis tools, dynamic application scanners, and penetration testing frameworks
  • Understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into agile development processes with SAST and DAST tools (Coverity, CodeQL, SonarQube, Contrast)
  • Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols
  • Familiarity with industry standards and frameworks such as ISO 27001, NIST, PCI DSS, and GDPR
  • Excellent communication and collaboration skills, with the ability to effectively communicate technical concepts to non-technical stakeholders
  • MS/M.Tech or BS/B.Tech in Computer Science or related field, or equivalent work experience required
  • English proficiency at B2 level or higher
Nice to have
  • CISSP, CSSLP, CEH, OSCP, OSWE certifications
  • Understanding of cyber security frameworks like OWASP, SANS, NIST, CIS
We offer
  • We gather like-minded people:
    • Top tech minds driving innovation in AI, cloud and digital platform modernization
    • Supportive team and agile, startup-like culture
    • Hybrid by design mode and opportunity to work remotely within Poland
    • Chance to work abroad for up to 60 days annually
    • Business-driven relocation opportunities
  • We provide growth opportunities:
    • Career development programs
    • Thought leadership, mentoring, soft skills and well-being programs
    • Certification (Anthropic, Gemini, GCP, Azure, AWS)
    • English classes
  • We cover it all:
    • Stable pay
    • Participation in the Employee Stock Purchase Plan with a 15% discount
    • Benefits package (health insurance, multisport, shopping vouchers)
    • Referral bonuses up to $2,000
    • Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and more
    • Corporate, social and well-being events
  • Please, note:
    • Benefits listed above are available to employees only
    • We are open for working with Contractors. Terms of B2B cooperation agreements are agreed individually
    • We will reach out to selected candidates exclusively

EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Testing Engineer
Lead Security Testing Engineer

EPAM Systems • Łódź

Hybrid
PLN 180,000 - 280,000
Hybrid work model
Relocation opportunities
Employee stock purchase plan
+5
Lead Azure AI Security Engineer
Lead Azure AI Security Engineer

EPAM Systems • Łódź

Hybrid
PLN 250,000 - 400,000
Hybrid by design
Remote within Poland
Relocation opportunities
+2
Senior Python Automation Engineer - Cyber Security Implementation & Adoption
Senior Python Automation Engineer - Cyber Security Implementation & Adoption

EPAM Systems • Województwo pomorskie

Hybrid
PLN 150,000 - 210,000
Hybrid by design mode
Work remotely within Poland
Work abroad up to 60 days annually
+4
Senior .NET Engineer with AI
Senior .NET Engineer with AI

EPAM Systems • Wrocław

Hybrid
PLN 240,000 - 360,000
Hybrid work
Remote within Poland
Relocation assistance
+3
Senior 3rd Line / Software Maintenance Engineer
Senior 3rd Line / Software Maintenance Engineer

EPAM Systems • Poland

Hybrid
PLN 180,000 - 300,000
Hybrid work
Mobility options
Relocation assistance
+5
Senior Systems Engineer - Unix/Windows
Senior Systems Engineer - Unix/Windows

EPAM Systems • Województwo pomorskie

Hybrid
PLN 180,000 - 260,000
Hybrid work model
Remote within Poland
Relocation opportunities
+3
Senior AI/ML Solution Engineer (AI Agentic Security Testing)
Senior AI/ML Solution Engineer (AI Agentic Security Testing)

EPAM Systems • Łódź

Hybrid
PLN 250,000 - 390,000
Hybrid work model
Relocation opportunities
English classes
+2
Senior Azure DevSecOps Engineer
Senior Azure DevSecOps Engineer

EPAM Systems • Poland

Hybrid
PLN 240,000 - 360,000
Hybrid by design
Remote work within Poland
Relocation opportunities
+3
Senior Full Stack Developer
Senior Full Stack Developer

EPAM Systems • Województwo pomorskie

Hybrid
PLN 180,000 - 240,000
Hybrid work model
Remote work within Poland
Work abroad up to 60 days annually
+6
Senior Full Stack Developer
Senior Full Stack Developer

EPAM Systems • Kraków

Hybrid
PLN 180,000 - 300,000
Hybrid work model
Remote work within Poland
Career development programs
+3