We are looking for a Senior Application Security Testing Engineer to join our ever-growing Security team. In this role, you will assess and strengthen the security posture of applications and systems, working closely with engineering teams to embed security best practices throughout the development lifecycle.ResponsibilitiesConduct regular scanning and manual security testing of web applications to identify vulnerabilitiesTrack identified issues through to remediation, working closely with development teams to ensure timely fixesPerform code-level reviews to identify insecure coding practices and recommend improvementsSupport and strengthen IaaS security across cloud environments, with a particular focus on AWSAssess cloud configurations against security best practice and industry benchmarksWork within a hybrid cloud environment to implement and operate appropriate security technologies and controlsResearch emerging security threats, vulnerabilities, and exploit techniques relevant to the technology stackRespond promptly to newly identified threats and support the implementation of new security requirementsContribute to incident response activities as required, maintaining the confidentiality of all investigation informationProvide technical guidance and oversight to developers on secure coding practices and application security standardsChampion OWASP principles across the organization, embedding them into the design and development of new solutionsCollaborate closely with cross-functional teams, contributing a security-first mindset to product and engineering discussionsRequirementsBachelor's Degree, preferably in a technical discipline such as Information Systems, Computer Science, or a related fieldA minimum of 3 years' demonstrated experience in manual security testingUnderstanding of security protocols, cryptography, authentication, and authorization, along with general application security requirementsKnowledge of at least one object-oriented programming language, such as Node.js or TypeScriptExperience implementing and operating security technologies and processes within a hybrid cloud environment, particularly AWSExpertise in OWASP concepts and their practical application across varied solutionsUnderstanding of IT operations and service support processesExcellent communication skills, with the ability to translate technical security concepts for non-technical stakeholdersEnglish proficiency at B2 level or higherNice to haveRelevant security certifications, such as CISSP, GIAC, CEH, Security+, or CSSLPPrior experience working within a fast-paced, product-led, or e-commerce technology environmentFamiliarity with automated security scanning and CI/CD pipeline integrationWe offerWe gather like-minded people:Top tech minds driving innovation in AI, cloud and digital platform modernizationSupportive team and agile, startup-like cultureHybrid by design mode and opportunity to work remotely within PolandChance to work abroad for up to 60 days annuallyBusiness-driven relocation opportunitiesWe provide growth opportunities:Career development programsThought leadership, mentoring, soft skills and well-being programsCertification (Anthropic, Gemini, GCP, Azure, AWS)English classesWe cover it all:Stable payParticipation in the Employee Stock Purchase Plan with a 15% discountBenefits package (health insurance, multisport, shopping vouchers)Referral bonuses up to $2,000Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and moreCorporate, social and well-being eventsPlease, note:Benefits listed above are available to employees onlyWe are open for working with Contractors. Terms of B2B cooperation agreements are agreed individuallyWe will reach out to selected candidates exclusivelyEPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.