Senior Application Security Engineer

EPAM Systems, Inc.

United States

Remote

USD 120,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Healthcare benefits
Paid time off
LinkedIn Learning access
Global career opportunities
Employee resource groups
Volunteer opportunities

Job summary

EPAM Systems, Inc. seeks a Senior Application Security Engineer to own the vulnerability remediation lifecycle, focusing on HackerOne findings, API security, and GraphQL authorization.

You will coordinate across Cybersecurity, Engineering, Product, and external vendors to ensure timely triage, assignment, remediation, and closure of security findings. You will reproduce and validate vulnerabilities, assess exploitability, and drive remediation with Postman and security tooling.

Qualifications

  • 3+ years of experience in software engineering or application security.
  • Knowledge of REST APIs, GraphQL, OAuth/JWT and API Security Top 10.
  • Experience reproducing security findings.
  • Proficiency in Postman.
  • Familiarity with Jira and ServiceNow.
  • English proficiency at B2 level or higher.
  • Nice to have HackerOne/Bug Bounty background.
  • Full-stack software development background.
  • Familiarity with GenAI automation.

Responsibilities

  • Own day-to-day management of the HackerOne program.
  • Manage vulnerability intake, triage, validation, routing, tracking, and closure.
  • Coordinate weekly operating reviews with HackerOne and internal stakeholders.
  • Track remediation commitments and drive accountability.
  • Manage disclosure and communication processes.
  • Reproduce and validate reported vulnerabilities, assessing exploitability and business impact.
  • Utilize Postman, browser tooling, and security testing tools to validate findings.
  • Support vulnerability prioritization based on customer and business risk.
  • Coordinate remediation efforts across multiple engineering organizations.
  • Identify service ownership and route findings appropriately, maintaining Jira and ServiceNow tracking.
  • Escalate critical and overdue items.
  • Produce executive-level reporting and dashboards, tracking backlog trends, SLA compliance, remediation progress, and risk reduction.
  • Present status updates to cybersecurity and engineering leadership.
  • Leverage GenAI and workflow automation to improve triage, remediation tracking, reporting, and service ownership identification.

Skills

REST APIs
GraphQL
OAuth/JWT
OWASP Top 10
API Security Top 10
Postman
Jira
ServiceNow
GenAI automation
Stakeholder management
Burp Suite
Full-stack development

Tools

Burp Suite
Jira
ServiceNow
Postman

Job description

We are seeking a Senior Application Security Engineer to own and drive application security vulnerability remediation programs, with an initial focus on HackerOne bug bounty findings, API security vulnerabilities, GraphQL authorization issues, and cross-functional remediation tracking. This role serves as the operational owner of the vulnerability remediation lifecycle, coordinating across Cybersecurity, Engineering, Product, and external vendors to ensure timely identification, validation, assignment, remediation, and closure of security findings.ResponsibilitiesOwn day-to-day management of the HackerOne programManage vulnerability intake, triage, validation, routing, tracking, and closureCoordinate weekly operating reviews with HackerOne and internal stakeholdersTrack remediation commitments and drive accountabilityManage disclosure and communication processesReproduce and validate reported vulnerabilities, assessing exploitability and business impactUtilize Postman, browser tooling, and security testing tools to validate findingsSupport vulnerability prioritization based on customer and business riskCoordinate remediation efforts across multiple engineering organizationsIdentify service ownership and route findings appropriately, maintaining Jira and ServiceNow trackingEscalate critical and overdue itemsProduce executive-level reporting and dashboards, tracking backlog trends, SLA compliance, remediation progress, and risk reductionPresent status updates to cybersecurity and engineering leadershipLeverage GenAI and workflow automation to improve triage, remediation tracking, reporting, and service ownership identificationRequirements3+ years of experience in Software Engineering or Application SecurityUnderstanding of REST APIs, GraphQL, and Authentication & Authorization mechanismsKnowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10Experience reproducing security findingsProficiency in PostmanExperience with Jira and ServiceNowStrong stakeholder management skillsEnglish proficiency at B2 level or higherNice to haveBackground in HackerOne or Bug Bounty programsExperience in AppSec and penetration testingFull-stack software development backgroundFamiliarity with Burp SuiteExperience with GenAI automationWe offerInternational projects with top brandsWork with global teams of highly skilled, diverse peersHealthcare benefitsEmployee financial programsPaid time off and sick leaveUpskilling, reskilling and certification coursesUnlimited access to the LinkedIn Learning library and 22,000+ coursesGlobal career opportunitiesVolunteer and community involvement opportunitiesEPAM Employee GroupsAward-winning culture recognized by Glassdoor, Newsweek and LinkedIn
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Application Security Engineer
Lead Application Security Engineer

EPAM Systems, Inc. • United States

Remote
USD 140,000 - 210,000
Healthcare benefits
Paid time off
LinkedIn Learning access
+1
Senior AppSec Engineer: Vulnerability Remediation Lead
Senior AppSec Engineer: Vulnerability Remediation Lead

EPAM Systems, Inc. • United States

Remote
USD 120,000 - 180,000
Healthcare benefits
Paid time off
LinkedIn Learning access
+3
Lead AppSec Engineer - HackerOne & API Security Lead
Lead AppSec Engineer - HackerOne & API Security Lead

EPAM Systems Inc • United States

Remote
USD 150,000 - 190,000
Lead AppSec & Vulnerability Remediation
Lead AppSec & Vulnerability Remediation

EPAM Systems, Inc. • United States

Remote
USD 140,000 - 210,000
Healthcare benefits
Paid time off
LinkedIn Learning access
+1
Product Security Analyst
Product Security Analyst

hackerone • Washington

On-site
USD 120,000 - 155,000
Health insurance
Equity stock options
Unlimited PTO
Senior Security Engineer
Senior Security Engineer

Foundation Capital • Phoenix (AZ)

On-site
USD 130,000 - 190,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • New York (NY)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Manager, AI Engineering
Senior Manager, AI Engineering

HackerOne Inc. • Washington

On-site
USD 240,000 - 280,000
Health (medical, vision, dental) insurance
Equity stock options
Retirement plans
+1
Senior Manager, AI Engineering
Senior Manager, AI Engineering

Milwaukee Succeeds • Austin (TX)

On-site
USD 240,000 - 280,000
Health insurance
Equity stock options
Retirement plans
+2
Senior Manager, AI Engineering HackerOne · Remote · US · AI Engineering $240,000–$280,000 3mo ago
Senior Manager, AI Engineering HackerOne · Remote · US · AI Engineering $240,000–$280,000 3mo ago

Aimlroles • Austin (TX), Northern (KY)

Hybrid
USD 240,000 - 280,000
Health insurance
Equity stock options
Retirement plans
+4