EPAM is seeking a skilled Senior Application Security Engineer to help our clients strengthen their security posture.
You will collaborate with a range of security and non-security teams to establish secure coding standards, perform in-depth code reviews, embed SAST/DAST tools within the CI/CD pipeline, and support threat modeling throughout the software development lifecycle.
Responsibilities
- Perform security assessments, threat modeling, and evaluate penetration testing outcomes for applications
- Work alongside developers and other stakeholders to fix identified security weaknesses
- Build and deploy automated security testing tools and workflows to detect vulnerabilities
- Embed security tools, standards, and processes within the secure software development lifecycle (SSDLC)
- Keep current with emerging security threats and update scanning rules accordingly
- Provide training and guidance to developers on security best practices and awareness
- Shape and drive the security strategy and roadmap for application development
- Fine-tune and adapt SAST processes to meet application security needs
- Gain thorough knowledge of SAST methodologies and champion their purpose within the development lifecycle
- Partner with developers to smoothly incorporate SAST tools into their workflows and CI/CD pipelines
Requirements
- Minimum 5 years of experience in Application Security
- Solid background with Checkmarx CxSAST or similar SAST tools
- Skilled in CxQL for creating and adjusting scanning rules
- Strong grasp of SAST and its function in secure software development
- Experience with GitHub and embedding security scans into CI/CD pipelines
- Sharp analytical abilities to interpret scan outcomes and enhance scan precision
- Effective communication skills for close collaboration with development teams and stakeholders
- Comprehensive understanding of DevSecOps principles, focusing on security integration across all development stages
- Fluent in English communication at a B2+ level
Nice to have
- Familiarity with Python, Go, or other scripting languages and automation tools
- General knowledge of Cloud Platforms
- Experience with CI/CD tools such as Jenkins, GitLab CI/CD, or Azure DevOps
- Background in containerization and orchestration technologies like Docker and Kubernetes
- Knowledge of SecOps tools and practices, covering security monitoring, incident response, and threat modeling
- Understanding of Infrastructure as Code tools like Terraform or Ansible
- Experience with security monitoring and logging tools like ELK Stack or Prometheus