Senior Application Security Engineer

EPAM·Lithuania, Latvia·Удалённо, Офис·сегодня

EPAM is seeking a skilled Senior Application Security Engineer to help our clients strengthen their security posture.

You will collaborate with a range of security and non-security teams to establish secure coding standards, perform in-depth code reviews, embed SAST/DAST tools within the CI/CD pipeline, and support threat modeling throughout the software development lifecycle.

Responsibilities

  • Perform security assessments, threat modeling, and evaluate penetration testing outcomes for applications
  • Work alongside developers and other stakeholders to fix identified security weaknesses
  • Build and deploy automated security testing tools and workflows to detect vulnerabilities
  • Embed security tools, standards, and processes within the secure software development lifecycle (SSDLC)
  • Keep current with emerging security threats and update scanning rules accordingly
  • Provide training and guidance to developers on security best practices and awareness
  • Shape and drive the security strategy and roadmap for application development
  • Fine-tune and adapt SAST processes to meet application security needs
  • Gain thorough knowledge of SAST methodologies and champion their purpose within the development lifecycle
  • Partner with developers to smoothly incorporate SAST tools into their workflows and CI/CD pipelines

Requirements

  • Minimum 5 years of experience in Application Security
  • Solid background with Checkmarx CxSAST or similar SAST tools
  • Skilled in CxQL for creating and adjusting scanning rules
  • Strong grasp of SAST and its function in secure software development
  • Experience with GitHub and embedding security scans into CI/CD pipelines
  • Sharp analytical abilities to interpret scan outcomes and enhance scan precision
  • Effective communication skills for close collaboration with development teams and stakeholders
  • Comprehensive understanding of DevSecOps principles, focusing on security integration across all development stages
  • Fluent in English communication at a B2+ level

Nice to have

  • Familiarity with Python, Go, or other scripting languages and automation tools
  • General knowledge of Cloud Platforms
  • Experience with CI/CD tools such as Jenkins, GitLab CI/CD, or Azure DevOps
  • Background in containerization and orchestration technologies like Docker and Kubernetes
  • Knowledge of SecOps tools and practices, covering security monitoring, incident response, and threat modeling
  • Understanding of Infrastructure as Code tools like Terraform or Ansible
  • Experience with security monitoring and logging tools like ELK Stack or Prometheus

Похожие вакансии

Другие вакансии EPAM