Lead AI Security Engineer
New
E
EPAM SystemsApplication security
Opportunity to work remotely within PolandFull-TimeLead
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Languages
- English B2
- Required Skills
- CI/CDPrompt Engineering
Requirements
- Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent practical experience.
- Hands-on application security experience across the software development lifecycle.
- Strong understanding of common application vulnerability classes, mitigations, the OWASP Top 10, and secure coding principles.
- Practical experience with application security tooling such as SAST, DAST, SCA, and secrets scanning, including CI/CD integration.
- Working knowledge of at least one programming language sufficient to read code and assess vulnerabilities.
- Experience with threat modeling and secure design review methodologies.
- Understanding of DevOps or DevSecOps practices, CI/CD pipelines, and secure-by-design principles.
- Familiarity with cloud application security on at least one major cloud platform, such as Azure, AWS, or GCP.
- Experience participating in several production projects or engineering teams.
- Practical understanding of AI-assisted productivity and automation, such as building agents, automating tasks, integrating LLMs with tools or workflows, or using structured prompting.
- Awareness of sensitive data handling and access control when using AI tools.
- English proficiency at B2 level.
Responsibilities
- Embed security into the software development lifecycle and promote shift-left and secure-by-design practices.
- Perform threat modeling, architecture security reviews, and design reviews for applications, services, and APIs.
- Conduct manual and AI-assisted secure code reviews and advise developers on secure coding and remediation.
- Implement and operate application security tools, including SAST, DAST, IAST, SCA, secrets scanning, and IaC scanning, in CI/CD pipelines.
- Triage and prioritize security findings, reduce false positives, and work with development teams through remediation.
- Define security gates and policies in CI/CD pipelines and strengthen software supply chain controls.
- Coordinate application penetration testing and validate vulnerability fixes.
- Establish a security champions program and deliver secure-coding training, standards, and reusable patterns.
- Build AI-assisted automations and agents for AppSec workflows, integrating LLMs with scanners, code hosts, ticketing, and security tools.
- Implement evaluation, human review, privacy, and security controls for AI-assisted AppSec workflows and AI-powered application features.
View Full Description & ApplyYou'll be redirected to the employer's site