Summary
✨ AI‑Generated
A leading technology firm seeks a senior engineer to protect web applications and APIs from security risks. You will perform secure design reviews, threat modeling, and vulnerability assessments, partnering with developers to prioritize and remediate issues effectively.
Highlights
Reduce security risk across web applications and APIs throughout the development lifecycle. Partner with engineering teams to validate findings and drive remediation. Focus on practical outcomes and reducing false positives.
Description
We are looking for a Senior Application Security Engineer to reduce security risk across web applications and APIs throughout the software development lifecycle.
You will partner closely with engineering teams to assess application security, perform secure design and code reviews, validate and prioritize findings, and drive remediation to closure.
This role focuses on practical application security outcomes: identifying real risk, reducing false positives, and helping teams build and ship secure software efficiently.
Responsibilities
Perform security assessments of web applications, APIs, services, and supporting componentsFacilitate threat modeling and review architectures and technical designs from a security perspectiveConduct secure code reviews and identify vulnerabilities and insecure implementation patternsValidate findings from automated tools, reduce false positives, and prioritize issues based on exploitability and business impactProvide clear, actionable remediation guidance and secure implementation recommendationsTrack findings through remediation and retesting in collaboration with development teamsAdvise teams on authentication, authorization, session management, input validation, data protection, cryptography, secrets handling, and API security controlsContribute to secure SDLC practices, security standards, guidelines, and reusable security patternsCommunicate security risks and recommendations to technical and non-technical stakeholders
Requirements
Hands-on experience in application security or product securityStrong knowledge of web application and API security, including OWASP Top 10 and common vulnerability classesPractical experience with security assessments, secure design reviews, and/or secure code reviewsUnderstanding of threat modeling and secure software design principlesStrong knowledge of authentication, authorization, session management, input validation, cryptography, secrets handling, and data protectionProficiency in English at a B2+ level
We offer
We gather like-minded people:Top tech minds driving innovation in AI, cloud and digital platform modernizationSupportive team and agile, startup-like cultureHybrid by design mode and opportunity to work remotely within PolandChance to work abroad for up to 60 days annuallyBusiness-driven relocation opportunitiesWe provide growth opportunities:Career development programsThought leadership, mentoring, soft skills and well-being programsCertification (Anthropic, Gemini, GCP, Azure, AWS)English classesWe cover it all:Stable payParticipation in the Employee Stock Purchase Plan with a 15% discountBenefits package (health insurance, multisport, shopping vouchers)Referral bonuses up to $2,000Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and moreCorporate, social and well-being eventsPlease, note:Benefits listed above are available to employees onlyWe are open for working with Contractors.
Terms of B2B cooperation agreements are agreed individuallyWe will reach out to selected candidates exclusively
EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups.
With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.