EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.
We are looking for a Senior Security Test Engineer to play a critical role in ensuring the security of our web and mobile applications and underlying infrastructure.
Want more jobs like this?
Get jobs in Bucharest, Romania delivered to your inbox every week.
You will be responsible for conducting periodic penetration tests, providing guidance on secure coding practices, configuring and monitoring web application firewalls (WAF), and responding to security incidents. Your expertise in secure software development lifecycle (SDLC) and familiarity with security tools will help strengthen our security posture and protect our systems from potential threats.
#LI-DNI
Responsibilities
- Conduct periodic penetration tests of web and mobile applications to identify vulnerabilities and security weaknesses
- Perform penetration tests on underlying infrastructure, including Kubernetes clusters, to ensure robust security measures are in place
- Provide guidance and support to the development team on secure coding practices to prevent security vulnerabilities
- Collaborate with external penetration testing vendors to execute comprehensive security assessments
- Respond promptly to security incidents and participate in incident resolution and post-mortem analysis
- Configure and monitor Web Application Firewalls (WAF) to detect and mitigate security threats in real time
- Follow up on the remediation of identified vulnerabilities to ensure timely resolution and risk mitigation
- Review and follow up on security findings from penetration tests, vulnerability assessments, and code reviews to maintain a high security standard
- Enhance the Continuous Integration/Continuous Deployment (CI/CD) pipeline by implementing quality gates that prevent or quickly report security vulnerabilities
- 3+ years of experience in Security Testing
- Strong understanding of secure software development lifecycle (SDLC) and best practices
- Familiarity with security tools such as OWASP ZAP, OWASP Dependency Track, Burp Suite, and others
- Experience with vulnerability assessment tools like Snyk, SonarQube, Trivy
- Proven track record of performing penetration tests on web, mobile applications, and infrastructure
- Ability to provide actionable guidance to development teams on secure coding practices
- Experience working with external vendors for penetration testing and other security services
- Skilled in security incident response and resolution
- Proficiency in configuring and monitoring Web Application Firewalls (WAF)
- Excellent communication and collaboration skills to effectively follow up on remediation and security findings
- We believe that the greatest strength of the company is its people. EPAM is fully committed to help its employees to reach their full potential and achieve their professional goals through continues learning. With this in mind, we would like to introduce to you few of the many opportunities and services which we believe will help you expand your current knowledge
- Full access to cutting-edge tools and technologies
- Competitive compensation depending on experience and skills
- All-around Social package: professional & soft skills training, medical & family care programs, sports
- Relocation opportunities
- Free English classes
- Unlimited access to LinkedIn learning solutions
- Continuous experience exchange with experts and professionals worldwide
- Friendly team and comfortable working environment
- Engineering, corporate, and social events within and outside the Company
- Flexible working schedule
- Opportunities for self-realization