ES
Senior/Lead Security Engineer - AI
EPAM Systems
๐ฎ๐ณ India
On-site
Staff / Principal
6 hours ago
- Penetration Testing
- IAM
- Devops
- CI/CD
- OWASP
- AWS
- Azure
- GCP
- Secrets Management
- Burp Suite
- Nmap
- Wireshark
- Metasploit
- Nessus
- OpenVAS
- Python
- Bash
- PowerShell
- JavaScript
- Test Automation
- Docker
- Kubernetes
- Terraform
- IaC
- OSCP
- OSWE
- GPEN
- GWAPT
- CISSP
6 hours ago
We are seeking an experiencedPenetration Tester to establish and operate a robust, repeatable security-testing capability for our products and supporting infrastructure. The role will design the penetration-testing framework, toolset, processes, and test environments needed to conduct regular assessments across web applications, APIs, virtual machines, cloud configurations, and related infrastructure. A key objective is to validate defenses against modern attack techniques and maintain high security coverage across the business product offering.
Responsibilities
- Design, implement, and maintain a penetration-testing framework covering methodology, scope definition, test frequency, evidence collection, reporting, retesting, and risk tracking
- Build, configure, and maintain the tools, scripts, environments, and automation required for recurring security assessments
- Perform manual and automated penetration testing of web applications, customer-facing portals, APIs, virtual machines, operating systems, networks, and cloud environments (IAM, storage, networking, logging, secrets, containers)
- Identify vulnerabilities, validate exploitability, assess business impact, and provide practical, prioritized remediation recommendations
- Design attack scenarios reflecting modern attacker behavior, including automated reconnaissance, vulnerability discovery, credential attacks, and attack chaining
- Collaborate with software engineering, DevOps, cloud, infrastructure, product, and security teams to explain findings, support remediation, and confirm fixes through retesting
- Integrate appropriate security testing and scanning into CI/CD pipelines and engineering workflows
- Stay current on vulnerabilities, offensive-security techniques, cloud-security threats, OWASP guidance, and emerging attack trends
Requirements
- 8+ years of hands-on experience in penetration testing, application security, offensive security, red teaming, or a similar role
- Proven experience testing web applications, APIs, cloud infrastructure, virtual machines, operating systems, and network services
- Strong knowledge of OWASP Top 10, OWASP API Security Top 10, common web and API attack techniques, and secure-development practices
- Practical experience assessing one or more major cloud platforms: AWS, Microsoft Azure, or Google Cloud Platform
- Strong understanding of identity and access management, authentication, authorization, session security, networking, encryption, secrets management, and common cloud misconfigurations
- Hands-on experience with tools such as Burp Suite, Nmap, Wireshark, Metasploit, Nessus/OpenVAS, sqlmap, and cloud-security tools
- Proficiency in scripting or programming using Python, Bash, PowerShell, JavaScript, or similar languages
- Ability to independently plan and execute tests, document evidence, communicate risk, and deliver concise, actionable technical reports
- Strong communication skills and the ability to work constructively with engineering and business stakeholders
Nice to have
- Experience building internal penetration-testing frameworks, labs, tools, scripts, or security-test automation
- Experience integrating security controls or testing activities into CI/CD pipelines
- Knowledge of Docker, Kubernetes, Terraform, infrastructure as code, and container-security testing
- Relevant certifications such as OSCP, OSWE, OSEP, CRTO, CREST, GPEN, GWAPT, PNPT, CISSP, or cloud-security certifications
Senior/Lead Security Engineer - AI ยท EPAM Systems