Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
ES

Senior Security Testing Engineer

EPAM Systems
๐Ÿ‡ฑ๐Ÿ‡น Lithuania | ๐Ÿ‡ฑ๐Ÿ‡ป Latvia
Hybrid
Senior
1 week ago
  • Penetration Testing
  • DNS
  • DHCP
  • Threat Modeling
  • Vulnerability Management
  • Python
  • Golang
  • AWS
  • GCP
  • Azure
  • Kubernetes
  • OWASP
  • Agile
  • SAST
  • DAST
  • CodeQL
  • SonarQube
  • ISO 27001
  • NIST
  • PCI DSS
  • GDPR
  • CISSP
  • CSSLP
  • CEH
  • OSCP
  • OSWE
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

We are seeking aSenior Security Testing Engineer to perform security assessments, application security reviews, and penetration testing for SaaS services and on-prem solutions focused on DNS/DHCP protocols, while collaborating with development teams to strengthen secure coding practices and embed threat modeling throughout the software development lifecycle.

Responsibilities

  • Perform security assessments, application security reviews, and penetration testing for SaaS services and on-prem solutions focused around DNS/DHCP protocol
  • Collaborate with development teams to enforce secure coding practices, guidelines, and standards
  • Ensure integration of security requirements and threat modeling considerations into the software development lifecycle
  • Offer guidance and support during security-related discussions and decision-making processes
  • Provide guidance on secure design principles and assist in addressing security issues
  • Plan, execute, and analyze application security testing, including penetration testing, vulnerability scanning, and code reviews
  • Interpret penetration test results and recommend remediation measures based on identified threats
  • Design and implement effective security controls, such as access controls, authentication mechanisms, encryption, and secure communication protocols, together with development teams
  • Utilize threat modeling outputs to guide security control selection and implementation
  • Stay up-to-date with emerging security threats, vulnerabilities, and best practices in application security and threat modeling
  • Educate development teams on secure coding practices, common vulnerabilities, and security best practices
  • Conduct security training sessions and workshops to raise awareness of threat modeling concepts and foster a security-conscious culture

Requirements

  • 5+ years of experience in vulnerability management and penetration testing
  • Knowledge of application security principles, threat modeling methodologies, and best practices
  • Proficiency in secure coding practices, vulnerability assessment, and penetration testing methodologies
  • Skills in Shell Scripts, Python, or Golang
  • Familiarity with cloud environments like AWS, GCP, and Azure, and technologies like Kubernetes and Containers
  • Familiarity with common web application vulnerabilities (e.g., OWASP Web/API Top 10) and corresponding mitigation techniques
  • Experience with implementing and managing security testing tools and technologies, such as static analysis tools, dynamic application scanners, and penetration testing frameworks
  • Understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into agile development processes with SAST & DAST tools (Coverity, CodeQL, SonarQube, Contrast)
  • Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols
  • Familiarity with industry standards and frameworks such as ISO 27001, NIST, PCI DSS, and GDPR
  • Excellent communication and collaboration skills, with the ability to effectively communicate technical concepts to non-technical stakeholders
  • MS/M.tech or BS/B.tech in Computer Science or related field, or equivalent work experience required

Nice to have

  • Relevant certifications (e.g CISSP, CSSLP, CEH, OSCP, OSWE)
  • Understanding of cyber security frameworks like OWASP, SANS, NIST, CIS

Senior Security Testing Engineer ยท EPAM Systems

Auto apply with Likeremote