ES
Lead Application Security Engineer
EPAM Systems
๐ง๐ท Brazil | ๐ฒ๐ฝ Mexico | ๐ฆ๐ท Argentina | ๐จ๐ฑ Chile | ๐จ๐ด Colombia
Remote
Staff / Principal
4 hours ago
- HackerOne
- GraphQL
- triage
- Postman
- Jira
- ServiceNow
- Machine Learning
- REST API
- OAuth
- JWT
- OWASP
- Bug Bounty
- AppSec
- Penetration Testing
- Burp Suite
4 hours ago
We are looking for aLead Application Security Engineer to lead application vulnerability remediation across teams, starting with HackerOne findings and API and GraphQL issues. You will own the end-to-end workflow from intake and validation to remediation tracking and closure across Cybersecurity, Engineering, Product, and vendors.
Responsibilities
- Own the daily operational execution of the HackerOne program
- Run vulnerability intake, triage, validation, assignment, tracking, and closure end to end
- Lead weekly operating reviews with HackerOne and internal stakeholders
- Track remediation commitments and reinforce accountability for delivery
- Manage coordinated disclosure and related communications
- Reproduce and validate reported vulnerabilities, evaluating exploitability and business impact
- Use Postman, browser tooling, and security testing tools to verify findings
- Support vulnerability prioritization based on customer and business risk
- Coordinate remediation work across multiple engineering organizations
- Identify service ownership and route findings correctly while maintaining Jira and ServiceNow tracking
- Escalate critical items and drive resolution for overdue work
- Deliver executive-ready reporting and dashboards on backlog trends, SLA compliance, remediation progress, and risk reduction
- Present status and outcomes to cybersecurity and engineering leadership
- Leverage GenAI and workflow automation to enhance triage, remediation tracking, reporting, and service ownership identification
Requirements
- Proven background with 5+ years of experience in Software Engineering or Application Security
- Solid understanding of REST APIs, GraphQL, and Authentication & Authorization mechanisms
- Working knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10
- Hands-on experience reproducing security findings
- Proficiency with Postman
- Practical experience using Jira and ServiceNow for tracking and workflow
- Strong stakeholder management skills across technical and non-technical teams
- English proficiency at B2 (Upper-Intermediate) level or higher
Nice to have
- Experience with HackerOne or other Bug Bounty programs
- Background in AppSec and penetration testing
- Full-stack software development experience
- Familiarity with Burp Suite
- Experience building or using GenAI automation
Lead Application Security Engineer ยท EPAM Systems