ES
Lead APT & Automated Validation Engineer
EPAM Systems
- ๐ต๐ฑ Poland
- Remote
- Staff / Principal
- 16 hours ago
- Penetration Testing
- OAuth
- Python
- DNS
- BGP
- TCP/IP
- OWASP
- Bash
16 hours ago
We are seeking aLead APT & Automated Validation Engineer who goes beyond traditional penetration testing. This role is for a developer at heart โ someone who can orchestrate, script, and chain network and web application exploits to run autonomously, driving continuous and scalable security validation across complex environments.
Responsibilities
- Design and sequence exploit chains that combine multiple vulnerabilities to achieve higher-impact outcomes (e.g., pairing information disclosure with SSRF to reach Remote Code Execution)
- Develop custom exploits and weaponized scripts to automate multi-stage attack scenarios
- Build and maintain automated authentication flows handling OAuth, TOTP, and MFA programmatically
- Configure, scale, and operate continuous automated security validation platforms
- Engineer exploit scripts capable of safely validating vulnerabilities in live production environments without disrupting services or corrupting data
- Analyze network and web application attack surfaces to identify opportunities for automated exploitation
- Collaborate with security and engineering teams to translate manual pentesting techniques into repeatable, automated workflows
- Continuously improve the organization's offensive automation framework and tooling
Requirements
- 5+ years of experience in offensive security, penetration testing, or security engineering roles
- At least 1 year of relevant leadership experience
- Expertise in exploit chaining and attack logic, including sequencing low-severity findings into high-impact compromises
- Proficiency in Python for writing custom exploits and automating complex multi-stage attack scripts
- Experience configuring and scaling continuous automated security validation tools such as Pentera, Cymulate, or Picus, including custom Pentest Robots architectures
- In-depth knowledge of the OSI model and core network protocols (DNS, BGP, TCP/IP)
- Understanding of web application vulnerabilities, including the OWASP Top 10 and API flaws such as IDOR
- Proven capability to engineer automated exploit scripts that safely validate vulnerabilities without crashing network infrastructure or corrupting production databases
- English proficiency at B1+ level or above
Nice to have
- Skills in Bash and/or Go for custom tooling and exploit development
- Familiarity with OAuth flows and programmatic handling of authentication
- Background in bypassing or automating Multi-Factor Authentication challenges
Lead APT & Automated Validation Engineer ยท EPAM Systems