ES
Senior Application Security Engineer
EPAM Systems
๐ฆ๐ท Argentina | ๐ง๐ท Brazil | ๐จ๐ฑ Chile | ๐จ๐ด Colombia | ๐ฒ๐ฝ Mexico
Remote
Senior
17 hours ago
- HackerOne
- Bug Bounty
- GraphQL
- triage
- Postman
- Jira
- ServiceNow
- Machine Learning
- REST API
- OAuth
- JWT
- OWASP
- AppSec
- Penetration Testing
- Burp Suite
17 hours ago
We are seeking aSenior Application Security Engineer to own and drive application security vulnerability remediation programs, with an initial focus on HackerOne bug bounty findings, API security vulnerabilities, GraphQL authorization issues, and cross-functional remediation tracking. This role serves as the operational owner of the vulnerability remediation lifecycle, coordinating across Cybersecurity, Engineering, Product, and external vendors to ensure timely identification, validation, assignment, remediation, and closure of security findings.
Responsibilities
- Own day-to-day management of the HackerOne program
- Manage vulnerability intake, triage, validation, routing, tracking, and closure
- Coordinate weekly operating reviews with HackerOne and internal stakeholders
- Track remediation commitments and drive accountability
- Manage disclosure and communication processes
- Reproduce and validate reported vulnerabilities, assessing exploitability and business impact
- Utilize Postman, browser tooling, and security testing tools to validate findings
- Support vulnerability prioritization based on customer and business risk
- Coordinate remediation efforts across multiple engineering organizations
- Identify service ownership and route findings appropriately, maintaining Jira and ServiceNow tracking
- Escalate critical and overdue items
- Produce executive-level reporting and dashboards, tracking backlog trends, SLA compliance, remediation progress, and risk reduction
- Present status updates to cybersecurity and engineering leadership
- Leverage GenAI and workflow automation to improve triage, remediation tracking, reporting, and service ownership identification
Requirements
- 3+ years of experience in Software Engineering or Application Security
- Understanding of REST APIs, GraphQL, and Authentication & Authorization mechanisms
- Knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10
- Experience reproducing security findings
- Proficiency in Postman
- Experience with Jira and ServiceNow
- Strong stakeholder management skills
- English proficiency at B2 level or higher
Nice to have
- Background in HackerOne or Bug Bounty programs
- Experience in AppSec and penetration testing
- Full-stack software development background
- Familiarity with Burp Suite
- Experience with GenAI automation
Senior Application Security Engineer ยท EPAM Systems