2023-04-13 14:47:21

Senior Security Testing Engineer

EPAM Systems, SIA
3600 - 5500 €/m Gross
Occasional remote work possibility

Job Description

We are seeking a Senior Security Testing Engineer to perform security assessments, application security reviews, and penetration testing for SaaS services and on-prem solutions focused on DNS/DHCP protocols, while collaborating with development teams to strengthen secure coding practices and embed threat modeling throughout the software development lifecycle.

This position offers hybrid setup with the flexibility to work from any location in Lithuania, whether it's your home or our dynamic offices in Vilnius and Kaunas.

  • Perform security assessments, application security reviews, and penetration testing for SaaS services and on-prem solutions focused around DNS/DHCP protocol
  • Collaborate with development teams to enforce secure coding practices, guidelines, and standards
  • Ensure integration of security requirements and threat modeling considerations into the software development lifecycle
  • Offer guidance and support during security-related discussions and decision-making processes
  • Provide guidance on secure design principles and assist in addressing security issues
  • Plan, execute, and analyze application security testing, including penetration testing, vulnerability scanning, and code reviews
  • Interpret penetration test results and recommend remediation measures based on identified threats
  • Design and implement effective security controls, such as access controls, authentication mechanisms, encryption, and secure communication protocols, together with development teams
  • Utilize threat modeling outputs to guide security control selection and implementation
  • Stay up-to-date with emerging security threats, vulnerabilities, and best practices in application security and threat modeling
  • Educate development teams on secure coding practices, common vulnerabilities, and security best practices
  • Conduct security training sessions and workshops to raise awareness of threat modeling concepts and foster a security-conscious culture

Requirements

  • 5+ years of experience in vulnerability management and penetration testing
  • Knowledge of application security principles, threat modeling methodologies, and best practices
  • Proficiency in secure coding practices, vulnerability assessment, and penetration testing methodologies
  • Skills in Shell Scripts, Python, or Golang
  • Familiarity with cloud environments like AWS, GCP, and Azure, and technologies like Kubernetes and Containers
  • Familiarity with common web application vulnerabilities (e.g., OWASP Web/API Top 10) and corresponding mitigation techniques
  • Experience with implementing and managing security testing tools and technologies, such as static analysis tools, dynamic application scanners, and penetration testing frameworks
  • Understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into agile development processes with SAST & DAST tools (Coverity, CodeQL, SonarQube, Contrast)
  • Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols
  • Familiarity with industry standards and frameworks such as ISO 27001, NIST, PCI DSS, and GDPR
  • Excellent communication and collaboration skills, with the ability to effectively communicate technical concepts to non-technical stakeholders
  • MS/M.tech or BS/B.tech in Computer Science or related field, or equivalent work experience required

Nice to have

  • Relevant certifications (e.g CISSP, CSSLP, CEH, OSCP, OSWE)
  • Understanding of cyber security frameworks like OWASP, SANS, NIST, CIS

Company offers

  • Engineering Heritage: Best-in-class experts sharing a culture of engineering excellence and tackling complex engineering challenges for over 30 years
  • Advanced Tech Stack: Innovative projects where you can apply or enhance your expertise in Cloud, Data, AI, and other emerging technologies
  • World-Class Clients: Work closely with 340+ of the Forbes Global 2000 on creating disruptive solutions that make a global impact
  • Professional Growth: Exceptional support for career development with comprehensive resources for upskilling or reskilling in pioneering practices
  • GenAI Community: Strong AI competencies with 600+ experts across 55+ locations driving GenAI-enabled transformation journeys
  • Entrepreneurial Culture: If you're passionate and dedicated to improving business transformation, we provide the support you need to bring your ideas to life
  • Hybrid Setup: The flexibility to work from any location in Lithuania, whether it's your home or our dynamic offices in Vilnius and Kaunas
  • Other Benefits: Additional vacation and trust days, private health insurance, Employee Stock Purchase Plan and more