26 sep
|
Epam Systems
|
México
26 sep
Epam Systems
México
We are looking for a Lead Application Security Engineer to lead application vulnerability remediation across teams, starting with HackerOne findings and API and GraphQL issues. You will own the end-to-end workflow from intake and validation to remediation tracking and closure across Cybersecurity, Engineering, Product, and vendors.
Responsibilities
- Own the daily operational execution of the HackerOne program
- Run vulnerability intake, triage, validation, assignment, tracking, and closure end to end
- Lead weekly operating reviews with HackerOne and internal stakeholders
- Track remediation commitments and reinforce accountability for delivery
- Manage coordinated disclosure and related communications
- Reproduce and validate reported vulnerabilities, evaluating exploitability and business impact
- Use Postman, browser tooling, and security testing tools to verify findings
- Support vulnerability prioritization based on customer and business risk
- Coordinate remediation work across multiple engineering organizations
- Identify service ownership and route findings correctly while maintaining Jira and ServiceNow tracking
- Escalate critical items and drive resolution for overdue work
- Deliver executive-ready reporting and dashboards on backlog trends, SLA compliance, remediation progress, and risk reduction
- Present status and outcomes to cybersecurity and engineering leadership
- Leverage GenAI and workflow automation to enhance triage, remediation tracking, reporting, and service ownership identification
Requirements
- Proven background with 5+ years of experience in Software Engineering or Application Security
- Solid understanding of REST APIs, GraphQL, and Authentication & Authorization mechanisms
- Working knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10
- Hands-on experience reproducing security findings
- Proficiency with Postman
- Practical experience using Jira and ServiceNow for tracking and workflow
- Strong stakeholder management skills across technical and non-technical teams
- English proficiency at B2 (Upper-Intermediate) level or higher
Nice to have
- Experience with HackerOne or other Bug Bounty programs
- Background in AppSec and penetration testing
- Full-stack software development experience
- Familiarity with Burp Suite
- Experience building or using GenAI automation
We offer
- International projects with top brands
- Work with global teams of highly skilled, diverse peers
- Healthcare benefits
- Employee financial programs
- Paid time off and sick leave
- Upskilling, reskilling and certification courses
- Unlimited access to the LinkedIn Learning library and 22,000+ courses
- Integral career opportunities
- Volunteer and community involvement opportunities
- EPAM Employee Groups
- Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn
EPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.
📌 Lead Application Security Engineer (México)
🏢 Epam Systems
📍 México