03 oct
|
Epam Systems
|
Ciudad de México
03 oct
Epam Systems
Ciudad de México
We are seeking a Senior Application Security Engineer to own and drive application security vulnerability remediation programs, with an initial focus on Hacker One bug bounty findings, API security vulnerabilities, Graph QL authorization issues, and cross-functional remediation tracking. This role serves as the operational owner of the vulnerability remediation lifecycle, coordinating across Cybersecurity, Engineering, Product, and external vendors to ensure timely identification, validation, assignment, remediation, and closure of security findings. Responsibilities Own day-to-day management of the Hacker One program Manage vulnerability intake, triage, validation, routing, tracking, and closure Coordinate weekly operating reviews with Hacker One and internal stakeholders Track remediation commitments and drive accountability Manage disclosure and communication processes Reproduce and validate reported vulnerabilities, assessing exploitability and business impact Utilize Postman, browser tooling, and security testing tools to validate findings Support vulnerability prioritization based on customer and business risk Coordinate remediation efforts across multiple engineering organizations Identify service ownership and route findings appropriately, maintaining Jira and Service Now tracking Escalate critical and overdue items Produce executive-level reporting and dashboards, tracking backlog trends, SLA compliance, remediation progress,
and risk reduction Present status updates to cybersecurity and engineering leadership Leverage Gen AI and workflow automation to improve triage, remediation tracking, reporting, and service ownership identification Requirements3+ years of experience in Software Engineering or Application Security Understanding of REST APIs, Graph QL, and Authentication & Authorization mechanisms Knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10 Experience reproducing security findings Proficiency in Postman Experience with Jira and Service Now Strong stakeholder management skills English proficiency at B2 level or higher Nice to have Background in Hacker One or Bug Bounty programs Experience in App Sec and penetration testing Full-stack software development background Familiarity with Burp Suite Experience with Gen AI automation We offer International projects with top brands Work with integral teams of highly skilled, diverse peers Healthcare benefits Employee financial programs Paid time off and sick leave Upskilling, reskilling and certification courses Unlimited access to the Linked In Learning library and 22,000+ courses Global career opportunities Volunteer and community involvement opportunities EPAM Employee Groups Award-winning culture recognized by Glassdoor, Newsweek and Linked In EPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.
#J-18808-Ljbffr
📌 Senior application security engineer (Ciudad de México)
🏢 Epam Systems
📍 Ciudad de México