Lead Application Security Engineer

Company: EPAM Systems
Location: Argentina, Brazil, Chile, Colombia, Mexico
Type: remote
Posted: Sep 29, 2026
Views: 0

We are looking for a Lead Application Security Engineer to lead application vulnerability remediation across teams, starting with HackerOne findings and API and GraphQL issues. You will own the end-to-end workflow from intake and validation to remediation tracking and closure across Cybersecurity, Engineering, Product, and vendors.

Responsibilities

  • Own the daily operational execution of the HackerOne program
  • Run vulnerability intake, triage, validation, assignment, tracking, and closure end to end
  • Lead weekly operating reviews with HackerOne and internal stakeholders
  • Track remediation commitments and reinforce accountability for delivery
  • Manage coordinated disclosure and related communications
  • Reproduce and validate reported vulnerabilities, evaluating exploitability and business impact
  • Use Postman, browser tooling, and security testing tools to verify findings
  • Support vulnerability prioritization based on customer and business risk
  • Coordinate remediation work across multiple engineering organizations
  • Identify service ownership and route findings correctly while maintaining Jira and ServiceNow tracking
  • Escalate critical items and drive resolution for overdue work
  • Deliver executive-ready reporting and dashboards on backlog trends, SLA compliance, remediation progress, and risk reduction
  • Present status and outcomes to cybersecurity and engineering leadership
  • Leverage GenAI and workflow automation to enhance triage, remediation tracking, reporting, and service ownership identification

Requirements

  • Proven background with 5+ years of experience in Software Engineering or Application Security
  • Solid understanding of REST APIs, GraphQL, and Authentication & Authorization mechanisms
  • Working knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10
  • Hands-on experience reproducing security findings
  • Proficiency with Postman
  • Practical experience using Jira and ServiceNow for tracking and workflow
  • Strong stakeholder management skills across technical and non-technical teams
  • English proficiency at B2 (Upper-Intermediate) level or higher

Nice to have

  • Experience with HackerOne or other Bug Bounty programs
  • Background in AppSec and penetration testing
  • Full-stack software development experience
  • Familiarity with Burp Suite
  • Experience building or using GenAI automation

Benefits

  • International projects with top brands
  • Work with global teams of highly skilled, diverse peers
  • Healthcare benefits
  • Employee financial programs
  • Paid time off and sick leave
  • Upskilling, reskilling and certification courses
  • Unlimited access to the LinkedIn Learning library and 22,000+ courses
  • Global career opportunities
  • Volunteer and community involvement opportunities
  • EPAM Employee Groups
  • Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn

About the Company

Name: EPAM Systems

No detailed information available about this company.

More jobs at EPAM Systems