Jobiglo

Sin resultados.

Lead Security Engineer

EPAM Systems

Senior 🇬🇧 English
kubernetes github actions sbom dependency management vulnerability management security automation nist hitrust cis soc 2 mitre att&ck oswe oscp+

Descripcion del puesto

About the role

We are looking for a Lead Security Engineer to work autonomously with client senior leadership, driving security improvements across applications, micro‑services and cloud environments. The role is fully hands‑on, requiring you to prioritize work, clear obstacles and communicate effectively across engineering, IT and compliance teams.

Key responsibilities

  • Manage vulnerability remediation for applications and micro‑services.
  • Define secure authentication, authorization, secrets management and data‑protection strategies.
  • Design and embed security automation in CI/CD pipelines (e.g., Kubernetes, GitHub Actions) to detect and fix issues early.
  • Tri­age, investigate and escalate alerts from platforms such as Security Scorecard and other monitoring tools.
  • Stay current on emerging threats, attacker tactics and incorporate findings into detection and response processes.
  • Support penetration‑testing remediation and guide the creation of security training material.
  • Collaborate with Engineering, IT, Infrastructure and Compliance to implement controls aligned with NIST, HITRUST, CIS and SOC 2 frameworks.
  • Research and apply AI/LLM‑based tooling to accelerate triage, deduplication and remediation guidance.

Required profile

  • Minimum 5 years of relevant security experience, including at least 1 year leading development teams.
  • Strong background in application security, cloud environments and supply‑chain security (SBOM, dependency management).
  • Hands‑on experience with container security, Kubernetes and CI/CD tools such as GitHub Actions.
  • Familiarity with offensive security practices and certifications (OSWE, OSCP+ preferred).
  • Knowledge of regulatory frameworks (SOC 2, NIST, HITRUST, CIS) and the MITRE ATT&CK matrix.

Required skills

  • Cloud security (AWS, Azure, GCP)
  • Kubernetes and container security
  • CI/CD pipeline security (GitHub Actions)
  • Software‑bill‑of‑materials (SBOM) and dependency management
  • Vulnerability management and remediation
  • Security automation and detection query scripting
  • AI/LLM tooling for security triage
  • Framework compliance (NIST, HITRUST, CIS, SOC 2)
  • MITRE ATT&CK knowledge
  • Offensive security certifications (OSWE, OSCP+)

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec EPAM Systems.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Por que reporta esta oferta?

Gracias por su reporte. Revisaremos esta oferta.

Postula en 30 segundos

Ingresa tu email para postular. Se creara una cuenta automaticamente.

Al continuar, aceptas nuestras condiciones de uso.

Ya tienes cuenta? Iniciar sesion

💬 Escríbenos en Telegram Chatear por WhatsApp

Publicado hace 1 mes

Expira en 2 semanas

29 vistas · 0 interested

Aumenta tus posibilidades

Sube tu CV: te propondremos las ofertas que coinciden con tu perfil.

Analizando tu CV...

EPAM Systems