Back to search
EPAM Systems Linkedin · Posted yesterday

Lead Security Engineer

Colombia

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.

We are seeking a Lead Security Engineer to become part of our team. This position calls for working autonomously alongside the client team, including senior leadership on the client side, paired with a proactive mindset. It is a completely hands-on role involving daily engagement across numerous issues, making the ability to prioritize work, clear obstacles, and communicate across teams just as vital as technical expertise. Being proactive in this role means continuously working to elevate security standards while improving, updating, and expanding processes, security pipelines, and alerting systems.

Responsibilities

  • Assist with vulnerability management across applications and microservices
  • Offer direction on secure authentication, authorization, secrets management, and data protection
  • Assess, improve, and suggest application security automation within CI/CD pipelines to catch and fix security issues early
  • Track, review, and triage alerts and logs from a range of security platforms, including Security Scorecard and other third-party monitoring tools
  • Handle triage, remediation, and escalation of security alerts, events, and reports
  • Keep up to date on emerging threats, vulnerabilities, and attacker behaviors, using this insight to strengthen detection and response
  • Assist with responding to and resolving vulnerabilities surfaced through the penetration testing program
  • Partner with Engineering, IT, Infrastructure, and Compliance teams to roll out security controls aligned with frameworks like NIST, HITRUST, and CIS
  • Uphold production security procedures and track relevant metrics
  • Research and build enhanced security training materials
  • Operate independently to meet goals defined by leadership, while contributing effectively within a team setting
  • Push continuous improvement by spotting automation opportunities, incorporating emerging best practices, and boosting detection and response capabilities
  • Assess and apply AI/LLM based tooling to speed up triage, deduplicate and correlate findings across scanners, prioritize based on exploitability and business context, and draft remediation guidance while keeping human review in the loop

Requirements

  • At least 5 years of relevant experience
  • A minimum of one year of experience leading and managing development teams
  • Background in application security or comparable security roles
  • Strong expertise in cloud environments
  • Familiarity with software development lifecycle (SDLC) processes and source control technologies
  • Experience with supply chain security, including dependency management and SBOMs
  • Exposure to container and CI/CD security, such as Kubernetes and GitHub Actions
  • Exposure to offensive security practices and penetration testing certifications, such as OSWE or OSCP+, viewed as highly desirable
  • Comfortable creating detection queries and scripts
  • Familiarity with regulatory frameworks such as SOC 2 and CIS
  • Understanding of common attack vectors and the MITRE ATT&CK framework
  • Strong problem-solving abilities and the capacity to succeed in a fast-paced, team-oriented environment
  • Experience with AWS, GCP, or CDN/edge security tools and services regarded as a plus
  • Experience with automation frameworks or scripting using PowerShell or Bash
  • Security certifications such as Security+, CEH, or equivalent
  • Excellent English proficiency (B2 level or higher)

Nice to have

  • Experience working with or reporting to a CISO
  • Development experience in a modern programming language, such as Python or Go
  • Familiarity with the HITRUST framework
  • Experience with SSO platforms, such as Okta and SAML

We offer

  • International projects with top brands
  • Work with global teams of highly skilled, diverse peers
  • Healthcare benefits
  • Employee financial programs
  • Paid time off and sick leave
  • Upskilling, reskilling and certification courses
  • Unlimited access to the LinkedIn Learning library and 22,000+ courses
  • Global career opportunities
  • Volunteer and community involvement opportunities
  • EPAM Employee Groups
  • Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn

EPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search