Lead Security Testing Engineer w Łódź, Polska is listed on Jobeax. Browse 110,000+ vacancies available.
We are looking for a Lead Security Testing Engineer to drive security assessments, penetration testing, and vulnerability management efforts across SaaS services and on-prem solutions focused on DNS/DHCP protocols. The ideal candidate will bring deep technical expertise in application security, threat modeling, and secure development practices, while guiding teams toward building more resilient and secure systems. Responsibilities Perform security assessments, application security reviews, and penetration testing for SaaS services and on-prem solutions centered on DNS/DHCP protocolReview vulnerability findings from SAST, DAST, SCA, container, secrets, and infrastructure security scanning tools, and define appropriate validation approachesValidate security remediations across applications, platforms, cloud services, infrastructure components, and development toolchains to ensure vulnerabilities are effectively addressed and root causes eliminatedPlan, execute, and analyze application security testing, including penetration testing, vulnerability scanning, and code reviewsInterpret penetration test results and recommend remediation measures based on identified threatsCollaborate with development teams to enforce secure coding practices, guidelines, and standardsIntegrate security requirements and threat modeling considerations into the software development lifecycleProvide guidance on secure design principles and support security-related discussions and decision-making processesWork closely with development teams to design and implement effective security controls, such as access controls, authentication mechanisms, encryption, and secure communication protocolsUtilize threat modeling outputs to guide security control selection and implementationEducate development teams on secure coding practices, common vulnerabilities, and security best practices through training sessions and workshopsAnalyze security test results, document findings, and provide clear evidence supporting vulnerability closure, risk acceptance, or remediation gaps Requirements 5+ years of experience in vulnerability management and penetration testingKnowledge of application security principles, threat modeling methodologies, and best practicesProficiency in secure coding practices, vulnerability assessment, and penetration testing methodologiesBackground in Shell Scripts, Python, or Golang developmentFamiliarity with cloud environments such as AWS, GCP, Azure, and technologies like Kubernetes and ContainersFamiliarity with common web application vulnerabilities (e.g., OWASP Web/API Top 10) and corresponding mitigation techniquesExperience implementing and managing security testing tools, such as static analysis tools, dynamic application scanners, and penetration testing frameworksUnderstanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into agile development processes with SAST and DAST tools (Coverity, CodeQL, SonarQube, Contrast)Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocolsFamiliarity with industry standards and frameworks such as ISO 27001, NIST, PCI DSS, and GDPRExcellent communication and collaboration skills, with the ability to effectively communicate technical concepts to non-technical stakeholdersMS/M.Tech or BS/B.Tech in Computer Science or related field, or equivalent work experience requiredEnglish proficiency at B2 level or higher Nice to have CISSP, CSSLP, CEH, OSCP, OSWE certificationsUnderstanding of cyber security frameworks like OWASP, SANS, NIST, CIS We offer We gather like-minded people:Top tech minds driving innovation in AI, cloud and digital platform modernizationSupportive team and agile, startup-like cultureHybrid by design mode and opportunity to work remotely within PolandChance to work abroad for up to 60 days annuallyBusiness-driven relocation opportunitiesWe provide growth opportunities:Career development programsThought leadership, mentoring, soft skills and well-being programsCertification (Anthropic, Gemini, GCP, Azure, AWS)English classesWe cover it all:Stable payParticipation in the Employee Stock Purchase Plan with a 15% discountBenefits package (health insurance, multisport, shopping vouchers)Referral bonuses up to $2,000Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and moreCorporate, social and well-being eventsPlease, note:Benefits listed above are available to employees onlyWe are open for working with Contractors. Terms of B2B cooperation agreements are agreed individuallyWe will reach out to selected candidates exclusively EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.