{"id":1153020,"url":"https://alion.io/job/epam-poland-senior-application-security-testing-engineer","title":"Senior Application Security Testing Engineer","company":{"id":2612641,"name":"Epam Poland","domain":"epam-poland.pl","url":"https://alion.io/company/epam-poland","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"inferred","locations":["Warsaw, Poland"],"countries":["PL"],"hiring_countries":["PL"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":56000,"max_usd":108000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":13},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"AWS","optional":false},{"name":"Node JS","optional":false},{"name":"OWASP","optional":false},{"name":"TypeScript","optional":false},{"name":"Agile","optional":true},{"name":"Anthropic","optional":true},{"name":"Azure","optional":true},{"name":"CI/CD","optional":true},{"name":"GCP","optional":true},{"name":"JavaScript","optional":true},{"name":"Platform Engineering","optional":true}],"status":"live","first_seen_at":"2026-09-23T18:10:22Z","employer_posted_date":null,"last_verified_at":"2026-09-23T18:10:22Z","board_verified":false,"closed_at":null,"days_open":2,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":2},"description":"We are looking for a Senior Application Security Testing Engineer to join our ever-growing Security team. In this role, you will assess and strengthen the security posture of applications and systems, working closely with engineering teams to embed security best practices throughout the development lifecycle.\nResponsibilities\nConduct regular scanning and manual security testing of web applications to identify vulnerabilities\nTrack identified issues through to remediation, working closely with development teams to ensure timely fixes\nPerform code-level reviews to identify insecure coding practices and recommend improvements\nSupport and strengthen IaaS security across cloud environments, with a particular focus on AWS\nAssess cloud configurations against security best practice and industry benchmarks\nWork within a hybrid cloud environment to implement and operate appropriate security technologies and controls\nResearch emerging security threats, vulnerabilities, and exploit techniques relevant to the technology stack\nRespond promptly to newly identified threats and support the implementation of new security requirements\nContribute to incident response activities as required, maintaining the confidentiality of all investigation information\nProvide technical guidance and oversight to developers on secure coding practices and application security standards\nChampion OWASP principles across the organization, embedding them into the design and development of new solutions\nCollaborate closely with cross-functional teams, contributing a security-first mindset to product and engineering discussions\nRequirements\nBachelor's Degree, preferably in a technical discipline such as Information Systems, Computer Science, or a related field\nA minimum of 3 years' demonstrated experience in manual security testing\nUnderstanding of security protocols, cryptography, authentication, and authorization, along with general application security requirements\nKnowledge of at least one object-oriented programming language, such as Node.js or TypeScript\nExperience implementing and operating security technologies and processes within a hybrid cloud environment, particularly AWS\nExpertise in OWASP concepts and their practical application across varied solutions\nUnderstanding of IT operations and service support processes\nExcellent communication skills, with the ability to translate technical security concepts for non-technical stakeholders\nEnglish proficiency at B2 level or higher\nNice to have\nRelevant security certifications, such as CISSP, GIAC, CEH, Security+, or CSSLP\nPrior experience working within a fast-paced, product-led, or e-commerce technology environment\nFamiliarity with automated security scanning and CI/CD pipeline integration\nWe offer\nWe gather like-minded people:\nTop tech minds driving innovation in AI, cloud and digital platform modernization\nSupportive team and agile, startup-like culture\nHybrid by design mode and opportunity to work remotely within Poland\nChance to work abroad for up to 60 days annually\nBusiness-driven relocation opportunities\n\nWe provide growth opportunities:\nCareer development programs\nThought leadership, mentoring, soft skills and well-being programs\nCertification (Anthropic, Gemini, GCP, Azure, AWS)\nEnglish classes\n\nWe cover it all:\nStable pay\nParticipation in the Employee Stock Purchase Plan with a 15% discount\nBenefits package (health insurance, multisport, shopping vouchers)\nReferral bonuses up to $2,000\nOffices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and more\nCorporate, social and well-being events\n\nPlease, note:\nBenefits listed above are available to employees only\nWe are open for working with Contractors. Terms of B2B cooperation agreements are agreed individually\nWe will reach out to selected candidates exclusively\n\nEPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.","description_format":"text","description_chars":4202,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"Upper-Intermediate (B2)","optional":false}]},"benefits":["Growth opportunities","Health insurance"],"hiring_locations":[{"name":"Poland","iso":"PL","kind":"country"}],"hiring_excludes":[],"relocation_offered":true,"industries":["Application Security"],"lifecycle":[{"event":"open","at":"2026-09-23T18:53:57Z"}],"liveness":{"score":90,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.903,"p_room":1,"age_days":1,"expected_fill_days":34,"reasons":["seen:1","velocity","win:early"],"computed_at":"2026-09-25T05:45:01Z"},"pay":null,"html_url":"https://alion.io/job/epam-poland-senior-application-security-testing-engineer","json_url":"https://alion.io/job/epam-poland-senior-application-security-testing-engineer.json","meta":{"generated_at":"2026-09-26T02:06:29Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2106,"day_limit":5000,"remaining_today":2894,"minute_limit":60,"resets_at":"2026-09-27T00:00:00Z"}}}