×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Lead Application Security Engineer

Job in Los Angeles, Los Angeles County, California, 90079, USA
Listing for: EPAM Systems, Inc.
Full Time position
Listed on 2026-10-03
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 140000 - 210000 USD Yearly USD 140000.00 210000.00 YEAR
Job Description & How to Apply Below
We are looking for a Lead Application Security Engineer to lead application vulnerability remediation across teams, starting with Hacker One findings and API and GraphQL issues. You will own the end-to-end workflow from intake and validation to remediation tracking and closure across Cybersecurity, Engineering, Product, and vendors.

Responsibilities Own the daily operational execution of the Hacker One program

Run vulnerability intake, triage, validation, assignment, tracking, and closure end to endLead weekly operating reviews with Hacker One and internal stakeholders

Track remediation commitments and reinforce accountability for delivery

Manage coordinated disclosure and related communications

Reproduce and validate reported vulnerabilities, evaluating exploitability and business impact

Use Postman, browser tooling, and security testing tools to verify findings

Support vulnerability prioritization based on customer and business risk Coordinate remediation work across multiple engineering organizations

Identify service ownership and route findings correctly while maintaining Jira and Service Now tracking

Escalate critical items and drive resolution for overdue work Deliver executive-ready reporting and dashboards on backlog trends, SLA compliance, remediation progress, and risk reduction

Present status and outcomes to cybersecurity and engineering leadership

Leverage GenAI and workflow automation to enhance triage, remediation tracking, reporting, and service ownership identification

Requirements

Proven background with 5+ years of experience in Software Engineering or Application Security Solid understanding of REST APIs, GraphQL, and Authentication & Authorization mechanisms

Working knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10

Hands-on experience reproducing security findings

Proficiency with Postman Practical experience using Jira and Service Now for tracking and workflow

Strong stakeholder management skills across technical and non-technical teams

English proficiency at B2 (Upper-Intermediate) level or higher

Nice to have

Experience with Hacker One or other Bug Bounty programs

Background in App Sec and penetration testing

Full-stack software development experience

Familiarity with Burp Suite Experience building or using GenAI automation

We offer

International projects with top brands

Work with global teams of highly skilled, diverse peers

Healthcare benefits

Employee financial programs

Paid time off and sick leave

Upskilling, reskilling and certification courses

Unlimited access to the Linked In Learning library and 22,000+ courses

Global career opportunities

Volunteer and community involvement opportunitiesEPAM Employee Groups Award-winning culture recognized by Glassdoor, Newsweek and Linked In
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary