×
Register Here to Apply for Jobs or Post Jobs. X

Senior Application Security Engineer

Job in Washington, District of Columbia, 20022, USA
Listing for: EPAM Systems, Inc.
Full Time position
Listed on 2026-10-04
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 120000 - 180000 USD Yearly USD 120000.00 180000.00 YEAR
Job Description & How to Apply Below
We are seeking a Senior Application Security Engineer to own and drive application security vulnerability remediation programs, with an initial focus on Hacker One bug bounty findings, API security vulnerabilities, GraphQL authorization issues, and cross-functional remediation tracking. This role serves as the operational owner of the vulnerability remediation lifecycle, coordinating across Cybersecurity, Engineering, Product, and external vendors to ensure timely identification, validation, assignment, remediation, and closure of security findings.

Responsibilities Own day-to-day management of the Hacker One program

Manage vulnerability intake, triage, validation, routing, tracking, and closure

Coordinate weekly operating reviews with Hacker One and internal stakeholders

Track remediation commitments and drive accountability

Manage disclosure and communication processes

Reproduce and validate reported vulnerabilities, assessing exploitability and business impact

Utilize Postman, browser tooling, and security testing tools to validate findings

Support vulnerability prioritization based on customer and business risk Coordinate remediation efforts across multiple engineering organizations

Identify service ownership and route findings appropriately, maintaining Jira and Service Now tracking

Escalate critical and overdue items

Produce executive-level reporting and dashboards, tracking backlog trends, SLA compliance, remediation progress, and risk reduction

Present status updates to cybersecurity and engineering leadership

Leverage GenAI and workflow automation to improve triage, remediation tracking, reporting, and service ownership identification

Requirements3+ years of experience in Software Engineering or Application Security Understanding of REST APIs, GraphQL, and Authentication & Authorization mechanisms

Knowledge of OAuth, JWT, OWASP Top 10, and API Security Top 10

Experience reproducing security findings

Proficiency in Postman

Experience with Jira and Service Now Strong  stakeholder management skills

English proficiency at B2 level or higher

Nice to have Background in Hacker One or Bug Bounty programs

Experience in App Sec and penetration testing

Full-stack software development background

Familiarity with Burp Suite

Experience with GenAI automation

We offer

International projects with top brands

Work with global teams of highly skilled, diverse peers

Healthcare benefits

Employee financial programs

Paid time off and sick leave

Upskilling, reskilling and certification courses

Unlimited access to the Linked In Learning library and 22,000+ courses

Global career opportunities

Volunteer and community involvement opportunitiesEPAM Employee Groups Award-winning culture recognized by Glassdoor, Newsweek and Linked In
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary