Unlock Full Resume Report
ATS Pass
Missing keywords
Tailored AI suggestions
Job match analysis
Interview-focused insights
New offer - be the first one to apply!
September 3, 2026
Lead Security Testing Engineer
Senior • Remote
Katowice, SL, Poland
Apply now
We are looking for a Lead Security Testing Engineer to drive security assessments, penetration testing, and vulnerability management efforts across SaaS services and on-prem solutions focused on DNS/DHCP protocols. The ideal candidate will bring deep technical expertise in application security, threat modeling, and secure development practices, while guiding teams toward building more resilient and secure systems.
Quick Facts
- Hybrid-by-design work mode and opportunity to work remotely within Poland
- Opportunity to work abroad for up to 60 days annually
- Business-driven relocation opportunities
- Open to working with contractors; B2B cooperation terms are agreed individually
- Benefits listed are available to employees only
- Only selected candidates will be contacted
Responsibilities
- Perform security assessments, application security reviews, and penetration testing for SaaS services and on-prem solutions centered on DNS/DHCP protocol.
- Review vulnerability findings from SAST, DAST, SCA, container, secrets, and infrastructure security scanning tools, and define appropriate validation approaches.
- Validate security remediations across applications, platforms, cloud services, infrastructure components, and development toolchains to ensure vulnerabilities are effectively addressed and root causes eliminated.
- Plan, execute, and analyze application security testing, including penetration testing, vulnerability scanning, and code reviews.
- Interpret penetration test results and recommend remediation measures based on identified threats.
- Collaborate with development teams to enforce secure coding practices, guidelines, and standards.
- Integrate security requirements and threat modeling considerations into the software development lifecycle.
- Provide guidance on secure design principles and support security-related discussions and decision-making processes.
- Work closely with development teams to design and implement effective security controls, such as access controls, authentication mechanisms, encryption, and secure communication protocols.
- Utilize threat modeling outputs to guide security control selection and implementation.
- Educate development teams on secure coding practices, common vulnerabilities, and security best practices through training sessions and workshops.
- Analyze security test results, document findings, and provide clear evidence supporting vulnerability closure, risk acceptance, or remediation gaps.
Requirements
- 5+ years of experience in vulnerability management and penetration testing.
- Knowledge of application security principles, threat modeling methodologies, and best practices.
- Proficiency in secure coding practices, vulnerability assessment, and penetration testing methodologies.
- Background in Shell Scripts, Python, or Golang development.
- Familiarity with cloud environments such as AWS, GCP, Azure, and technologies like Kubernetes and Containers.
- Familiarity with common web application vulnerabilities, including OWASP Web/API Top 10, and corresponding mitigation techniques.
- Experience implementing and managing security testing tools, such as static analysis tools, dynamic application scanners, and penetration testing frameworks.
- Understanding of secure software development lifecycle (SDLC) and ability to integrate security practices and threat modeling into agile development processes with SAST and DAST tools (Coverity, CodeQL, SonarQube, Contrast).
- Knowledge of authentication, authorization, and access control mechanisms, cryptographic algorithms, and secure network communication protocols.
- Familiarity with industry standards and frameworks such as ISO 27001, NIST, PCI DSS, and GDPR.
- Excellent communication and collaboration skills, with the ability to effectively communicate technical concepts to non-technical stakeholders.
- MS/M.Tech or BS/B.Tech in Computer Science or related field, or equivalent work experience.
- English proficiency at B2 level or higher.
Nice to Have
- CISSP, CSSLP, CEH, OSCP, or OSWE certifications.
- Understanding of cybersecurity frameworks such as OWASP, SANS, NIST, and CIS.
Benefits
- Career development programs.
- Thought leadership, mentoring, soft skills, and well-being programs.
- Certification opportunities: Anthropic, Gemini, GCP, Azure, and AWS.
- English classes.
- Stable pay.
- Participation in the Employee Stock Purchase Plan with a 15% discount.
- Benefits package including health insurance, multisport, and shopping vouchers.
- Referral bonuses up to $2,000.
- Offices with entertainment and relaxation zones, table tennis and football, free snacks, coffee, and more.
- Corporate, social, and well-being events.
Similar jobs you might like

Lead Security Testing Engineer
EPAM Systems
Senior
Technology
Poznan, Poland · Remote
N/A
23m ago

Lead Security Testing Engineer
EPAM Systems
Senior
Technology
Wroclaw, DS, Poland · Remote
N/A
23m ago

Lead Security Testing Engineer
EPAM Systems
Senior
Technology
Krakow, MA, Poland · Remote
N/A
23m ago

Lead Security Testing Engineer
EPAM Systems
Senior
Technology
Gdansk, PM, Poland · Remote
N/A
23m ago

Lead Security Testing Engineer
EPAM Systems
Senior
Technology
Warsaw, Poland · Remote
N/A
23m ago

Lead Security Testing Engineer
EPAM Systems
Senior
Technology
Lodz, LD, Poland · Remote
N/A
23m ago

Lead AI Security Engineer
EPAM Systems
Senior
Technology
Wroclaw, DS, Poland · Remote
N/A
1 days ago

Lead AI Security Engineer
EPAM Systems
Senior
Technology
Warsaw, Poland · Remote
N/A
1 days ago

Lead AI Security Engineer
EPAM Systems
Senior
Technology
Poznań, WP, Poland · Remote
N/A
1 days ago

Lead AI Security Engineer
EPAM Systems
Senior
Technology
Katowice, Poland · Remote
N/A
1 days ago