EPAM Systems
Senior Application Security Engineer (Application Security)
EPAM SystemsQatar10 hours ago
Full-timeBusiness Development, Information Technology +1

EPAM is seeking an experienced Senior Application Security Engineer to join our dynamic security team in Qatar. In this role, you will focus on threat modeling and security code review, working closely with offensive security engineers. Our team employs a dual approach: offensive engineers conduct blackbox testing, while application security engineers perform source code examination and threat modeling. Collaboration between teams is essential to enrich findings and deliver comprehensive remediation plans.

 

Responsibilities

  • Conduct threat modeling and security code reviews for web and enterprise applications
  • Collaborate with offensive security engineers to correlate blackbox and whitebox testing results
  • Analyze application architectures, data flow diagrams and source code to identify security vulnerabilities
  • Develop and document comprehensive remediation plans based on combined testing results
  • Act as a Security Champion within development teams, promoting secure coding practices and awareness
  • Participate in the design and implementation of secure development processes
  • Communicate findings and recommendations to both technical and non-technical stakeholders

 

Requirements

  • 7 + years of experience in application security, with a focus on threat modeling and security code review
  • Bachelor’s degree in computer science, information security or a related field
  • Strong understanding of secure development practices and common application vulnerabilities
  • Experience working with development teams and offensive security engineers
  • Familiarity with data flow diagrams and application architecture analysis
  • Experience with modern web frameworks (e.g., Angular) is a plus
  • Excellent communication and documentation skills

 

Nice to have

  • Experience as a Security Champion within development teams
  • Hands-on experience with security development lifecycle (S-SDLC) processes
  • Knowledge of both blackbox and whitebox testing methodologies
  • Experience in developing or reviewing applications built with Angular or similar frameworks

 

We offer

  • Private healthcare and life insurance
  • End of service gratuity
  • Annual air travel tickets for expatriates
  • Corporate Programs including Employee Referral Program with rewards
  • Learning and development opportunities including in-house training and coaching, professional certifications, over 22,000 courses on LinkedIn Learning Solutions and much more
  • *All benefits and perks are subject to certain eligibility requirements

Key Skills

Ranked by relevance