Live opening · Posted 23 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
EPAM is a leading global provider of digital platform engineering and development services. We are committed to having a positive impact on our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to continuously learn and grow. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential.
We are looking for a Lead-level Security Engineer to strengthen container and supply chain security through automation and hands-on remediation. You will harden container images, secure Kubernetes workloads, and build tooling that turns scan results into tested fixes.
Responsibilities
Build and maintain hardened container base images with automated testing for development and production use
Implement Kubernetes security controls including runtime monitoring, network policies, and admission policies
Secure software supply chain workflows across build pipelines, registries, and infrastructure configuration
Create and evolve security automation tools and services using Go
Triage vulnerabilities from pentests, SAST, DAST, and SCA to separate real risk from noise
Partner with engineering teams to prioritize findings and commit remediation patches and dependency upgrades
Automate alert grouping and first-pass fix drafting using Gen AI assisted development and MCP-based integrations
Requirements
5+ years of security engineering experience in DevSecOps and security automation
Strong leadership skills to partner with engineering teams and drive remediation work to completion
Proven project ownership to write, test, and commit patches rather than only filing tickets
Advanced Go (Golang) skills to build security tooling, CLIs, and services
Strong AWS security knowledge including IAM and container services such as EKS and ECS
Solid CI/CD pipeline experience with automated testing and security checks
Deep container security expertise including hardened base images and attack surface reduction
Hands-on Kubernetes security skills including network policies, runtime controls, and admission policies
Strong vulnerability management skills across SAST, DAST, SCA, and pentest findings
Practical infrastructure-as-code skills with Terraform for secure configurations
Applied Gen AI assisted development skills with disciplined review and testing of generated code
Upper-Intermediate English skills (B2) for clear written and verbal collaboration
Nice to have
Model Context Protocol (MCP) integration experience for security automation
Microsoft Azure experience securing container platforms such as AKS
Node.js development experience supporting security tooling
Supply chain security expertise with SLSA, in-toto, Sigstore/Cosign, and SBOMs
We offer
International projects with top brands
Work with global teams of highly skilled, diverse peers
Healthcare benefits
Employee financial programs
Paid time off and sick leave
Upskilling, reskilling and certification courses
Unlimited access to the LinkedIn Learning library and 22,000+ courses
Global career opportunities
Volunteer and community involvement opportunities
EPAM Employee Groups
Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn
EPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.