Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
We are looking for a Senior Security Engineer to strengthen the software supply chain and container security through practical automation and hands-on remediation. You will partner with engineering teams to harden Kubernetes workloads, improve CI/CD guardrails, and ship tested fixes.
Responsibilities
Build and maintain hardened container base images for development and production use
Implement Kubernetes security controls including runtime monitoring, network policies, and admission controllers
Embed security checks and policy gates into CI/CD pipelines to deliver fast, automated feedback
Secure software supply chain workflows across build systems, registries, and infrastructure-as-code
Write and maintain security automation utilities and services in Go
Triage vulnerabilities from pentests, SAST, DAST, and SCA and separate real risks from noise
Partner with engineering teams to prioritize issues and commit remediation patches and dependency upgrades
Automate alert grouping and first-pass fixes using LLMs and Model Context Protocol integrations
Review and test all generated code before merging changes into codebases
Requirements
3+ years of security engineering experience in SaaS environments with DevSecOps and automation focus
Proven leadership ability to partner with engineering teams and drive remediation to completion
Hands-on project experience delivering hardened container images and Kubernetes security controls in production
Strong Go (Golang) programming skills for building security tooling, CLIs, or services
Solid CI/CD pipeline experience with automated testing and security checks
Deep AWS security knowledge including IAM and container services such as EKS and ECS
Practical Kubernetes security expertise including network policies, runtime controls, and admission controllers
Strong vulnerability management skills across SAST, DAST, pentesting, and SCA with false-positive triage
Terraform infrastructure-as-code skills for cloud and security configurations
Strong communication skills to explain findings and provide actionable fixes to engineers
Careful verification mindset when using AI coding assistants and LLM-driven automation
Upper-Intermediate English proficiency (B2, Upper-Intermediate)
Nice to have
Model Context Protocol (MCP) integration experience for security automation
Supply chain security experience with SLSA, in-toto, Sigstore/Cosign, and SBOMs (SPDX or CycloneDX)
Microsoft Azure (AKS) experience securing container workloads
Node.js or TypeScript development experience
We offer
International projects with top brands
Work with global teams of highly skilled, diverse peers
Healthcare benefits
Employee financial programs
Paid time off and sick leave
Upskilling, reskilling and certification courses
Unlimited access to the LinkedIn Learning library and 22,000+ courses
Global career opportunities
Volunteer and community involvement opportunities
EPAM Employee Groups
Award-winning culture recognized by Glassdoor, Newsweek and LinkedIn
EPAM is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity or expression, disability, protected veteran status, or any other characteristic protected by applicable law.
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.