Overview
We are looking for a Senior Application Security Engineer to join our forward-thinking team.
We are delivering a Unified Automation Platform (Internal Developer Platform) to standardize delivery, reduce security gaps, and enable secure self-service across Azure and on-premises VMware. You will lead critical security-tooling integrations and policy automation for a governance-heavy environment.
- Implement and operate the certificate-management integration with Venafi: issuance workflows and distribution across F5, Azure Key Vault, and VM/OS certificate stores, including renewal/rotation automation
- Build and maintain the secrets-management integration (OpenBao, Azure Key Vault): configuration-as-code for authentication methods, namespaces, mounts, policies, and dynamic secrets engines (database, cloud)
- Implement the Privileged Access Management (PAM) "break-the-glass" workflow: time-boxed grant requests, approval-chain automation, session recording hooks, and audit-trail logging
- Build SIEM and WAF alert-integration pipelines (alert feed ingestion, entity correlation, severity views) and the Vulnerability Dashboard, integrating findings from SAST/DAST/SCA/IAST/ASPM scanners
- Implement Policy as Code checks (OPA/Conftest, Azure Policy): baseline policy library, CI gate integration, and exemption/waiver workflow automation
- Support the platform's Auth/RBAC configuration from a security-tooling perspective (Entra ID, Active Directory, GPOs, M365 groups), ensuring audit-retention settings are correctly applied
- Work with the Network Architect to translate firewall/WAF policy requirements (PaloAlto, F5, Cloudflare) into the SIEM/WAF alert integration and Vulnerability Dashboard
- Support SOC and IAM teams during security reviews, preparing evidence and configuration details for security-sensitive integrations
- Troubleshoot and remediate security-tooling issues during Implementation and Adoption
- 3+ years of hands-on experience implementing security-tool integrations: certificate-lifecycle management (Venafi or equivalent), secrets management (OpenBao, Key Vault), and PAM workflows
- Practical experience with SIEM/SOAR alert pipelines and vulnerability-management tooling (SAST/DAST/SCA/IAST/ASPM)
- Experience implementing Policy as Code checks (OPA/Conftest, Azure Policy) and CI/CD gate enforcement
- Working knowledge of enterprise identity and access management (Entra ID, Active Directory, RBAC/claims-based authorization)
- Familiarity with firewall/WAF concepts (PaloAlto, F5, Cloudflare) sufficient to define alerting/finding-correlation requirements
- Ability to work within governance-heavy, security-sensitive change-control processes
- Excellent command of written and spoken English (B2+ level)
- Delivering innovative solutions to industry leaders, making a global impact
- Enjoyable working environment, whether it is the vibrant office or the comfort of your home
- Opportunity to work abroad for up to two months per year
- Relocation opportunities within our offices in 55+ countries
- Corporate and social events
- Leadership development, career advising, soft skills and well-being programs
- Certifications, including GCP, Azure and AWS
- Unlimited access to EPAM's internal learning database
- Free English classes with certified teachers
- Participation in the Employee Stock Purchase Plan
- Monetary bonuses for engaging in the referral program
- Comprehensive medical & family care package
- Four trust days per year for personal needs
- Discounts for fitness clubs
- Benefits package (hotels, restaurants, stores and services)
- Experience integrating security tooling with a Backstage-based (or comparable) developer portal
- Familiarity with supply-chain security practices (artifact signing/SBOM, e.g., cosign/Sigstore)
- Knowledge of Conditional Access automation (Entra ID/Microsoft Graph API)
- Experience with Infrastructure as Code (Terraform/OpenTofu) for implementing security modules
- Security.Engineering
- Azure DevOps
- Github Copilot
- Microsoft Azure
- Security Architecture
✨ Our intelligent job search engine discovered this job and republished it for your convenience.
Please be aware that the job information may be incorrect or incomplete. The job announcement remains the property of its original publisher. To view the original job and its full details, please visit the job's URL on the owner’s page.
Please clearly mention that you have heard of this job opportunity on https://ijob.am.

