3 сен

application security engineer

ориентир по рынку
вакансия зп не указана
в среднем 320 875 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

EPAM delivers a Unified Automation Platform, an Internal Developer Platform that standardizes delivery, reduces security gaps, and enables secure self-service across Azure and on-premises VMware.

задачи

  • Implement and operate the certificate-management integration with Venafi, including issuance workflows, distribution across F5, Azure Key Vault, and VM/OS certificate stores, and renewal/rotation automation;
  • Build and maintain the secrets-management integration with OpenBao and Azure Key Vault using configuration-as-code for authentication methods, namespaces, mounts, policies, and dynamic secrets engines;
  • Implement the Privileged Access Management break-the-glass workflow with time-boxed grant requests, approval-chain automation, session recording hooks, and audit-trail logging;
  • Build SIEM and WAF alert-integration pipelines and the Vulnerability Dashboard, integrating findings from SAST, DAST, SCA, IAST, and ASPM scanners;
  • Implement Policy as Code checks with OPA/Conftest and Azure Policy, including a baseline policy library, CI gate integration, and exemption/waiver workflow automation;
  • Support the platform's Auth/RBAC configuration from a security-tooling perspective across Entra ID, Active Directory, GPOs, and M365 groups;
  • Ensure that audit-retention settings are correctly applied;
  • Work with the Network Architect to translate firewall/WAF policy requirements into SIEM/WAF alert integration and Vulnerability Dashboard requirements;
  • Support SOC and IAM teams during security reviews by preparing evidence and configuration details for security-sensitive integrations;
  • Troubleshoot and remediate security-tooling issues during Implementation and Adoption.

требования

  • Have 3+ years of hands-on experience implementing security-tool integrations, including certificate-lifecycle management, secrets management, and PAM workflows;
  • Have practical experience with SIEM/SOAR alert pipelines and vulnerability-management tooling;
  • Have experience implementing Policy as Code checks and CI/CD gate enforcement;
  • Have working knowledge of enterprise identity and access management, including Entra ID, Active Directory, RBAC, and claims-based authorization;
  • Have familiarity with firewall/WAF concepts and the ability to define alerting and finding-correlation requirements;
  • Can work within governance-heavy, security-sensitive change-control processes;
  • Have excellent written and spoken English at B2+ level;
  • Nice to have: Experience integrating security tooling with a Backstage-based or comparable developer portal, familiarity with supply-chain security practices such as artifact signing and SBOM, knowledge of Conditional Access automation with Entra ID/Microsoft Graph API, experience with Infrastructure as Code using Terraform/OpenTofu for implementing security modules.

условия

  • Location-specific conditions and benefits are available.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.