Senior Security Engineer

EPAM Systems, Inc.
Frankfurt am Main, Germany
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Github Open Source Technology Systems Development Life Cycle Software Engineering Systems Integration Software Vulnerability Management Free and Open-Source Software Devsecops Software Library Security Orchestration, Automation & Response

Job description

We’re looking for a Senior Security Engineer (m/f/d) to join our team in Germany in a hybrid working mode.

In this role, you will be focused on building security solutions that help organizations monitor, assess and improve the security posture of open-source software. You will work on a platform that provides unified visibility into open-source vulnerabilities and delivers security ratings for open-source libraries, enabling risk-based decision-making for development teams.

The role combines expertise in DevSecOps, vulnerability management and automation to design, implement and iterate security solutions integrated into modern development workflows. You will collaborate with engineers across disciplines to deliver scalable, secure and efficient security products.

Responsibilities

  • Contribute to the design and enhancement of solutions for open-source vulnerability monitoring and security ratings
  • Integrate and improve security controls in CI/CD pipelines using GitHub Actions and automation tools
  • Apply DevSecOps principles and secure software development practices across the engineering lifecycle
  • Collaborate with cross-functional teams to ensure stability, scalability and compliance of delivered solutions
  • Share knowledge, drive continuous improvement and uphold secure engineering effectiveness within the team

Requirements

Do you have experience in SDLC?, * Strong background in security engineering, DevSecOps orchestration and security-as-code

  • Knowledge of open-source security concepts, including Software Composition Analysis and license compliance
  • Understanding of vulnerability management processes, CVSS scoring and remediation strategies
  • Hands-on experience securing CI/CD pipelines with GitHub Actions or similar tools
  • Familiarity with common security standards, secure SDLC and open-source security frameworks
  • Excellent collaboration, communication and problem-solving skills

Nice to have

  • Knowledge of OSS security monitoring platforms and compliance tools
  • Experience in creating security automation scripts and workflows
  • Familiarity with integrating security gates into build/test pipelines
  • Background in continuous improvement practices for security, risk mitigation and compliance auditing

Benefits & conditions

  • 30 days holiday per annum
  • Company Pension Scheme
  • Regular performance assessments
  • Discount on Fitness-First Black Membership
  • bitkom - Corporate Benefits
  • Employee Stock Purchase Plan (ESPP) (subject to certain eligibility requirements)
  • Learning and development opportunities, including in-house training and coaching, professional certifications, and courses
  • Friendly and enjoyable working team
  • Regular corporate and social events
  • Flexible and remote working opportunities
  • Award-winning workplace: Great Place To Work® certified in 2026, Kununu (Top Company 2022-2026), NewWork Business Award 2025 for outstanding culture, innovation and employee satisfaction.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

3:25 min

Transitioning a software library to a dual licensing model

Kevin Kevin +1 · World Congress 2025

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all