Skip navigation

Security Architect

  • Sofia, Bulgaria
  • hot
Job #: 45254
Striving for excellence is in our DNA. Since 1993, we have been helping the world’s leading companies imagine, design, engineer, and deliver software and digital experiences that change the world. We are more than just specialists, we are experts.

DESCRIPTION


EPAM is looking for an experienced Security Architect with good communication skills to join our global team of IT professionals. A Security Engineer will be a part of the Information Security Team and will be responsible for assessing, designing, resolving and integrating security technology solutions. As a Security Architect you will be responsible for increasing Security Awareness among Project Teams and making products more robust and secure. You will work with the Development Teams, mentoring and driving them through the security baseline assessment and adopting Secure SDLC process.

Responsibilities

  • Perform security audits for ongoing projects: both architecture and implementation/code review
  • Contribute in building Secure Architecture and Design for the new projects or making corrections to the existing ones
  • Consult on all third-party application security Penetration Testing
  • Consult on vulnerability response process, impact assessments and remediation plans
  • Recommend design and code changes to meet product security objectives and remedy security findings
  • Perform unit test if needed to verify a remediation or provide proof of- oncept as evidence of a vulnerability
  • Work as a Security Advisor helping tevelopment activitieo establish secure development activities in SDLC end-to-end
  • Communicate with customers and teams, be able to convey the message about importance of security, the ways of establishing it and the wrong ways of enforcing it (e.g. do penetration testing before release)
  • Work on Presales making sure Security is addressed properly and taken into account in budget and effort estimations

Requirements

  • Knowledge of at least one Security Development methodologies (e.g. Microsoft SDL, OWASP CLASP, etc.)
  • Knowledge of main Security-related activities in development such as Risk and Privacy Assessment, Threat Modeling, Security Code Review
  • Deep understanding of the nature of Security Treats and their classification
  • Knowledge of most common implementations of the Threats (e.g. XSS, SQL Injection, XSRF, buffer overruns, brute force, rainbow tables, DoS, etc.) and how they match the general classification
  • Understanding of main security principles, such as multi-layered protection (Defense in depth)
  • Understanding of main areas of protection (security, privacy, availability) and levels of defense (networking, infrastructure, operation system, application)
  • Understanding of mitigation mechanisms for every type of threats (e.g. validation, sanitizing, cryptographic operations, etc.)
  • Good knowledge of Security Features and Mechanisms provided by at least one Operation System (e.g. Windows, Linux, Android, iOS, etc.) and development platform/technologies (e.g. Java, .NET Framework, databases, etc.)
  • Familiar with existing Security Standards (e.g. PCI DSS, HIPAA, NIST, Common Criteria, etc.) and what does it mean to implement compliance with them
  • Familiar with the tools for various security activities: Static Code Analysis, Penenetration testing, Intrusion Detection/Prevention, etc
  • Experience with Vulnerability Assessment and Penetration Testing and familiarity with common security vulnerabilities, the lexicon of findings (CVSS, CVE), ability to assess severity, etc
  • Understanding of basic principles of Infrastructure security and Penetration testing
  • Ability to use the tools to perform actual attacks is a plus
  • Possess security certifications (CEH, CSSLP, CREST, CISSP, etc.) is a plus

We offer

  • Personal development program that will allow you to be valued for your strengths
  • Wide range of professional trainings and workshops
  • Attractive salary, additional health and dental insurance as well as other social benefits
  • Broad projects variety and possible mobility between projects over the time
  • Experience exchange with colleagues around the world
  • Work-life balance and flexible schedule, team buildings and sport opportunities
  • Modern office in the Infinity Tower business center
  • If you are interested in this role please send your CV in English. All applications will be treated as strictly confidential
  • Only short-listed applicants will be contacted

Equal Employment Opportunity

EPAM Systems, Inc. is an equal opportunity employer.  We recognize the value of diversity and inclusion in creating success for our customers, business partners, shareholders, employees and communities. We are committed to recruiting, hiring, developing and promoting employees without discrimination. As a global employer, this commitment includes complying with all laws in the countries in which we operate. Nevertheless, we believe equal employment practices should not be limited to what the law requires. Equal opportunity and inclusion are essential to motivate, empower and recognize the best in everyone.

At EPAM, employment actions are based on individual qualifications, without regard to race, color, religion, creed, gender, pregnancy status, sexual orientation, gender identity, gender expression, marital or familial status, national origin, ancestry, genetics, age, disability status, veteran status, citizenship status when otherwise legally able to work, or any other characteristic protected by law.

Pay Transparency Non-Discrimination Provision

EPAM will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35(c)

Affirmative Action Obligations as a U.S. Government Federal Contractor

As a U.S. federal government contractor, EPAM is committed to meet its affirmative action obligations to make good faith efforts to expand the recruiting pool of women, minorities, individuals with disabilities, and protected veterans through outreach, targeted recruitment, training opportunities and other activities. We affirm this commitment annually in EPAM’s Affirmative Action Plans. The full text of our Affirmative Action Plan for Persons with a Disability and Protected Veterans is available for inspection in the People Operations Department during normal business hours. Email the People Operations Department to schedule an appointment.

Accessibility for Applicants with Disabilities

EPAM is committed to working with and providing reasonable accommodation to individuals with disabilities. If you require an accommodation at any stage of the employment application process, please send an email to the People Operations Department including your name, a detailed description of your requested accommodation, and the best method to contact you. If you have already reviewed a job posting or submitted an application for a job, please include the requisition number. We will assist you and make a determination on your accommodation request on a case-by-case basis.

EEO is the Law. Applicants to and employees of EPAM Systems Inc., are protected under Federal law from discrimination.

EPAM Systems, Inc. participates in eVerify.

Background investigations are required for all new hires as a condition of employment, after the job offer is made. Employment will not begin until EPAM Systems receives and approves the results of the background check.

Hello. How Can We Help You?


Our Offices

  • Canada

    • Ottawa

      343 Preston Street,
      ON K1S 1N4, Ottawa
      Canada

      Map
    • Toronto

      5 Park Home Avenue,
      Suite 400,
      ON M2N 6L4, North York,
      Toronto
      Canada

      Map
      F: +1-416-595-1551
  • Mexico

    • Guadalajara

      Periférico Sur #8110,
      Col. El Mante
      45609 Tlaquepaque, Jalisco
      Mexico

      Map
  • United States

    • Newtown, PA

      41 University Drive,
      Suite 202,
      Newtown, PA 18940
      USA

      Map
      F: +1-267-759-8989
    • Bellevue, WA

      110 110th Ave. NE,
      Suite 310
      Bellevue, WA 98004
      USA

      Map
    • Boston, MA

      21 Drydock Avenue,
      Suite 410 W,
      Boston, MA 02210
      USA

      Map
    • Conshohocken, PA

      101 East 8th Ave,
      Suite 201,
      Conshohocken, PA 19428
      USA

      Map
    • Los Angeles, CA

      11601 Wilshire Blvd,
      Suite 350,
      Los Angeles, CA 90025
      USA

      Map
    • New York, NY

      24 West 25th Street,
      5th Floor,
      New York, NY 10010
      USA

      Map
      F: +1-267-759-8989
    • Philadelphia, PA

      30 South 15th Street,
      9th Floor,
      Philadelphia, PA 19102
      USA

      Map
    • San Francisco, CA

      222 Kearny Street,
      Suite 308,
      San Francisco, CA 94108
      USA

      Map
    • San Jose, CA

      2055 Gateway Place,
      Suite 510,
      San Jose, CA 95110
      USA

      Map
    • Washington D.C.

      7901 Jones Branch Drive,
      Suite 400,
      McLean, VA 22102
      USA

      Map
  • Australia

  • China

    • Guangzhou

      Unit B01, 23/F,
      Yuexiuxinduhui Building,
      No. 236, 6th Zhongshan Road,
      Yuexiu District, Guangzhou,
      China 510180

      Map
    • 广州

      中国广州市越秀区
      中山六路236号
      越秀新都会大厦中座 23楼 B01室
      邮编510180

      地图
    • Shanghai

      Room B509, 5th Floor,
      48 Weihai Road,
      Huangpu District, Shanghai,
      China 200000

      Map
    • 上海

      上海市黄浦区
      威海路48号
      5楼B509室
      邮编200000

      地图
    • Shenzhen

      3/F, Block 5, Vision Shenzhen Business Park,
      9th Gaoxin South Road, 
      Shenzhen Hi-tech Industrial Park,
      Nanshan District, Shenzhen,
      Guangdong, China 518057

      Map
    • 深圳

      中国广东省深圳市
      南山区高新南九道
      威新软件园5号楼3楼
      邮编518057

      地图
    • Suzhou

      Building 12, Creative Industrial Park,
      328 Xinghu Street,
      Suzhou Industrial Park,
      Suzhou, China 215123

      Map
    • 苏州

      中国江苏省苏州市
      苏州工业园区星湖街328号
      创意产业园内12号楼
      邮编215123

      地图
  • Hong Kong

    • Hong Kong

      26F&17F, The Wellington Tower,
      198 Wellington Street,
      Central, HK

      Map
  • India

    • Bangalore

      Smartworks,  
      Global Technology Park,
      Block C, Outer Ring Rd,
      Adarsh Palm Retreat, Bellandur,
      Bengaluru, Karnataka 560103
      India

      Map
    • Hyderabad

      10, 11 & 12th Floors,
      Salarpuria Sattva Knowledge City,
      Plot No. 2, Phase - 1,
      Survey No. 83/1,
      Raidurgam Village,
      Serilingampally Mandal,
      Hyderabad, Telangana - 500081
      India

      Map
    • Pune

      SmartWork Business Center Pvt Ltd,
      Suite 8, Level 1,
      West Wing, Nyati Unitree,
      Samrat Ashok Road,
      Yerwada, Pune - 411006,
      Maharashtra
      India

      Map
  • Japan

    • Tokyo

      Floor 1-10-11
      Shibadaimon Centre Building 10th
      Shibadaimon Minato-ku
      Tokyo 105-0012
      Japan

      Map
      F: +81-03-6880-9201
  • Singapore

    • Singapore

      5 Shenton Way
      UIC Building, #10-01,
      Singapore (068808)

      Map
  • United Arab Emirates

    • Dubai

      EPAM Systems FZ-LLC Dubai Branch
      2307 Arenco Tower, Dubai Media City
      PO Box 501929 Dubai
      United Arab Emirates

      Map