---
title: Senior Application Security Engineer at EPAM Systems
description: We are looking for a Senior Application Security Engineer to join our forward-thinking team. We are delivering a Unified Automation Platform (Internal Developer Platform) to standardize delivery, redu
---

# Senior Application Security Engineer

**Company:** EPAM Systems  
**Location:** Georgia  
**Posted:** 2026-09-03  
**Apply by:** 2026-10-18

**Tags:** security

[Apply / View original posting](https://www.linkedin.com/jobs/view/4461696984)

## Job description

We are looking for a Senior Application Security Engineer to join our forward-thinking team. We are delivering a Unified Automation Platform (Internal Developer Platform) to standardize delivery, reduce security gaps, and enable secure self-service across Azure and on-premises VMware. You will lead critical security-tooling integrations and policy automation for a governance-heavy environment. Experience the freedom of remote work from anywhere in Georgia, whether from the comfort of your home, our modern offices in Tbilisi and Batumi or a coworking space in Kutaisi. Responsibilities Implement and operate the certificate-management integration with Venafi: issuance workflows and distribution across F5, Azure Key Vault, and VM/OS certificate stores, including renewal/rotation automation Build and maintain the secrets-management integration (OpenBao, Azure Key Vault): configuration-as-code for authentication methods, namespaces, mounts, policies, and dynamic secrets engines (database, cloud) Implement the Privileged Access Management (PAM) "break-the-glass" workflow: time-boxed grant requests, approval-chain automation, session recording hooks, and audit-trail logging Build SIEM and WAF alert-integration pipelines (alert feed ingestion, entity correlation, severity views) and the Vulnerability Dashboard, integrating findings from SAST/DAST/SCA/IAST/ASPM scanners Implement Policy as Code checks (OPA/Conftest, Azure Policy): baseline policy library, CI gate integration, and exemption/waiver workflow automation Support the platform's Auth/RBAC configuration from a security-tooling perspective (Entra ID, Active Directory, GPOs, M365 groups), ensuring audit-retention settings are correctly applied Work with the Network Architect to translate firewall/WAF policy requirements (PaloAlto, F5, Cloudflare) into the SIEM/WAF alert integration and Vulnerability Dashboard Support SOC and IAM teams during security reviews, preparing evidence and configuration details for security-sensitive integrations Troubleshoot and remediate security-tooling issues during Implementation and Adoption Requirements 3+ years of hands-on experience implementing security-tool integrations: certificate-lifecycle management (Venafi or equivalent), secrets management (OpenBao, Key Vault), and PAM workflows Practical experience with SIEM/SOAR alert pipelines and vulnerability-management tooling (SAST/DAST/SCA/IAST/ASPM) Experience implementing Policy as Code checks (OPA/Conftest, Azure Policy) and CI/CD gate enforcement Working knowledge of enterprise identity and access management (Entra ID, Active Directory, RBAC/claims-based authorization) Familiarity with firewall/WAF concepts (PaloAlto, F5, Cloudflare) sufficient to define alerting/finding-correlation requirements Ability to work within governance-heavy, security-sensitive change-control processes Excellent command of written and spoken English (B2+ level) Nice to have Experience integrating security tooling with a Backstage-based (or comparable) developer portal Familiarity with supply-chain security practices (artifact signing/SBOM, e.g., cosign/Sigstore) Knowledge of Conditional Access automation (Entra ID/Microsoft Graph API) Experience with Infrastructure as Code (Terraform/OpenTofu) for implementing security modules We offer We connect like-minded people Delivering innovative solutions to industry leaders, making a global impact Enjoyable working environment, whether it is the vibrant office or the comfort of your own home Opportunity to work abroad for up to two months per year Relocation opportunities within our offices in 55+ countries Corporate and social events We invest in your growth Leadership development, career advising, soft skills and well-being programs Certifications, including GCP, Azure and AWS Unlimited access to EPAM's internal learning database Free English classes with certified teachers We cover it all Participation in the Employee Stock Purchase Plan Monetary bonuses for engaging in the referral program Comprehensive medical & family care package Five trust days per year (sick leave without a medical certificate) Benefits package (sports activities, a variety of stores and services) EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.

---

🔔 [Monitor similar jobs on Gurify](https://gurify.com/?utm_source=techgeo&utm_medium=jobboard&utm_campaign=monitor_similar&role=Senior+Application+Security+Engineer) — get alerted when matching roles are posted in Georgia.

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Application Security Engineer","description":"<p>We are looking for a Senior Application Security Engineer to join our forward-thinking team. We are delivering a Unified Automation Platform (Internal Developer Platform) to standardize delivery, reduce security gaps, and enable secure self-service across Azure and on-premises VMware. You will lead critical security-tooling integrations and policy automation for a governance-heavy environment. Experience the freedom of remote work from anywhere in Georgia, whether from the comfort of your home, our modern offices in Tbilisi and Batumi or a coworking space in Kutaisi. Responsibilities Implement and operate the certificate-management integration with Venafi: issuance workflows and distribution across F5, Azure Key Vault, and VM/OS certificate stores, including renewal/rotation automation Build and maintain the secrets-management integration (OpenBao, Azure Key Vault): configuration-as-code for authentication methods, namespaces, mounts, policies, and dynamic secrets engines (database, cloud) Implement the Privileged Access Management (PAM) \"break-the-glass\" workflow: time-boxed grant requests, approval-chain automation, session recording hooks, and audit-trail logging Build SIEM and WAF alert-integration pipelines (alert feed ingestion, entity correlation, severity views) and the Vulnerability Dashboard, integrating findings from SAST/DAST/SCA/IAST/ASPM scanners Implement Policy as Code checks (OPA/Conftest, Azure Policy): baseline policy library, CI gate integration, and exemption/waiver workflow automation Support the platform's Auth/RBAC configuration from a security-tooling perspective (Entra ID, Active Directory, GPOs, M365 groups), ensuring audit-retention settings are correctly applied Work with the Network Architect to translate firewall/WAF policy requirements (PaloAlto, F5, Cloudflare) into the SIEM/WAF alert integration and Vulnerability Dashboard Support SOC and IAM teams during security reviews, preparing evidence and configuration details for security-sensitive integrations Troubleshoot and remediate security-tooling issues during Implementation and Adoption Requirements 3+ years of hands-on experience implementing security-tool integrations: certificate-lifecycle management (Venafi or equivalent), secrets management (OpenBao, Key Vault), and PAM workflows Practical experience with SIEM/SOAR alert pipelines and vulnerability-management tooling (SAST/DAST/SCA/IAST/ASPM) Experience implementing Policy as Code checks (OPA/Conftest, Azure Policy) and CI/CD gate enforcement Working knowledge of enterprise identity and access management (Entra ID, Active Directory, RBAC/claims-based authorization) Familiarity with firewall/WAF concepts (PaloAlto, F5, Cloudflare) sufficient to define alerting/finding-correlation requirements Ability to work within governance-heavy, security-sensitive change-control processes Excellent command of written and spoken English (B2+ level) Nice to have Experience integrating security tooling with a Backstage-based (or comparable) developer portal Familiarity with supply-chain security practices (artifact signing/SBOM, e.g., cosign/Sigstore) Knowledge of Conditional Access automation (Entra ID/Microsoft Graph API) Experience with Infrastructure as Code (Terraform/OpenTofu) for implementing security modules We offer We connect like-minded people Delivering innovative solutions to industry leaders, making a global impact Enjoyable working environment, whether it is the vibrant office or the comfort of your own home Opportunity to work abroad for up to two months per year Relocation opportunities within our offices in 55+ countries Corporate and social events We invest in your growth Leadership development, career advising, soft skills and well-being programs Certifications, including GCP, Azure and AWS Unlimited access to EPAM's internal learning database Free English classes with certified teachers We cover it all Participation in the Employee Stock Purchase Plan Monetary bonuses for engaging in the referral program Comprehensive medical & family care package Five trust days per year (sick leave without a medical certificate) Benefits package (sports activities, a variety of stores and services) EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.</p>","identifier":{"@type":"PropertyValue","name":"TechGeo","value":"4461696984"},"url":"https://techgeo.ge/job/senior-application-security-engineer-286df25","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Georgia","addressCountry":"GE"}},"hiringOrganization":{"@type":"Organization","name":"EPAM Systems"},"directApply":false,"datePosted":"2026-09-03","validThrough":"2026-10-18T23:59:59+04:00","jobLocationType":"TELECOMMUTE","applicantLocationRequirements":{"@type":"Country","name":"Georgia"}}
```
