---
title: Senior Application Security Engineer at EPAM Systems
description: We are looking for a Senior Application Security Engineer to reduce security risk across web applications and APIs throughout the software development lifecycle. You will partner closely with engineer
---

# Senior Application Security Engineer

**Company:** EPAM Systems  
**Location:** Georgia  
**Posted:** 2026-10-10  
**Apply by:** 2026-11-24

**Tags:** security

[Apply / View original posting](https://www.linkedin.com/jobs/view/4476897136)

## Job description

We are looking for a Senior Application Security Engineer to reduce security risk across web applications and APIs throughout the software development lifecycle. You will partner closely with engineering teams to assess application security, perform secure design and code reviews, validate and prioritize findings, and drive remediation to closure. This role focuses on practical application security outcomes: identifying real risk, reducing false positives, and helping teams build and ship secure software efficiently. Experience the freedom of remote work from anywhere in Georgia, whether from the comfort of your home, our modern offices in Tbilisi and Batumi or a coworking space in Kutaisi. Responsibilities Perform security assessments of web applications, APIs, services, and supporting components Facilitate threat modeling and review architectures and technical designs from a security perspective Conduct secure code reviews and identify vulnerabilities and insecure implementation patterns Validate findings from automated tools, reduce false positives, and prioritize issues based on exploitability and business impact Provide clear, actionable remediation guidance and secure implementation recommendations Track findings through remediation and retesting in collaboration with development teams Advise teams on authentication, authorization, session management, input validation, data protection, cryptography, secrets handling, and API security controls Contribute to secure SDLC practices, security standards, guidelines, and reusable security patterns Communicate security risks and recommendations to technical and non-technical stakeholders Requirements Hands-on experience in application security or product security Strong knowledge of web application and API security, including OWASP Top 10 and common vulnerability classes Practical experience with security assessments, secure design reviews, and/or secure code reviews Understanding of threat modeling and secure software design principles Strong knowledge of authentication, authorization, session management, input validation, cryptography, secrets handling, and data protection Hands-on experience with one or more application security technologies, such as SAST, DAST, IAST, SCA, or secrets-scanning tools Ability to validate security findings, distinguish actionable risks from false positives, and prioritize remediation Ability to read and understand code in at least one programming language (e.g., Java, C#, JavaScript/TypeScript, Python, or Go) Familiarity with modern application architectures, APIs, distributed services, and common software development practices Strong communication skills and the ability to provide practical guidance to engineering teams Nice to have Experience with DevSecOps practices, including integrating application security tools and security gates into CI/CD pipelines Experience creating or improving secure SDLC processes, security standards, and developer-facing secure coding guidance Familiarity with cloud application security concepts (AWS, Microsoft Azure, or Google Cloud) Knowledge of IAM and application identity concepts (SSO, OAuth 2.0, OpenID Connect, SAML) Experience with containers/Kubernetes or Infrastructure as Code security (Terraform and similar) Relevant security certifications (e.g., CSSLP, CISSP) or equivalent practical expertise We offer We connect like-minded people Delivering innovative solutions to industry leaders, making a global impact Enjoyable working environment, whether it is the vibrant office or the comfort of your own home Opportunity to work abroad for up to two months per year Relocation opportunities within our offices in 55+ countries Corporate and social events We invest in your growth Leadership development, career advising, soft skills and well-being programs Certifications, including GCP, Azure and AWS Unlimited access to EPAM's internal learning database Free English classes with certified teachers We cover it all Participation in the Employee Stock Purchase Plan Monetary bonuses for engaging in the referral program Comprehensive medical & family care package Five trust days per year (sick leave without a medical certificate) Benefits package (sports activities, a variety of stores and services) EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.

---

🔔 [Monitor similar jobs on Gurify](https://gurify.com/?utm_source=techgeo&utm_medium=jobboard&utm_campaign=monitor_similar&role=Senior+Application+Security+Engineer) — get alerted when matching roles are posted in Georgia.

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Senior Application Security Engineer","description":"<p>We are looking for a Senior Application Security Engineer to reduce security risk across web applications and APIs throughout the software development lifecycle. You will partner closely with engineering teams to assess application security, perform secure design and code reviews, validate and prioritize findings, and drive remediation to closure. This role focuses on practical application security outcomes: identifying real risk, reducing false positives, and helping teams build and ship secure software efficiently. Experience the freedom of remote work from anywhere in Georgia, whether from the comfort of your home, our modern offices in Tbilisi and Batumi or a coworking space in Kutaisi. Responsibilities Perform security assessments of web applications, APIs, services, and supporting components Facilitate threat modeling and review architectures and technical designs from a security perspective Conduct secure code reviews and identify vulnerabilities and insecure implementation patterns Validate findings from automated tools, reduce false positives, and prioritize issues based on exploitability and business impact Provide clear, actionable remediation guidance and secure implementation recommendations Track findings through remediation and retesting in collaboration with development teams Advise teams on authentication, authorization, session management, input validation, data protection, cryptography, secrets handling, and API security controls Contribute to secure SDLC practices, security standards, guidelines, and reusable security patterns Communicate security risks and recommendations to technical and non-technical stakeholders Requirements Hands-on experience in application security or product security Strong knowledge of web application and API security, including OWASP Top 10 and common vulnerability classes Practical experience with security assessments, secure design reviews, and/or secure code reviews Understanding of threat modeling and secure software design principles Strong knowledge of authentication, authorization, session management, input validation, cryptography, secrets handling, and data protection Hands-on experience with one or more application security technologies, such as SAST, DAST, IAST, SCA, or secrets-scanning tools Ability to validate security findings, distinguish actionable risks from false positives, and prioritize remediation Ability to read and understand code in at least one programming language (e.g., Java, C#, JavaScript/TypeScript, Python, or Go) Familiarity with modern application architectures, APIs, distributed services, and common software development practices Strong communication skills and the ability to provide practical guidance to engineering teams Nice to have Experience with DevSecOps practices, including integrating application security tools and security gates into CI/CD pipelines Experience creating or improving secure SDLC processes, security standards, and developer-facing secure coding guidance Familiarity with cloud application security concepts (AWS, Microsoft Azure, or Google Cloud) Knowledge of IAM and application identity concepts (SSO, OAuth 2.0, OpenID Connect, SAML) Experience with containers/Kubernetes or Infrastructure as Code security (Terraform and similar) Relevant security certifications (e.g., CSSLP, CISSP) or equivalent practical expertise We offer We connect like-minded people Delivering innovative solutions to industry leaders, making a global impact Enjoyable working environment, whether it is the vibrant office or the comfort of your own home Opportunity to work abroad for up to two months per year Relocation opportunities within our offices in 55+ countries Corporate and social events We invest in your growth Leadership development, career advising, soft skills and well-being programs Certifications, including GCP, Azure and AWS Unlimited access to EPAM's internal learning database Free English classes with certified teachers We cover it all Participation in the Employee Stock Purchase Plan Monetary bonuses for engaging in the referral program Comprehensive medical & family care package Five trust days per year (sick leave without a medical certificate) Benefits package (sports activities, a variety of stores and services) EPAM is global leader in AI transformation engineering and integrated consulting, serving Forbes Global 2000 companies and ambitious startups. With over thirty years of expertise in custom software, product and platform engineering, we empower our clients to become AI-Native enterprises, driving measurable value from innovation and digital investments.</p>","identifier":{"@type":"PropertyValue","name":"TechGeo","value":"4476897136"},"url":"https://techgeo.ge/job/senior-application-security-engineer-4d1cbe2","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Georgia","addressCountry":"GE"}},"hiringOrganization":{"@type":"Organization","name":"EPAM Systems"},"directApply":false,"datePosted":"2026-10-10","validThrough":"2026-11-24T23:59:59+04:00","jobLocationType":"TELECOMMUTE","applicantLocationRequirements":{"@type":"Country","name":"Georgia"}}
```
