Senior Application Security Engineer
EPAM Systems
Job description
About the role
We are seeking a Senior Application Security Engineer to lead security‑tooling integrations and policy automation for our Unified Automation Platform. You will work in a governance‑heavy environment, ensuring secure self‑service across Azure and on‑premises VMware.
Key responsibilities
- Implement and operate certificate‑management integration with Venafi, including issuance, distribution, renewal and rotation across F5, Azure Key Vault and VM/OS stores.
- Build and maintain secrets‑management integration (OpenBao, Azure Key Vault) using configuration‑as‑code for authentication, namespaces, policies and dynamic secret engines.
- Design and run Privileged Access Management “break‑the‑glass” workflows with time‑boxed grants, approval automation, session recording and audit logging.
- Create SIEM and WAF alert‑integration pipelines, correlate entities, and develop a Vulnerability Dashboard aggregating findings from SAST, DAST, SCA, IAST and ASPM scanners.
- Implement Policy‑as‑Code checks (OPA/Conftest, Azure Policy) with baseline libraries, CI gate integration and exemption workflows.
- Support Auth/RBAC configuration (Entra ID, Active Directory, GPOs, M365 groups) and ensure proper audit‑retention settings.
- Collaborate with Network Architects to translate firewall/WAF requirements (PaloAlto, F5, Cloudflare) into SIEM/WAF alerts and dashboard views.
- Assist SOC and IAM teams during security reviews, providing evidence and configuration details.
- Troubleshoot and remediate security‑tooling issues throughout implementation and adoption phases.
Required profile
- 3+ years of hands‑on experience with security‑tool integrations such as certificate lifecycle (Venafi or equivalent), secrets management (OpenBao, Azure Key Vault) and PAM workflows.
- Practical experience building SIEM/SOAR alert pipelines and managing vulnerability‑management tooling (SAST, DAST, SCA, IAST, ASPM).
- Experience implementing Policy‑as‑Code checks (OPA/Conftest, Azure Policy) and CI/CD gate enforcement.
- Strong knowledge of enterprise identity and access management (Entra ID, Active Directory, RBAC/claims‑based authorization).
- Familiarity with firewall/WAF concepts (PaloAlto, F5, Cloudflare) sufficient to define alerting and correlation requirements.
- Ability to operate within governance‑heavy, security‑sensitive change‑control processes.
- Excellent written and spoken English (B2+ level).
Required skills
- Venafi
- OpenBao
- Azure Key Vault
- Privileged Access Management (PAM) workflows
- SIEM / SOAR platforms
- SAST, DAST, SCA, IAST, ASPM scanners
- OPA and Conftest
- Azure Policy
- CI/CD pipeline integration
- Entra ID (Azure AD)
- Active Directory
- RBAC / claims‑based authorization
- PaloAlto firewalls
- F5 load balancers / WAF
- Cloudflare WAF
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Kyrgyzstan.
Salary: Senior Platform Engineer Based on 7 job offers in KyrgyzstanSalaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 2 weeks ago
Expires 1 month from now
18 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
EPAM Systems
Related job offers
-
SAP S/4HANA Consultant – Treasury & Cash Management
EPAM Systems Kirghizistan -
Go & Java Backend Engineer (Russian speaking)
STB Union Kirghizistan -
Senior BI Analyst
EPAM Systems Kirghizistan -
Senior Business Process Analyst
General Dynamics Information Technology International -
Principal Systems Analyst – IT Change Management
General Dynamics Information Technology International