4,192 open roles
Lead APT & Automated Validation Engineer
Job description
We are seeking a Lead APT & Automated Validation Engineer who goes beyond traditional penetration testing. This role is for a developer at heart — someone who can orchestrate, script, and chain network and web application exploits to run autonomously, driving continuous and scalable security validation across complex environments.
Responsibilities
Design and sequence exploit chains that combine multiple vulnerabilities to achieve higher-impact outcomes (e.g., pairing information disclosure with SSRF to reach Remote Code Execution) Develop custom exploits and weaponized scripts to automate multi-stage attack scenarios Build and maintain automated authentication flows handling OAuth, TOTP, and MFA programmatically Configure, scale, and operate continuous automated security validation platforms Engineer exploit scripts capable of safely validating vulnerabilities in live production environments without disrupting services or corrupting data Analyze network and web application attack surfaces to identify opportunities for automated exploitation Collaborate with security and engineering teams to translate manual pentesting techniques into repeatable, automated workflows Continuously improve the organization's offensive automation framework and tooling Requirements 5+ years of experience in offensive security, penetration testing, or security engineering roles At least 1 year of relevant leadership experience Expertise in exploit chaining and attack logic, including sequencing low-severity findings into high-impact compromises Proficiency in Python for writing custom exploits and automating complex multi-stage attack scripts Experience configuring and scaling continuous automated security validation tools such as Pentera, Cymulate, or Picus, including custom Pentest Robots architectures In-depth knowledge of the OSI model and core network protocols (DNS, BGP, TCP/IP) Understanding of web application vulnerabilities, including the OWASP Top 10 and API flaws such as IDOR Proven capability to engineer automated exploit scripts that safely validate vulnerabilities without crashing network infrastructure or corrupting production databases English proficiency at B1+ level or above Nice to have Skills in Bash and/or Go for custom tooling and exploit development Familiarity with OAuth flows and programmatic handling of authentication Background in bypassing or automating Multi-Factor Authentication challenges
Description copied from EPAM Systems's careers page. Read the full posting before you apply.
More jobs at EPAM Systems
Physics Content Specialist
EPAM Systems· Remote (Kazakhstan; Kyrgyzstan)Chemistry Content Specialist
EPAM Systems· Remote (Uzbekistan)Physics Content Specialist
EPAM Systems· Remote (Uzbekistan)Business Consultant, Networks & Telecommunication
EPAM Systems· PolandTest Automation Engineer - Hardware and Robotics
EPAM Systems· Boulder, Colorado, USA