Senior Cloud Security Specialist Armenia or Remote
Senior Cloud Security Specialist Description
Job #: 79285Description
We are looking for a Cloud Security Specialist who will increase security awareness among project teams and make products more robust and secure. This goal includes various activities: communicating with customers, creating security-related artifacts, contributing to security testing, and others.
What You’ll Do
- Perform security audits for ongoing projects: both architecture and implementation/code review
- Contribute to building secure architecture and design for the new projects or make corrections to the existing ones
- Act as a security advisor helping to establish secure activities in software development life cycle end-to-end
- Provide security training for development teams
- Communicate with customers and internal teams, building a consistent understanding of security requirements, main threats, mitigations implemented
- Work as a consultant answering questions related to security in the development
- Participate in pre-sales ensuring security is addressed properly and considered in budget and effort estimations
What You Have
- Knowledge of security features provided by at least one operating system (Windows, Linux, Android, iOS, etc.) and development platform/technologies (Java, .NET Framework, databases, etc.)
- Flexibility to use at least one security methodology: Microsoft SDL, OWASP CLASP, etc
- Understanding of the nature of security threats, the most common implementations of the threats (XSS, SQL Injection, XSRF, buffer overruns, brute force, rainbow tables, DoS, etc.) and how they match the general classification
- Competency in main security-related activities: risk and privacy assessment, threat modeling, security code review
- Expertise in security principles such as multi-layered protection, areas of protection, levels of defense, and mitigation mechanisms for every type of threat (validation, sanitizing, crypto operations, etc.)
- Familiarity with security standards (PCI DSS, HIPAA, NIST, Common Criteria, etc.) and tools for various activities (static code analysis, pen testing, intrusion detection/prevention, etc.)
Nice to have
- Ability to use the tools to perform actual attacks is a plus
- Certification in any security area is a plus
We offer
- Outstanding career development opportunities with a transparent roadmap to accelerate your journey
- Knowledge sharing within the community of 61,600+ industry’s top professionals worldwide
- Various opportunities for self-development: hard & soft skills internal training courses, mentoring programs, and unlimited access to 8,000+ LinkedIn Learning courses
- Free English classes with certified teachers
- Relocation opportunities within our offices in 45+ countries
- Bonuses for participating in the referral program
- Friendly team, enjoyable working environment, and flexible working schedule
- Medical & family care programs, wellness & fitness programs, corporate and social events
- Participation in the Employee Stock Purchase Plan
About EPAM
- EPAM is a leading global provider of digital platform engineering and development services. We are committed to positively impacting our customers, our employees, and our communities. We embrace a dynamic and inclusive culture. Here you will collaborate with multi-national teams, contribute to a myriad of innovative projects that deliver the most creative and cutting-edge solutions, and have an opportunity to learn and grow continuously. No matter where you are located, you will join a dedicated, creative, and diverse community that will help you discover your fullest potential