Java Security Integration Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+41 more
Job description
The ideal candidate is a hands-on developer with 5+ years of experience who bridges the gap between core Java development and modern web application security practices. You will be responsible for developing secure integrations, implementing robust Customer Identity & Access Management (CIAM) systems, establishing secure Single Sign-On (SSO) pathways, work on legacy system refactoring, troubleshooting application behaviors behind Web Application Firewalls (WAF), and ensuring that security logging seamlessly integrates with our enterprise SIEM platforms., Secure Coding: Design, develop, and maintain high-performance, secure Java-based backend services and APIs using modern frameworks (e.g., Spring Boot, Spring Security).
- AppSec Best Practices: Conduct threat modeling, perform secure code reviews, and remediate application vulnerabilities based on OWASP Top 10 standards., SSO Integrations: Design and configure secure Single Sign-On (SSO) workflows utilizing industry-standard protocols including SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).
- IdP Management: Integrate enterprise application suites with primary Identity Providers (IdPs) such as Okta, Auth0, Microsoft Entra ID (Azure AD), or Keycloak.
- CIAM Implementation: Lead the implementation of Customer Identity & Access Management (CIAM) systems
- Experience with B2C authentication architecture.
- A strong understanding of modern authentication and authorization protocols to secure client-facing portals, including multi-factor authentication (MFA) and registration workflows.
* Perimeter Protection & Incident Monitoring
* WAF Integration: Partner with infrastructure and cloud engineering teams to Develop custom WAF rules to safeguard against OWASP vulnerabilities.
- Analyze WAF logs and fine-tune security policies to minimize false positives.
- SIEM Logging & Integration: Architect and implement structured, standardized logging patterns within our Java services to enable seamless event ingestion, correlation, and alerting in Security Information and Event Management (SIEM) systems (e.g., Splunk, Datadog, Microsoft Sentinel).
* Secure AI & API Integration
- AI & LLM Integration: Design and implement backend integrations with Large Language Models (LLMs) and AI platform endpoints (e.g., OpenAI, Azure OpenAI, AWS Bedrock).
- RAG Architectures: Build and maintain Retrieval-Augmented Generation (RAG) pipelines, ensuring that corporate data sources are safely queried, contextually injected, and filtered.
* Collaboration & Compliance
- Deliver clear documentation including technical integration guides, identity flow architecture diagrams, and run books.
- Work collaboratively with DevOps, Cloud Infrastructure, and Compliance teams to align development practices with internal security policies and external compliance requirements.
- Data Sovereignty: Assist in the architectural planning, database schema split, and data migration strategies required to establish an isolated EU-specific instance to comply with GDPR
Requirements
- Core Java Mastery: 5+ years of professional experience developing enterprise-grade software applications using Java (Spring Framework / Spring Boot).
- Identity Protocols: Strong hands-on experience designing and troubleshooting complex identity federation flows using SAML 2.0, OpenID Connect (OIDC), OAuth 2.0, and JWT.
- CIAM/IAM Expertise: Deep familiarity with integrating apps with Customer Identity systems and major IdPs (e.g., Okta, Auth0, Keycloak).
- Application Security (AppSec): Thorough understanding of cryptography, transport security (TLS/SSL), API security, and secure coding fundamentals.
- Perimeter Security: Experience coordinating and troubleshooting Web Application Firewall (WAF) rule sets, traffic filtering, and rate limiting.
- SIEM & Logging Infrastructure: Practical experience setting up application logging frameworks (Logback, Log4j2) to output security event formats consumable by SIEM monitoring tools.
- Contractor Mindset: Proven ability to work independently in a fast-paced environment with minimal supervision; highly organized and milestone-driven., * Familiarity with containerization technologies (Docker, Kubernetes) and secure cloud deployment architectures (AWS, Azure, or OCI).
- Experience working with Picture Archiving and Communication Systems (PACS) for medical devices using DICOM (DICOM (Digital Imaging and Communications in Medicine) protocol.
- Understanding of modern regulatory frameworks (e.g., GDPR, NIS2, or HIPAA/HITRUST) as they relate to application security and data privacy.
- Relevant industry certifications are a plus.
Benefits & conditions
3.93.9 out of 5 stars Loveland, CO 80538 Hybrid work $70 - $90 an hour - Contract, Pulled from the full job description
- Referral program
- Employee discount
- Vision insurance
- Dental insurance
- Life insurance
- Disability insurance
- Credit union membership, At Ledgent Technology, we prioritize our contractors, whom we proudly call Ambassadors. Our commitment to you is demonstrated through a comprehensive benefits program that stands out in the temporary staffing industry. We annually review and update our vendor relationships to ensure we provide the most cost-effective benefits options. Our Ambassadors are eligible for a wide range of benefits, including:
- Minimum Essential Coverage (MEC) Plan
- Basic and enhanced hospital indemnity plans
- Dental and vision coverage
- Accident and critical illness plans
- Term life insurance
- Short-term disability plan
- Direct deposit/pay card options
- Credit union membership
- Employee discount clubs
- Referral bonuses
- Training and coaching
- Specialized recognition programs
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
93 Java Interview Questions You Should Prepare For
Why Upskilling And Reskilling is Important For Developers
Is Software Engineering Over-Saturated?
Dev Digest 121 - AI goes offline