> Markdown version of [/jobs/ext/1840456-java-scala-developer](https://www.wearedevelopers.com/jobs/ext/1840456-java-scala-developer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Java/Scala Developer - **Company:** NESS INC - **Location:** United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Akka (Toolkit), Amazon Web Services, Application Integration Architecture, Software Applications, Software System Penetration Testing, Unit Testing, Code Review, Computer Programming, Data Validation, Event-Driven Programming, Interoperability, Java Virtual Machine (JVM), Key Management, PostgreSQL, OAuth, Open Web Application Security, Secure Coding, Software Engineering, Transport Layer Security, Software Security, Kubernetes, Apache Kafka, Functional Programming, Docker, Static Application Security Testing - **Published:** July 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=56d222cd23b14f24 ## About the Role * 5+ years of Java software development experience * 3+ years of Scala software development experience * 2+ years AKKA development experience * Experience working with Kafka * Experience working with Postgres * Experience with writing unit tests Preferred Qualifications: * Hands-on experience remediating application security findings (e.g., from SAST tools or penetration test reports) * Packaged application integration experience, including knowledge of and the ability to implement packaged application software and integrate it with technology platforms * Familiarity with transport security configuration (TLS/SSL) and secrets management in JVM-based services * Experience with JWT / OAuth 2.0 in a JVM context * Familiarity with CI/CD pipelines and security controls within build tooling Technical Skills: * Solid understanding of JVM internals and interoperability between Scala and Java * Familiarity with secure coding practices and common vulnerability classes (OWASP Top 10) * Knowledge of AWS and Kubernetes * Experience with Docker * Experienced in functional programming, and event driven programing * Familiarity with Actor model This contractor will not be working independently - they will be paired with our Clearing development lead and Application Security team to review findings, confirm fix approaches, and implement changes in accordance with existing coding standards. ## Description * Review findings identified by our Application Security team alongside the Clearing development lead, and develop a clear understanding of the vulnerability pattern and its root cause * Design and implement code fixes with an emphasis on consistent, repeatable solutions where the same vulnerability pattern appears in multiple locations * Write or update unit and integration tests to validate fixes and prevent regression * Follow existing coding standards and participate in code review with the development lead prior to merge The vulnerability categories in scope span authentication and authorization controls, transport security, secrets handling, input validation, and related secure coding domains. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) - [Microservices: how to get started with Spring Boot and Kubernetes](https://www.wearedevelopers.com/videos/242-microservices-how-to-get-started-with-spring-boot-and-kubernetes) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [93 Java Interview Questions You Should Prepare For](https://www.wearedevelopers.com/magazine/14-93-java-interview-questions-you-should-prepare-for)