Java Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+12 more
Job description
We are looking for a Senior Java Security Engineer with strong expertise in Java Cryptography Architecture (JCA), Java Cryptography Extension (JCE), PKI, X.509 certificates, encryption, digital signatures, and secure application development., * Design and develop secure Java applications using industry-standard cryptographic practices.
- Implement encryption/decryption, hashing, digital signatures, key generation, and key-management mechanisms.
- Work extensively with JCA/JCE and Java security providers.
- Implement and manage AES, RSA, ECC and other cryptographic algorithms appropriately.
- Design and integrate PKI infrastructure, X.509 certificates, certificate chains, CSRs, keystores, truststores, and certificate lifecycle management.
- Implement and troubleshoot SSL/TLS configurations, mutual TLS (mTLS), cipher suites, and certificate validation.
- Develop secure authentication and authorization mechanisms using Spring Security, OAuth2, OpenID Connect, and JWT.
- Integrate applications with HashiCorp Vault, AWS KMS, HSMs, or other key-management platforms.
- Design secure approaches for encryption of data at rest and in transit.
- Participate in security architecture and threat-modeling activities.
- Conduct secure code reviews and identify cryptographic and application-security vulnerabilities.
- Establish and enforce secure coding standards and cryptographic best practices.
- Collaborate with application, cloud, DevOps, and security teams to implement enterprise security controls.
- Troubleshoot complex certificate, TLS, authentication, encryption, and key-management issues.
- Ensure solutions align with organizational security policies and relevant industry standards.
Requirements
5-7 years in Java development with strong hands-on experience in application security, cryptography, PKI, and secure software development., The ideal candidate will have hands-on experience implementing cryptographic solutions using AES, RSA, ECC, SSL/TLS, certificate management, OAuth2/JWT, and security frameworks such as Spring Security. Experience with cloud-based key management solutions such as AWS KMS and HashiCorp Vault is highly desirable., * Strong Java programming experience.
- JCA / JCE
- Java KeyStore (JKS), PKCS#12, truststores and keystores
- Java security providers and cryptographic APIs
- Secure coding and application security principles
Cryptography
- Symmetric encryption: AES
- Asymmetric cryptography: RSA, ECC
- Hashing: SHA-2/SHA-3 and related concepts
- Digital signatures and signature verification
- Key generation, storage, rotation, and lifecycle management
- Encryption at rest and encryption in transit
- Strong understanding of cryptographic primitives, algorithms, modes, padding, IVs/nonces, and randomness
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
93 Java Interview Questions You Should Prepare For
Java Basics
6 Reasons to Use Java For Your Next AI Project
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again