Technical Lead - Application Security Remediation (Java / Spring Boot / Angular)

Purple Drive Technologies LLC
United States
3 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Code Review Continuous Integration DevOps Github Open Web Application Security Systems Development Life Cycle Secure Coding Software Engineering SonarQube TypeScript
+14 more
Software Vulnerability Management Enterprise Software Applications Spring-boot Sonatype Software Security Veracode AngularJS Checkmarx Software Coding Restful APIs Devsecops Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

  • Lead application security remediation initiatives across multiple engineering teams.
  • Analyze vulnerabilities and security findings from ArmorCode, Contrast Security, Snyk, SonarQube, and similar tools.
  • Prioritize vulnerabilities based on severity, risk, and business impact.
  • Track remediation activities and drive vulnerabilities to closure.
  • Perform hands-on coding to implement security fixes in Java/Spring Boot and Angular applications.
  • Conduct code reviews and recommend secure coding practices.
  • Develop reusable security remediation patterns to reduce recurring vulnerabilities.
  • Collaborate with Engineering, Architecture, Security, and DevOps teams.
  • Lead and mentor a 3-5 member security remediation team.
  • Monitor remediation progress and provide dashboards, status reports, and executive-level updates.
  • Support security governance, change management, and continuous improvement initiatives.

Requirements

10+ years of software engineering experience, Java Strong hands-on experience Spring Boot Strong hands-on experience Angular Strong hands-on experience JavaScript / TypeScript Strong hands-on experience REST APIs Required Microservices Required GitHub Required CI/CD Required OWASP Top 10 Strong understanding Secure SDLC Required DevSecOps Required SAST / DAST Required Vulnerability Management Required Security Tools ArmorCode, Contrast, Snyk, Veracode, Checkmarx, SonarQube or similar

Security & Governance

  • Strong understanding of application security principles and secure software development.
  • Experience identifying and remediating vulnerabilities throughout the SDLC.
  • Understanding of SAST, DAST, code scanning, dependency vulnerabilities, and security findings.
  • Experience with security governance and vulnerability tracking.
  • Ability to work with development teams to implement sustainable security improvements.

Leadership & Soft Skills

  • Strong technical leadership and mentoring capabilities.
  • Experience leading a small technical/security remediation team.
  • Excellent communication and stakeholder management skills.
  • Ability to work with engineering, architecture, security, and business stakeholders.
  • Strong problem-solving and analytical skills.
  • Ability to provide clear technical and executive-level status reporting.

Preferred Background

  • Experience in enterprise application security remediation.
  • Experience working with Java/Spring Boot and Angular applications.
  • Experience managing vulnerabilities across multiple applications or engineering teams.
  • Healthcare/security governance experience is beneficial if applicable.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:15 min

Correlating OpenSSF scorecard metrics with real vulnerability data

Niels Tanis Niels Tanis · World Congress 2024

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

2:41 min

Dynamic application security testing during the test phase

Milecia Mcgregor · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all