> Markdown version of [/jobs/ext/2737098-senior-java-technical-lead-application-security-remediation](https://www.wearedevelopers.com/jobs/ext/2737098-senior-java-technical-lead-application-security-remediation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Java Technical Lead - Application Security Remediation - **Company:** Purple Drive Technologies LLC - **Location:** McLean, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Code Review, Continuous Integration, DevOps, Github, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Engineering, SonarQube, TypeScript, Software Vulnerability Management, Enterprise Software Applications, Spring-boot, Sonatype, Software Security, Veracode, AngularJS, Checkmarx, Software Coding, Restful APIs, Devsecops, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** September 5, 2026 - **Apply:** https://www.careerjet.com/jobad/us84d7b8ca66c445550d77cbb817b1a4e3 ## About the Role 10+ years of software engineering experience, Java Strong hands-on experience Spring Boot Strong hands-on experience Angular Strong hands-on experience JavaScript / TypeScript Strong hands-on experience REST APIs Required Microservices Required GitHub Required CI/CD Required OWASP Top 10 Strong understanding Secure SDLC Required DevSecOps Required SAST / DAST Required Vulnerability Management Required Security Tools ArmorCode, Contrast, Snyk, Veracode, Checkmarx, SonarQube or similar Security & Governance * Strong understanding of application security principles and secure software development. * Experience identifying and remediating vulnerabilities throughout the SDLC. * Understanding of SAST, DAST, code scanning, dependency vulnerabilities, and security findings. * Experience with security governance and vulnerability tracking. * Ability to work with development teams to implement sustainable security improvements. Leadership & Soft Skills * Strong technical leadership and mentoring capabilities. * Experience leading a small technical/security remediation team. * Excellent communication and stakeholder management skills. * Ability to work with engineering, architecture, security, and business stakeholders. * Strong problem-solving and analytical skills. * Ability to provide clear technical and executive-level status reporting. Preferred Background * Experience in enterprise application security remediation. * Experience working with Java/Spring Boot and Angular applications. * Experience managing vulnerabilities across multiple applications or engineering teams. * Healthcare/security governance experience is beneficial if applicable. ## Description We are seeking a hands-on Senior Technical Lead to lead enterprise-wide application security remediation initiatives across multiple engineering teams. The role combines software development, application security, vulnerability management, and technical leadership. The candidate will analyze security vulnerabilities, define remediation strategies, implement security fixes across Java/Spring Boot and Angular applications, and drive secure development practices across engineering teams., * Lead application security remediation initiatives across multiple engineering teams. * Analyze vulnerabilities and security findings from ArmorCode, Contrast Security, Snyk, SonarQube, and similar tools. * Prioritize vulnerabilities based on severity, risk, and business impact. * Track remediation activities and drive vulnerabilities to closure. * Perform hands-on coding to implement security fixes in Java/Spring Boot and Angular applications. * Conduct code reviews and recommend secure coding practices. * Develop reusable security remediation patterns to reduce recurring vulnerabilities. * Collaborate with Engineering, Architecture, Security, and DevOps teams. * Lead and mentor a 3-5 member security remediation team. * Monitor remediation progress and provide dashboards, status reports, and executive-level updates. * Support security governance, change management, and continuous improvement initiatives. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)