Java Developer (Application Security)

WACKOWAVE INC
Raleigh, NC, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$100,000.0 - $120,000.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Software System Penetration Testing Application Performance Management Encodings Cross-Site Request Forgery Data Validation Software Debugging Enterprise JavaBeans Java Platform Enterprise Edition (J2EE) Ext JS Hibernate (Java) IBM Websphere Application Server
+16 more
Java Persistence API JavaScript Libraries JQuery Open Web Application Security Scrum Methodology Secure Coding Web Application Security Session Management Software Engineering Software Vulnerability Management Java Application Server Spring-mvc Software Security Cross-Site Scripting (XSS) Backend Vulnerability Analysis

Job description

Java Developer with Application Security expertise to design, develop, and maintain secure enterprise-grade Java applications. The ideal candidate will possess strong Java/J2EE development skills along with hands-on experience identifying, analyzing, and remediating application security vulnerabilities.

This role requires close collaboration with development, infrastructure, and security teams to ensure applications comply with enterprise security standards and secure coding best practices., * Design, develop, and maintain secure Java/J2EE-based applications.

  • Build and support backend components using:
  • Core Java
  • Spring MVC
  • EJB
  • Hibernate
  • JPA
  • Identify, analyze, and remediate application security vulnerabilities, including:
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Insecure Direct Object References (IDOR)
  • Session Fixation
  • Path Traversal
  • Collaborate with security teams to address findings from:
  • Vulnerability Assessments
  • Penetration Testing
  • Security Audits
  • Implement secure coding practices including:
  • Input Validation
  • Output Encoding
  • Authentication & Authorization Controls
  • Maintain and upgrade third-party libraries and frameworks, ensuring vulnerable versions are removed.
  • Configure and enforce web security controls such as:
  • Content Security Policy (CSP)
  • Secure Cookies (HttpOnly, Secure, SameSite)
  • Cache Control Directives
  • Troubleshoot and resolve application issues including:
  • HTTP 500 Errors
  • Session Management Problems
  • Application Performance and Security Issues
  • Participate in Agile/Scrum ceremonies and collaborate with cross-functional teams.

Requirements

Do you have experience in Vulnerability management?, * Minimum 5+ years of experience in Java/J2EE application development.

  • Strong hands-on expertise with:
  • Java 8+
  • Spring MVC
  • EJB
  • Hibernate
  • JPA
  • Minimum 3+ years of Application Security experience, including vulnerability remediation.
  • Experience addressing security vulnerabilities such as:
  • XSS
  • CSRF
  • IDOR
  • Session Management Vulnerabilities
  • Path Traversal
  • Experience implementing secure coding and OWASP best practices.
  • Minimum 1+ year of Agile/Scrum experience.
  • Strong debugging and troubleshooting skills.

Preferred Qualifications

  • Experience with IBM WebSphere Application Server.
  • Knowledge of OWASP Top 10 security risks and mitigation strategies.
  • Experience working with security scanning and vulnerability management tools.
  • Familiarity with JavaScript libraries such as:
  • Axios
  • jQuery
  • Ext JS

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • Paid time off
  • Vision insurance
  • Health savings account
  • Dental insurance, * Dental insurance
  • Health insurance
  • Health savings account
  • Paid time off
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

3:04 min

Revisiting jQuery 4 and its historical web impact

Chris Heilmann +3 · LIVE

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:12 min

Choosing TypeScript for complex backend applications

Maximilian Otto Maximilian Otto · WWC 2024

1:30 min

Lessons from jQuery and early JavaScript frameworks

Victor Savkin Victor Savkin · WWC Europe 2026

2:39 min

Identifying legacy code patterns and vulnerabilities

Shaaf Syed Shaaf Syed · WWC 2025

Videos

See all

Related articles

See all