> Markdown version of [/jobs/ext/458130-java-developer-application-security](https://www.wearedevelopers.com/jobs/ext/458130-java-developer-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Java Developer (Application Security) - **Company:** WACKOWAVE INC - **Location:** Raleigh, NC, United States - **Salary:** $100,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Software System Penetration Testing, Application Performance Management, Encodings, Cross-Site Request Forgery, Data Validation, Software Debugging, Enterprise JavaBeans, Java Platform Enterprise Edition (J2EE), Ext JS, Hibernate (Java), IBM Websphere Application Server, Java Persistence API, JavaScript Libraries, JQuery, Open Web Application Security, Scrum Methodology, Secure Coding, Web Application Security, Session Management, Software Engineering, Software Vulnerability Management, Java Application Server, Spring-mvc, Software Security, Cross-Site Scripting (XSS), Backend, Vulnerability Analysis - **Published:** June 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=eaf5011f32eabff8 ## About the Role Do you have experience in Vulnerability management?, * Minimum 5+ years of experience in Java/J2EE application development. * Strong hands-on expertise with: * Java 8+ * Spring MVC * EJB * Hibernate * JPA * Minimum 3+ years of Application Security experience, including vulnerability remediation. * Experience addressing security vulnerabilities such as: * XSS * CSRF * IDOR * Session Management Vulnerabilities * Path Traversal * Experience implementing secure coding and OWASP best practices. * Minimum 1+ year of Agile/Scrum experience. * Strong debugging and troubleshooting skills. Preferred Qualifications * Experience with IBM WebSphere Application Server. * Knowledge of OWASP Top 10 security risks and mitigation strategies. * Experience working with security scanning and vulnerability management tools. * Familiarity with JavaScript libraries such as: * Axios * jQuery * Ext JS ## Description Java Developer with Application Security expertise to design, develop, and maintain secure enterprise-grade Java applications. The ideal candidate will possess strong Java/J2EE development skills along with hands-on experience identifying, analyzing, and remediating application security vulnerabilities. This role requires close collaboration with development, infrastructure, and security teams to ensure applications comply with enterprise security standards and secure coding best practices., * Design, develop, and maintain secure Java/J2EE-based applications. * Build and support backend components using: * Core Java * Spring MVC * EJB * Hibernate * JPA * Identify, analyze, and remediate application security vulnerabilities, including: * Cross-Site Scripting (XSS) * Cross-Site Request Forgery (CSRF) * Insecure Direct Object References (IDOR) * Session Fixation * Path Traversal * Collaborate with security teams to address findings from: * Vulnerability Assessments * Penetration Testing * Security Audits * Implement secure coding practices including: * Input Validation * Output Encoding * Authentication & Authorization Controls * Maintain and upgrade third-party libraries and frameworks, ensuring vulnerable versions are removed. * Configure and enforce web security controls such as: * Content Security Policy (CSP) * Secure Cookies (HttpOnly, Secure, SameSite) * Cache Control Directives * Troubleshoot and resolve application issues including: * HTTP 500 Errors * Session Management Problems * Application Performance and Security Issues * Participate in Agile/Scrum ceremonies and collaborate with cross-functional teams. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [WeAreDevelopers LIVE - the weekly developer show with Chris Heilmann and Daniel Cranney](https://www.wearedevelopers.com/videos/1309-wearedevelopers-live-the-weekly-developer-show-with-chris-heilmann-and-daniel-cranney) - [Bulletproof Web Applications: The 2025 OWASP Top Ten](https://www.wearedevelopers.com/videos/100072-bulletproof-web-applications-the-2025-owasp-top-ten) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [Meta Harnesses: What the JS Framework Wars Teach Us About What Is Next for AI Agents](https://www.wearedevelopers.com/videos/100353-meta-harnesses-what-the-js-framework-wars-teach-us-about-what-is-next-for-ai-agents) ## Related Articles - [93 Java Interview Questions You Should Prepare For](https://www.wearedevelopers.com/magazine/14-93-java-interview-questions-you-should-prepare-for) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Top 10 Java Libraries](https://www.wearedevelopers.com/magazine/364-top-10-java-libraries) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)