Software Principal Engineer
Serves as the technical authority for product security, triaging vulnerabilities, implementing fixes in a complex Java backend, and guiding threat modeling and secure development. Requires 8–10 years of Java backend engineering or security research experience, with expertise in PKI, cryptography, application security, and cloud-native environments.
About the job
Responsibilities
- Own the lifecycle of security issues reported by customers and automated scans.
- Analyze incoming reports to determine severity, exploitability, and business impact, including identifying false positives.
- Design and implement high-quality, performant fixes in a complex Java backend environment.
- Consult with product teams to integrate security by design into the development lifecycle.
- Conduct architectural threat-modeling reviews to identify weaknesses before production.
- Direct the strategy for maintaining or migrating legacy cryptographic implementations using RSA BSAFE (Crypto-J / SSL-J) to support FIPS 140-2/3 compliance.
Requirements
- 8–10 years of experience in backend engineering with Java and/or security research.
- Proven experience fixing vulnerabilities in a large-scale Java production environment.
- Deep expertise in Core and Enterprise Java and common frameworks such as Spring Boot and Hibernate.
- Hands-on experience designing and maintaining Public Key Infrastructure, including integrations among Certificate Authorities, Registration Authorities, and the Java application layer.
- Strong understanding of the OWASP Top 10 and attack vectors including XSS, SQL injection, CSRF, SSRF, and deserialization flaws.
- Experience with SAST, DAST, and SCA tools such as Nessus, Veracode, or Burp Suite.
- Familiarity with securing cloud-native applications on AWS, Azure, or Google Cloud and containerized environments using Docker and Kubernetes.
Nice-to-haves
- CISSP, CSSLP, OSCP, or GWEB certification. Certifications are a plus but do not substitute for hands-on experience.
Skills
Java, Spring Boot, Hibernate, Public Key Infrastructure, Owasp Top 10, SAST, DAST, Sca, Burp Suite, AWS, Azure, GCP, Docker, Kubernetes, Rsa Bsafe
Similar jobs
Security Engineering jobsSenior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.
Leads application and AI security assessments across web, API, cloud-native, and LLM-based systems. Requires 8+ years of cybersecurity experience, hands-on penetration testing and secure SDLC expertise, and experience adversarially testing AI applications.
The Senior Security Engineer will build and operate detection and incident-response capabilities across cloud production and corporate environments. The role requires 7+ years of security engineering experience, AWS expertise, threat hunting, investigations, automation, and SIEM/SOAR proficiency.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.