# Software Principal Engineer

**Company:** [RSA](https://hotfix.jobs/companies/rsa)
**Location:** Bengaluru, India
**Role:** Security Engineering
**Experience:** 8+ years
**Skills:** Java, Spring Boot, Hibernate, Public Key Infrastructure, Owasp Top 10, SAST, DAST, Sca, Burp Suite, AWS, Azure, GCP, Docker, Kubernetes, Rsa Bsafe
**Posted:** 2026-05-11

> Serves as the technical authority for product security, triaging vulnerabilities, implementing fixes in a complex Java backend, and guiding threat modeling and secure development. Requires 8–10 years of Java backend engineering or security research experience, with expertise in PKI, cryptography, application security, and cloud-native environments.

## Job Description

## Responsibilities
- Own the lifecycle of security issues reported by customers and automated scans.
- Analyze incoming reports to determine severity, exploitability, and business impact, including identifying false positives.
- Design and implement high-quality, performant fixes in a complex Java backend environment.
- Consult with product teams to integrate security by design into the development lifecycle.
- Conduct architectural threat-modeling reviews to identify weaknesses before production.
- Direct the strategy for maintaining or migrating legacy cryptographic implementations using RSA BSAFE (Crypto-J / SSL-J) to support FIPS 140-2/3 compliance.

## Requirements
- 8–10 years of experience in backend engineering with Java and/or security research.
- Proven experience fixing vulnerabilities in a large-scale Java production environment.
- Deep expertise in Core and Enterprise Java and common frameworks such as Spring Boot and Hibernate.
- Hands-on experience designing and maintaining Public Key Infrastructure, including integrations among Certificate Authorities, Registration Authorities, and the Java application layer.
- Strong understanding of the OWASP Top 10 and attack vectors including XSS, SQL injection, CSRF, SSRF, and deserialization flaws.
- Experience with SAST, DAST, and SCA tools such as Nessus, Veracode, or Burp Suite.
- Familiarity with securing cloud-native applications on AWS, Azure, or Google Cloud and containerized environments using Docker and Kubernetes.

## Nice-to-haves
- CISSP, CSSLP, OSCP, or GWEB certification. Certifications are a plus but do not substitute for hands-on experience.

## Similar jobs

- [Senior Security Engineer](https://hotfix.jobs/jobs/2a1ede09-d608-462e-bb14-223603034206) - Greenlight - Bengaluru, India
- [Lead Security Engineer - Penetration Testing & AI Security](https://hotfix.jobs/jobs/ac8bc34d-2a43-4c67-870e-a1e01edee0cb) - GoHighLevel - Remote
- [Senior Security Engineer - DART](https://hotfix.jobs/jobs/8f733ffe-5874-43b6-9dcb-4a76ac35e099) - Rippling - Bengaluru, India
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Detection and Response Engineer](https://hotfix.jobs/jobs/ebb8ac3d-4282-4505-bdb8-4699d594df80) - Anyscale - $200k – $240k/yr

**Apply:** https://hotfix.jobs/jobs/aab0de4d-086d-4046-80ac-eabc3039854a
**Canonical:** https://hotfix.jobs/jobs/aab0de4d-086d-4046-80ac-eabc3039854a