
Lead Engineer
Majesco · Posted today
- India (Remote)
- Full-time
About the role
Job Description
Description for Internal Candidates
About The Role
We are seeking a hands-on Java Spring Boot Developer with strong application-security experience. The successful candidate will develop and maintain Java applications while independently analyzing, remediating, and validating vulnerabilities identified through Snyk, SonarQube, penetration testing, and VAPT assessments.
This role requires practical experience in secure coding, dependency management, authentication and authorization, security-focused code reviews, and DevSecOps. The candidate must be comfortable tracing security findings to source code or dependencies, implementing appropriate fixes, and providing evidence of successful remediation with minimal supervision.
Key responsibilities
- Develop, enhance, and maintain Java, Spring Boot, REST API, and microservices applications.
- Analyze security findings reported by Snyk, SonarQube, penetration tests, and VAPT assessments.
- Identify vulnerability root causes, affected code paths, dependency relationships, exploitability, and business impact.
- Remediate vulnerabilities through secure code changes, dependency upgrades, configuration changes, or approved mitigating controls.
- Address application-security issues involving authentication, authorization, access control, input validation, injection, secrets management, session management, file handling, logging, and secure configuration.
- Analyze direct and transitive dependency vulnerabilities and recommend upgrades, replacements, patches, or risk-based mitigation.
- Perform CVE, CWE, and CVSS-based risk assessment and remediation prioritization.
- Review and resolve findings from penetration testing and VAPT reports, including authentication bypass, exposed secrets, IDOR, XSS, CSRF, insecure file upload, and missing rate limiting where applicable.
- Implement and review authentication and authorization controls using Spring Security, OAuth 2.0, JWT, Keycloak, or similar frameworks.
- Participate in security-focused code reviews and recommend secure-coding improvements.
- Develop or update unit, integration, regression, and security tests to validate remediation and prevent recurrence.
- Re-run Snyk and SonarQube scans after fixes and document remediation evidence and closure status.
- Collaborate with development, QA, DevOps, and information-security teams to embed security checks into CI/CD pipelines.
- Provide clear technical documentation, remediation notes, risk explanations, and status updates.
- Independently manage assigned vulnerabilities through analysis, implementation, testing, and verified closure.
- Mandatory Qualifications And Skills
- Strong hands-on experience in Java and Spring Boot application development.
- Experience developing secure RESTful APIs and microservices.
- Demonstrated experience analyzing and remediating vulnerabilities reported by Snyk.
- Hands-on experience with SonarQube, including resolving security hotspots, vulnerabilities, bugs, and code-quality issues.
- Experience implementing fixes for penetration-testing and VAPT findings.
- Good knowledge of Maven or Gradle dependency management.
- Understanding of CVE, CWE, CVSS, OWASP Top 10, vulnerability severity, and remediation prioritization.
- Experience with Spring Security and authentication and authorization frameworks such as OAuth 2.0, JWT, or Keycloak.
- Experience writing unit and integration tests using JUnit, Mockito, or equivalent tools.
- Familiarity with Jenkins or another CI/CD platform and DevSecOps practices.
- Ability to work independently with security scan reports and implement fixes with minimal guidance.
- Strong debugging, analytical, documentation, and communication skills.
Preferred Qualifications
- Experience in insurance, banking, financial services, or another regulated industry.
- Exposure to OWASP ASVS, secure API design, threat modeling, or application-security standards.
- Experience with Burp Suite, OWASP ZAP, Black Duck, Fortify, Veracode, or similar tools.
- Experience with Docker, Kubernetes, AWS, or cloud-native applications.
- Relevant application-security certification or formal security training.
Skills
JavaSpring BootREST API developmentMicroservicesSecure codingDependency managementAuthentication and authorizationDevSecOpsCI/CD pipelines