Software Principal Engineer
Core
Own the lifecycle of security issues, design and implement vulnerability fixes, and integrate security-by-design practices into a complex Java backend environment.
Role type
Principal Security Engineer (Java Backend)
Builds
Secure Java backend services and cryptographic implementations
Domain
Cybersecurity / Backend Engineering
Deliverable
production ML models | product features
Required skills
Java (Core/Enterprise/Spring Boot/Hibernate), Public Key Infrastructure (PKI), Cryptography (RSA BSAFE, FIPS 140-2/3), Threat Modeling, Vulnerability Management, OWASP Top 10, SAST/DAST/SCA tools, Cloud Security (AWS/Azure/GCP), Container Security (Docker/Kubernetes)
Preferred skills
CISSP, CSSLP, OSCP, GWEB
Technologies
Java, Spring Boot, Hibernate, RSA BSAFE, Nessus, Veracode, Burp Suite, Docker, Kubernetes, AWS, Azure, GCP
Responsibilities
Analyze vulnerability reports to determine severity and exploitability; Design and implement high-quality vulnerability fixes; Conduct architectural threat modeling and security reviews; Direct maintenance or migration of legacy cryptographic implementations; Design and maintain PKI integrations; Mentor teams on product security practices
Seniority
Senior, hands-on IC