TopQuadrant is seeking a Security Engineer with expertise in Java and the Spring Framework to enhance security in enterprise applications. This role involves securing Java-based systems and ensuring compliance with data protection regulations.
Requirements
- Design and implement security solutions for Java-based applications
- Secure applications, microservices, APIs, and databases against vulnerabilities
- Perform static (SAST) and dynamic (DAST) security testing
- Perform quarterly Vulnerability Scans and annual Penetration Test
- Manage application dependencies and vulnerabilities within established SLAs
- Implement and support authentication (OAuth, SAML), authorization (RBAC), and encryption
- Integrate security into the CI/CD pipeline to automate security testing and compliance checks
- Monitor, analyze, and respond to security incidents and security questionnaires
- Manage Drata for security monitoring, compliance automation, and audit readiness
- Ensure compliance with data protection regulations (GDPR, CCPA, HIPAA) and security frameworks (ISO 27001, NIST, SOC 2)
- Collaborate with development teams to enforce secure coding best practices via code reviews
- Work with Spring Security to enforce access controls and secure distributed applications
- Maintain and publish TopQuadrant’s Authorized Software List
- Stay updated on the latest security vulnerabilities affecting Java and Spring ecosystems