Senior Application Security Engineer

Marlabs — United States · Posted ~23 hours ago

Senior Full-time Remote

Skills

Java Azure Application Security Cloud Security CI/CD Vulnerability Remediation Cloudflare WAF

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior security-focused engineering role responsible for improving application security, modernizing enterprise services, strengthening cloud environments, and implementing secure development practices. The ideal candidate has strong backend development experience and expertise in cloud security operations.

Highlights

Opportunity to work on complex security initiatives, cloud modernization, vulnerability remediation, and secure software development across diverse technical environments.

Description

Sr. Application Security Engineer (Java & Azure) Remote – if hired must go in IG office to get verified Day to day: We are currently seeking a motivated Senior Software Engineer / Developer to support data engineering and application security initiatives. This centralized role will support a broad portfolio of technical application teams and will be shared across multiple remediation, modernization, and security implementation efforts. The role will focus on remediating security vulnerabilities across cloud, batch, and application environments; modernizing Java-based services; improving CI/CD and deployment automation; supporting secrets and credential lifecycle remediation; enabling secure cloud migration patterns; provisioning and validating cloud infrastructure; strengthening application inventory and ownership controls; supporting batch and legacy workload remediation; and implementing security controls such as WAF (Cloudflare), logging, tagging, policy guardrails, automated patching, regression testing, operational readiness, and evidence collection. The engineer will partner with a wide range of application teams, platform teams, security stakeholders, operations teams, and project leadership to translate high-level security requirements into practical engineering deliverables. Duties: • Serve as a centralized engineering resource shared across multiple technical application teams, balancing priorities, coordinating dependencies, and supporting concurrent remediation and modernization efforts • Design, test, debug, implement dynamic applications and user interfaces using Java and PrimeFaces • Maintain Java applications and services in Microsoft Azure • Work with users to understand requirements then elicit feedback and refine solution through demonstrations • Present the solution at formal and informal design reviews and document the design • Strong initiative: must be able to take a high-level requirement, ask questions, seek clarifications, and get the job done • Support application security and cloud modernization initiatives including vulnerability remediation, secrets remediation, credential lifecycle enforcement, WAF implementation readiness, secure image adoption, CI/CD pipeline automation, cloud tagging, observability, and policy guardrail implementation • Analyze security dashboards, vulnerability findings, scan results, and exception requests to prioritize remediation activities and identify false positives, compensating controls, and required application changes • Develop and update automation scripts, deployment pipelines, infrastructure-as-code modules, and remediation utilities using tools such as Terraform, Ansible, Jenkins, GitHub Actions, or similar platforms • Implement or support secure application patterns including managed services, containerization, serverless migration, automated patching, Chainguard base images, least-privilege access, and secrets management integrations • Partner with application owners to prepare WAF implementations by validating application inventories, DNS dependencies, audit-mode readiness, policy visibility, security event logging, and Sentinel integration requirements • Provision, configure, and validate non-production and production cloud environments, including networking dependencies, access controls, deployment readiness, tagging, monitoring, and security baseline requirements • Validate application inventories, ownership records, system dependencies, and remediation accountability to support prioritization, implementation planning, and audit readiness • Support remediation of batch operations, legacy workloads, scheduled processing, and related infrastructure dependencies while coordinating with operations teams to minimize production impact • Plan and execute regression testing after remediation activities such as patching, dependency upgrades, secure image adoption, WAF policy changes, configuration updates, and cloud migration work • Produce technical documentation, remediation evidence, design notes, developer guidance, runbooks, and status updates needed for implementation tracking, audit readiness, and leadership reporting Required Technical Experience: • Experience as Senior Developer on large web application UI's from start to finish • Expertise with Java, JavaScript, Spring, Hibernate, JSON, HTML4/5, AJAX, JSF, CSS, JDBC • Experience with Eclipse (or alternates: IntelliJ, VS Code), Jira, and Git for design, development, and testing • Extensive JavaScript framework experience (ex. Angular JS, Bootstrap) • Experience writing and consuming web services (SOAP/RESTful) • Experience with web security, WAF, OAuth, HTTP/s, HSTS, etc. • Experience in Java Web Containers (Tomcat etc.) • Experience migrating applications to cloud infrastructure (Azure, AWS, OpenStack) • Experience writing deployment scripts (Ansible, Terraform, Jenkins) • Experience working with customers and team members to define requirements and demonstrate solutions • Experience designing and delivering complex, highly scalable software components • Experience utilizing various debugging tools and methodologies for debugging UI and components • Experience with vulnerability management tools and processes, including interpreting findings from scanners and security platforms, prioritizing P1-P4 vulnerabilities, validating remediation, and documenting exceptions • Hands-on experience with secrets remediation and credential lifecycle controls, including AWS access keys, Azure service principal credentials, credential rotation, least-privilege access, and integration with approved secrets management solutions • Experience with secure CI/CD practices, pipeline scanning, policy-as-code, infrastructure-as-code, automated deployment controls, and developer workflow integration for security tools such as Wiz Code, Mend, Snyk, Dependabot, JFrog Artifactory, or similar platforms • Experience implementing or supporting WAF solutions and related security controls, including Cloudflare, Imperva, Radware, AWS WAF, Azure WAF, policy management, management console access, security event logging, and Microsoft Sentinel integration • Experience with container security, hardened base images, ChandiGuard or equivalent secure images, automated patching, dependency upgrades, regression testing, and migration from VM-based workloads to PaaS, containers, serverless, or managed services where appropriate • Experience provisioning and validating Azure infrastructure across non-production and production environments, including network configuration, identity and access controls, resource tagging, deployment pipelines, monitoring, and security baseline validation • Experience supporting application inventory cleanup, ownership validation, dependency mapping, server fingerprinting, remediation tracking, dashboard validation, and evidence repository maintenance • Experience supporting migration, modernization, or decommissioning of legacy workloads, including evaluating VM-based applications for managed services, containers, serverless platforms, or retirement where appropriate • Experience supporting cloud governance and inventory controls, including resource tagging, ownership identification, server fingerprinting, dashboard validation, logging, monitoring, observability, and audit evidence collection Major Pluses: • Developing 100% automated unit tests • Must be able to multitask efficiently and progressively and work comfortably in an ever-changing data environment • Must work well in a team environment as well as independently • Excellent verbal/written communication and problem-solving skills, ability to communicate information to a variety of groups at different technical skill levels? Qualifications Needed: • Bachelor's degree or equivalent experience • 5+ years of software development, coding, and scripting experience • 5+ yrs. Cloud / Azure Development experience required • Experience in Linux environment and Windows? • 5+ yrs. Java, HTML, JavaScript and framework libraries required • Tomcat based environment is preferred • Experience remediating application, infrastructure, dependency, container image, secrets, and cloud configuration vulnerabilities across Java, Linux, Windows, AWS, Azure, and GitHub environments • Experience working with information security, platform engineering, DevOps, SRE, application development, and project management teams to deliver security remediation outcomes • Experience working in a shared-services or centralized delivery model, supporting multiple application teams, managing competing priorities, and coordinating across diverse technical stakeholders • Experience supporting operational handoff and production readiness activities, including runbooks, support models, monitoring, escalation paths, release coordination, and transition to steady-state support