Senior Java Software Engineer

InRhythm

Pune District

Hybrid

INR 1,800,000 - 3,200,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

InRhythm, a boutique technology firm, is seeking a Senior Software Engineer for Corporate Security Engineering in Pune. The role emphasizes end-to-end ownership of secure service platforms, cryptographic key management, and PCI/regulatory‑driven controls within a fast-paced, security‑critical environment.

You will design, implement, test, and deploy high‑assurance components, mentor peers, and collaborate across time zones to ensure robust, scalable solutions for enterprise clients.

Qualifications

  • Expert understanding of software engineering concepts and patterns.
  • Experience designing and operating multi-tenant service platforms and RESTful APIs.
  • Strong grasp of concurrency, transactional integrity, idempotency, and resilience in distributed systems.

Responsibilities

  • Plan, design, develop, and deliver technical solutions meeting security standards.
  • Own substantial features end-to-end across services including API design and persistence.
  • Perform hands-on development and code reviews to improve design clarity and security.
  • Design and evolve APIs in an API-first, backward-compatible manner.
  • Contribute to platform architecture with architects and leads; refine ADRs and trade‑offs.
  • Define requirements for new applications and translate security needs into specs.
  • Drive engineering quality with tests, static analysis, and CI/CD pipelines.
  • Diagnose and resolve production and pre‑production issues across cryptographic and multi‑region systems.
  • Participate in on-call rotations and improve observability and automation.
  • Mentor junior engineers and onboard new joiners to the domain.
  • Collaborate across teams across time zones to deliver coherent solutions.

Skills

Security engineering
API design
Distributed systems
Cryptography
Code review
Observability

Tools

Java (modern)
Spring Boot
PostgreSQL
Kafka
Docker

Job description

InRhythm is a boutique technology consulting firm based in New York City, founded in 2002, focused on product innovation and platform modernization for Fortune 500 companies. The firm partners with clients across wealth & asset management, payments, and enterprise sectors — including names like American Express, Goldman Sachs, Mastercard, and Morgan Stanley — to accelerate digital transformation through senior engineering expertise, agile delivery, and AI-driven modernization. InRhythm has been recognized on the Inc. 5000 list of America's fastest-growing companies for multiple consecutive years, including a place in the Inc. 5000 Hall of Fame.


Location: Pune, Maharashtra


Work Mode: Hybrid


Shift Timings: UK Shift (12:00 PM – 9:00 PM)


Experience Required: 6+ years


Overview

Corporate Security Engineering is a global team that designs, builds, and operates the service platforms providing cryptographic, key management, and certificate management capabilities consumed by application teams across the enterprise.


Our inventory of shared services spans payment key management, EMV issuer certificate services, key translation, key distribution and synchronisation, HSM abstraction services, code signing, and the audit and monitoring capabilities that surround them.


These are high-assurance, highly available platforms — they sit on the critical path of payment and security flows, are subject to strict regulatory, PCI, and audit controls, and operate across multiple regions and data centres.


As a Senior Software Engineer, you will take end-to-end ownership of significant components of this estate — from design and implementation through to testing, deployment, observability, and production support — and act as a technical multiplier for the engineers around you.


Are you motivated to protect the most sensitive assets — its keys? Do you enjoy working in a fast-paced, security-critical, technically demanding environment where correctness genuinely matters?


The Role

What You Will Do


  • Plan, design, develop, and deliver technical solutions that meet business requirements while adhering to security standards, engineering processes, and best practices.

  • Own substantial features end-to-end across one or more services: API contract design, domain modelling, persistence, messaging, HSM integration, tests, documentation, deployment, and post-release support.

  • Perform significant hands‑on development and high-quality code review; raise the bar for design clarity, testability, error handling, and secure coding within the team.

  • Design and evolve service APIs in an API‑first / contract‑first manner, keeping changes backward compatible for consuming application teams and managing versioning and deprecation responsibly.

  • Contribute to the architecture of the platform: partner with Corporate Security Engineering Architects and Technical Leads on solution designs, ADRs, and trade‑off analysis, and challenge designs constructively.

  • Define and refine requirements for new applications and enhancements, translating business and security needs into workable technical specifications.

  • Drive engineering quality: meaningful unit, slice, integration, and contract tests, architecture conformance rules, static analysis, dependency hygiene, and automated build/release pipelines.

  • Diagnose and resolve complex production and pre‑production issues within your area of expertise, including cryptographic, HSM, messaging, data consistency, and multi‑region behaviours; drive root cause analysis and durable fixes.

  • Participate in a rotational on‑call support rotation for escalated issues, and continuously reduce operational toil through better observability, automation, and design.

  • Mentor and grow junior and mid‑level engineers through pairing, design reviews, code reviews, and knowledge sharing; onboard new joiners to the domain.

  • Work independently and self-directed: identify what needs doing, sequence it sensibly, communicate progress, and elevate early when blocked.

  • Collaborate across teams and time zones — with consuming application teams, security architecture, infrastructure, HSM operations, and audit — to deliver coherent solutions.


All About You


  • Expert understanding of software engineering concepts, patterns, and methodologies — clean layering (e.g., hexagonal / ports-and-adapters), domain modelling, separation of concerns, data structures, and algorithms.

  • Extensive experience designing, building, operating, and supporting shared, multi‑tenant service platforms and RESTful APIs used by many internal consumers.

  • Strong grasp of concurrency, transactional integrity, idempotency, resilience patterns, and failure modes in distributed systems.

  • Understands the need for quality tests and how to apply them: unit, integration, contract, and non‑functional testing; comfortable with test‑first and mutation/coverage-driven thinking.


Core Technology Stack


  • Java (modern LTS, 21+) as the primary language — deep, current, hands‑on expertise is essential.

  • Spring Boot 3.x and the wider Spring ecosystem (Spring Web / WebFlux, Spring Security, Spring Data, Spring Cloud); reactive programming with Project Reactor is a strong plus.

  • Gradle (Kotlin DSL), version catalogs, multi‑repo / composite builds, and CI/CD pipelines (Jenkins, Git‑based workflows).

  • OpenAPI‑first API design with code generation, API linting/governance, and disciplined versioning.

  • Relational databases and schema evolution: PostgreSQL, JPA/Hibernate, Flyway migrations, query performance, and data modelling.

  • Event‑driven and asynchronous messaging: Apache Kafka, event/command‑driven or CQRS‑style architectures (e.g., Axon), and reliable delivery patterns such as the transactional outbox.

  • Containerised delivery and cloud‑native operations: Docker, orchestration platforms, configuration and secret management (e.g., HashiCorp Vault), 12‑factor configuration.

  • Observability in production: structured logging, metrics, tracing, dashboards, and alerting — including how to instrument systems that must never log sensitive data.

  • Git and modern collaborative development practices (PR-based workflows, code review culture, semantic versioning).


Security and Cryptography


  • Good working knowledge of industry‑standard cryptographic algorithms and primitives — symmetric (AES, 3DES), asymmetric (RSA, ECC), hashing, MAC/CMAC, key derivation, and key wrapping — and sound judgement on how, where, and when to apply them.

  • Practical experience with key management concepts: key hierarchies, LMKs, transport/zone keys, key blocks (e.g., TR‑31), key ceremonies, rotation, custody, key states, and lifecycle.

  • Hands‑on experience integrating with Hardware Security Modules (e.g., Thales payShield, Entrust nShield) and cryptographic interfaces such as PKCS#11 and JCE/JCA.

  • PKI and certificate management: X.509, CA hierarchies, CSR/issuance flows, certificate lifecycle and validation; EMV issuer certificate concepts are a strong plus.

  • Secure service‑to‑service communication: TLS/mTLS, keystores and truststores, authentication/authorisation, and policy enforcement at the gateway.

  • Secure development mindset: threat modelling, least privilege, secure defaults, secrets handling, and an instinct for never exposing key material, PANs, cryptograms, or tokens in logs, traces, or errors.

  • Familiarity with payments domain standards and regulatory/compliance drivers (PCI DSS / PCI PIN / PCI P2PE, EMV, ISO 8583) is highly desirable.


Ways of Working


  • Expert critical‑thinking and problem‑solving skills; able to reason from first principles about unfamiliar, high‑stakes systems.

  • Highly motivated and proactive about the success of the team and the product, not just individual deliverables.

  • High‑energy, detail‑oriented, and able to handle multiple high‑priority demands while driving consistent, predictable results.

  • Excellent written and verbal communication; can explain complex cryptographic and architectural concepts to both specialist and non‑specialist audiences.

  • Comfortable working in a globally distributed team, and a demonstrated willingness to mentor, document, and share knowledge.


Nice to Have


  • Experience with multi‑region / active‑active deployments and the data‑consistency challenges they bring.

  • Experience modernising or decomposing legacy security services without disrupting existing consumers.

  • Exposure to chaos engineering, performance/load testing, or capacity planning for latency‑sensitive services.


Corporate Security Responsibility

Every person working for, or on behalf of, the organization is responsible for information security. All activities involving access to assets, information, and networks come with an inherent risk to the organisation and, therefore, it is expected that the successful candidate for this position must:



  • Abide by the organization's security policies and practices.

  • Ensure the confidentiality and integrity of the information being accessed.

  • Report any suspected information security violation or breach.

  • Complete all periodic mandatory security trainings in accordance with guidelines.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Operations Engineer
Staff Security Operations Engineer

Jobgether • India

Remote
INR 3,500,000 - 5,500,000
Remote-first environment
In-person team sprints abroad
Learning budget USD 2,000 (annual)
Information Technology-Security
Information Technology-Security

Yokohama-ATG • Mumbai

On-site
INR 3,500,000 - 6,000,000
Infrastructure Security Officer
Infrastructure Security Officer

Thompsons HR Consulting Pvt Ltd • Pune District

Hybrid
INR 1,200,000 - 1,800,000
IT Manager Security
IT Manager Security

Globalstep • Pune District

On-site
INR 1,800,000 - 2,400,000
Application Security Lead
Application Security Lead

Sagility • Bengaluru

On-site
INR 3,500,000 - 7,000,000
Information Security Manager
Information Security Manager

FCI CCM, Inc. • Dadri

On-site
INR 2,500,000 - 4,000,000
Principal Security Engineer
Principal Security Engineer

Cashfree • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Director Information Security
Director Information Security

Ocwen Financial Solutions Pvt. Ltd. - APAC • Bengaluru Urban

On-site
INR 3,000,000 - 4,500,000
Cybersecurity Engineer – Engineering
Cybersecurity Engineer – Engineering

Practice by Numbers • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Senior Information Security Engineer
Senior Information Security Engineer

Aspora • Bengaluru

On-site
INR 3,500,000 - 7,500,000