Senior Java Security Engineer

Cream City Cyber

Milwaukee (WI)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary
Health benefits
Professional development opportunities

Job summary

A cybersecurity firm in Milwaukee seeks a Senior Java Security Engineer to secure high-performance backend services. The ideal candidate will have substantial Java experience and a deep understanding of application security. This role includes developing secure microservices, conducting threat modeling, and ensuring compliance with security standards. If you have a passion for building secure systems and can lead secure design discussions, this opportunity is for you.

Qualifications

  • 7+ years of experience in backend software engineering with significant Java depth.
  • Proven experience building and securing production-grade Java services.
  • Experience with secure API design patterns and authentication/authorization.

Responsibilities

  • Design and implement robust, secure Java backend services and APIs.
  • Conduct secure code reviews and threat modeling.
  • Collaborate with cross-functional teams to embed security best practices.

Skills

Java proficiency
Secure coding practices
Threat modeling
Microservices architecture
API security

Education

Bachelor's degree in computer science or related field

Tools

Spring/Spring Boot
PostgreSQL
Docker
Git

Job description

At Cream City Cyber, we understand the convergence of physical and digital risks and how they impact businesses and governments alike. Our battle-tested experts have been trusted advisors for decades, offering tailored security solutions to help clients navigate evolving landscapes. We strive to mitigate risks with confidence, enabling our partners to thrive in a connected world.

We are seeking a talented, self-motivated Senior Java Security Engineer who is passionate about application security and building secure, high-performance backend services and platforms. The ideal candidate will have deep hands-on experience designing, building, and securing Java-based systems (microservices, APIs, and supporting infrastructure) with a security-first mindset. This role is focused on consulting and evaluating secure software engineering and application security, including architecture reviews, secure coding practices, threat modeling, vulnerability remediation, and secure SDLC enablement. This is a unique opportunity to contribute to critical systems that protect millions of users globally. If you are passionate about building secure, scalable products and are eager to shape the future of our digital platform, this role is for you!

Key Responsibilities
Development and Implementation
  • Design, develop, and maintain robust, scalable Java backend services and APIs using modern frameworks (e.g., Spring/Spring Boot, Jakarta EE).
  • Build and evolve secure microservices architectures, including service-to-service authentication, authorization, and secure communication patterns.
  • Contribute to the entire development lifecycle, from concept and design to deployment and maintenance, with a security-first mindset.
  • Help design and implement comprehensive security architectures for backend platforms, ensuring secure data flow across services, APIs, and supporting systems.
  • Optimize performance, reliability, and scalability while enforcing secure coding standards and defensive programming practices.
Security and Quality Assurance
  • Conduct manual and automated secure code reviews (primarily Java) to identify security flaws and improve code quality.
  • Perform threat modeling, identify vulnerabilities, and develop risk mitigation strategies for APIs, services, and distributed systems.
  • Troubleshoot, debug, and upgrade existing systems, ensuring security patches and dependency updates are applied promptly.
  • Ensure compliance with standards such as OWASP Top 10, secure API best practices, and data privacy/security requirements.
  • Integrate and manage database technologies such as PostgreSQL, MySQL, Oracle, or MongoDB, ensuring secure configurations, encryption, and safe query patterns.
  • Partner with engineering teams to build strong authentication and authorization (e.g., OAuth2/OIDC, JWT, RBAC/ABAC) and implement secure secrets management.
Collaboration and Cross-Functional Teamwork
  • Collaborate with cross-functional teams (engineers, leadership, risk analysts, operations, etc.) to embed security and best practices throughout the SDLC.
  • Partner with developers and platform teams to ensure encryption in transit/at rest, secure key management, and secure data storage are integral to connected applications.
  • Collaborate with teams to integrate and automate security checks, SAST/SCA, dependency scanning, and vulnerability management within CI/CD pipelines.
  • Write clear technical documentation, contribute to secure engineering guidelines, and provide support where required.
Maintenance and Continuous Improvement
  • Stay updated on emerging security threats, technologies, and industry trends to continuously improve our applications’ security posture.
  • Manage the vulnerability lifecycle from discovery through remediation, verification, and monitoring.
  • Ensure secure API integrations to prevent injection attacks, data exposure, broken auth, SSRF, deserialization, and other common vulnerabilities.
  • Help inform, develop, and enforce security policies, standards, and guidelines for secure software development practices.
  • Champion secure-by-design improvements such as standardized libraries, secure frameworks, and reusable security components.
Required Qualifications
  • Bachelor’s degree in computer science, software engineering, or a related field, and 7+ years of experience in backend software engineering with significant Java depth.
  • Proven experience building and securing production-grade Java services using Spring/Spring Boot (or comparable Java frameworks).
  • Strong proficiency in Java (modern versions preferred), including concurrency, performance tuning, JVM fundamentals, and secure coding practices.
  • Demonstrated understanding of application security vulnerabilities (e.g., OWASP Top 10) and remediation techniques in real-world systems.
  • Experience with secure API design patterns (REST and/or gRPC), authentication/authorization, and secure session/token handling.
  • Experience with database technology such as PostgreSQL, MySQL, Oracle, and/or MongoDB, including secure schema design and safe query patterns.
  • Familiarity with version control tools like Git and modern CI/CD workflows.
  • Experience with common security tooling and practices such as SAST, SCA, secrets scanning, dependency management, and SBOM fundamentals.
Preferred Qualifications
  • Relevant security certifications (e.g., CISSP, CSSLP, GIAC, CEH, GWEB).
  • Experience with application security testing tools and workflows (e.g., Burp Suite, OWASP ZAP, SAST/SCA platforms, container/image scanning).
  • Experience with cloud platforms (AWS, Azure, GCP) and containers (Docker, Kubernetes) including secure deployment patterns.
  • Knowledge of secure architecture for distributed systems (zero trust principles, service meshes, mTLS, policy-as-code).
  • Familiarity with regulatory or compliance frameworks (SOC 2, ISO 27001, PCI, HIPAA) as they relate to application security controls.
  • Problem-Solving: Ability to think like an attacker, identify threats, and architect robust, scalable, and secure solutions.
  • Strong Communication: Capable of explaining complex technical and security concepts to both technical and non-technical stakeholders.
  • Collaboration: Excellent at working with cross-functional teams to achieve shared goals and build secure, high-quality products.
  • Continuous Learning: Passionate about staying updated on the latest Java development and security trends.
  • Attention to Detail: Thorough in code implementation, reviews, architecture design, and security assessments.

Ideal Candidate

The ideal candidate for this role has built and supported multiple Java-based services in production, understands secure software engineering practices, and has a strong track record of improving the security posture of complex systems. They can lead secure design discussions, perform deep code and architecture reviews, and drive practical remediation across teams. We are looking for individuals who either have, or want to further develop, strong cybersecurity expertise while maintaining the development skillset and ownership mindset of a senior software engineer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Java, Full-stack Engineer – Security Engineer
Java, Full-stack Engineer – Security Engineer

Jobtailor • North Carolina

On-site
USD 100,000 - 140,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Backend Engineer
Backend Engineer

Compunnel, Inc. • New York (NY)

On-site
USD 110,000 - 150,000
Principal Java Software Engineer
Principal Java Software Engineer

Stay Gold Solutions • California (MO)

Remote
USD 90,000 - 150,000
Industry-competitive salary
Stock grants
Performance bonuses
+7
Java Software Engineer
Java Software Engineer

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 120,000 - 150,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Application Security Engineer
Application Security Engineer

ALLTECH CONSULTING SVC INC • Georgia

On-site
USD 100,000 - 130,000
Software Development Engineer (Java & Application Security)
Software Development Engineer (Java & Application Security)

Aptonet • Omaha (NE)

On-site
USD 110,000 - 140,000