Shift: Monday - Friday, standard 1st shift hours
Duration: 06 Months
Pay range: $83.33 - $98.48/hr.
Remote - but if a local candidate is chosen, there may be an onsite requirement/request.
Job Description
This is a hands-on engineering role focused on executing remediation work within existing production applications. The ideal candidate has strong Java development experience, practical application security remediation expertise, and the ability to quickly contribute in a fast-paced Agile environment.
Key Responsibilities
- Triage and prioritize application security findings from approved vulnerability management and scanning tools.
- Remediate application code vulnerabilities using secure coding best practices.
- Perform dependency, framework, library, runtime, and version upgrades while minimizing compatibility and regression risk.
- Resolve static analysis, software composition analysis (SCA), exposed secret, and repository security findings.
- Execute unit, integration, regression, and security testing to validate remediation efforts.
- Produce traceable remediation documentation, including pull requests, tickets, test results, scan results, and approval evidence.
- Collaborate with engineering, infrastructure, platform, and security teams to deliver remediation packages that meet defined acceptance criteria.
- Contribute reusable remediation patterns, documentation, and automation where appropriate.
Required Qualifications
โข 5+ years of enterprise software engineering experience.
โข Strong Java development experience supporting enterprise production applications.
โข Hands-on experience remediating application security vulnerabilities within existing codebases.
โข Experience with:
Dependency and library upgrades
CVE remediation
Static analysis findings
Software Composition Analysis (SCA)
Secret remediation
Secure application configuration
โข Experience using Git-based development workflows, including pull requests and branch management.
โข Knowledge of repository security controls such as code scanning, dependency alerts, secret scanning, and branch protections.
โข Experience developing REST APIs.
โข Experience building and executing automated unit, integration, and regression tests.
โข Ability to independently manage assigned remediation work while collaborating effectively within Agile teams.
โข Ability to produce clear remediation documentation and evidence supporting completed work.
โข Ability to work during U.S. Central Time business hours.
Preferred Qualifications
- Experience working in Kotlin codebases or the ability to quickly become productive within existing Kotlin applications.
- Experience with GitHub Advanced Security, Dependabot, Renovate, or comparable enterprise security tooling.
- Experience remediating vulnerabilities within JVM applications, microservices, APIs, or messaging platforms.
- Experience developing remediation automation, reusable engineering patterns, playbooks, or operational documentation.
Success Measures
Successful consultants will:
- Deliver assigned remediation packages that meet documented acceptance criteria.
- Resolve or properly disposition security findings with complete supporting evidence.
- Complete dependency and framework upgrades that successfully pass validation testing.
- Demonstrate measurable reduction of prioritized security backlog.
- Deliver reusable documentation and knowledge transfer that enables ongoing engineering support after the engagement.
Ideal Candidate
We are seeking senior Java engineers with proven experience remediating application security vulnerabilities in enterprise production environments. Candidates should be comfortable working independently, collaborating across engineering teams, and delivering high-quality remediation work with minimal oversight.
Experience working in Kotlin codebases is preferred but not required. Candidates with strong Java expertise who can quickly become productive within existing Kotlin applications are encouraged to apply.
This position is intended for hands-on software engineers who execute application security remediation-not security architects, governance specialists, or policy-focused security professionals.
Employee Benefits:
At LanceSoft, full time regular employees who work a minimum of 30 hours a week or more are entitled to the following benefits:
- Four options of medical Insurance
- Dental and Vision Insurance
- 401k Contributions
- Critical Illness Insurance
- Voluntary Permanent Life Insurance
- Accident Insurance
- Other Employee Perks
About LanceSoft
LanceSoft is rated as one of the largest staffing firms in the US by SIA. Our mission is to establish global cross-culture human connections that further the careers of our employees and strengthen the businesses of our clients. We are driven to use the power of our global network to connect businesses with the right people, and people with the right businesses without bias. We provide Global Workforce Solutions with a human touch.
Meet Your Recruiter
Pradeep Jha