Responsibilities
- Design, develop, and maintain secure backend applications using Java, Spring Boot, and modern microservices architecture.
- Identify, remediate, and prevent security vulnerabilities including SQL Injection, CSRF, XSS, insecure secrets management, and exposure of sensitive information.
- Build and secure REST APIs using authentication, authorization, encryption, and industry-standard security controls.
- Partner with engineering, architecture, and cybersecurity teams to improve backend architecture, security posture, and application resilience.
- Champion secure coding practices, code reviews, and continuous improvement across the software development lifecycle.
Requirements
- Strong commercial experience developing backend applications using Java, Spring Boot, and RESTful APIs.
- Experience working on application security initiatives, vulnerability remediation projects, or secure software development within enterprise environments.
- Strong understanding of backend security fundamentals including authentication vs. authorization, CSRF protection, SQL injection prevention, secure secrets management, XSS mitigation, and protection of personally identifiable information (PII).
- Experience designing or supporting secure microservices architectures, including secure service-to-service communication and API security.
- Strong communication and collaboration skills with the ability to work effectively across multidisciplinary engineering teams.
Nice to Have
- Experience working within financial services or other highly regulated industries.
- Knowledge of OAuth2, OpenID Connect, JWT, TLS, mTLS, or API gateway security.
- Experience with cloud platforms such as AWS, Azure, or Google Cloud and their security services.
- Familiarity with DevSecOps practices, CI/CD security scanning, and automated vulnerability management.
- Security-related certifications such as CSSLP, Security+, AWS Security Specialty, or similar.
Work Arrangement
Hybrid — Toronto