
Software Principal Engineer
RSA Security, LLC10 hours ago
Bengaluru, IndiaStaff+
Responsibilities
- Own the lifecycle of security issues reported by customers and automated scans.
- Analyze vulnerability reports to determine severity, exploitability, business impact, and false positives.
- Design and implement high-quality, performant vulnerability fixes in a complex Java backend environment.
- Advise product teams and integrate security-by-design practices into the development lifecycle.
- Conduct architectural threat modeling and deep-dive security reviews before production.
- Direct the maintenance or migration of legacy cryptographic implementations using RSA BSAFE for FIPS 140-2/3 compliance.
- Design and maintain PKI integrations among certificate authorities, registration authorities, and the Java application layer.
- Mentor teams on product security and application security practices.
Requirements
- 8–10 years of experience in backend engineering with Java and/or security research.
- Deep expertise in Core and Enterprise Java, including the Spring Boot and Hibernate frameworks.
- Hands-on experience designing and maintaining Public Key Infrastructure and integrating certificate authorities, registration authorities, and Java applications.
- Strong understanding of the OWASP Top 10 and attack vectors including XSS, SQL injection, CSRF, SSRF, and deserialization flaws.
- Experience with SAST, DAST, and SCA tools such as Nessus, Veracode, or Burp Suite.
- Familiarity with securing cloud-native applications on AWS, Azure, or GCP and containerized environments using Docker and Kubernetes.
- Proven record of fixing vulnerabilities in a large-scale Java production environment.
- CISSP, CSSLP, OSCP, or GWEB certification is preferred but does not replace hands-on experience.