Java Developer (Application Security)Day to Day Job Duties: (What This Person Will Do On A Daily/Weekly Basis)Design, develop, and maintain secure Java/J2EE-based applications, ensuring adherence to enterprise security standards and best practicesImplement and maintain backend components using Spring MVC, EJB, Hibernate, and JPAIdentify, analyze, and remediate application security vulnerabilities such as XSS, CSRF, session fixation, IDOR, and path traversal issuesCollaborate with security teams to triage and resolve findings from vulnerability scans, penetration testing, and security auditsImplement secure coding practices, including input validation, output encoding, and proper authentication/authorization mechanismsUpdate and manage third-party libraries (e.g., Axios, jQuery, Ext.js), ensuring no outdated or vulnerable versions are in useConfigure and enforce web security controls such as CSP headers, secure cookies (HttpOnly, Secure, SameSite), and cache directivesDebug and resolve issues related to HTTP errors (e.g., 500 errors), session management, and application behavior inconsistenciesBasic Qualifications: (What Are The Skills Required To This Job With Minimum Years Of Experience On Each)Minimum 5+ years of experience in Java/J2EE development, including building and maintaining enterprise-level web applicationsStrong proficiency in Core Java 8+, Spring MVC, EJB, Hibernate, and JPAFamiliarity with IBM WebSphere application server (preferred)At least 3+ years of hands-on experience in application security, including identifying and remediating vulnerabilities such as XSS, CSRF, IDOR, and session-related issuesAt least 1+ year of experience working in Agile/Scrum environments, participating in sprint ceremonies and collaborative developmentTravel: This position requires 3 days in office either in Charlotte, NC or Jersey City, NJ. Preferred location is Charlotte, NC.Degree: Bachelors in Computer Science or equivalent work experience