03 Aug
|
Giniminds
|
India
Job Title: Java Developer Lead
Location: Bengaluru
Experience Level: 8+ years of hands-on software engineering
Employment Type: Full-time
Work Mode: 5 days’ work from office
General Summary:
We are seeking a Senior Java Developer to lead the design, governance and evolution of secure and scalable Java-based enterprise systems. He/she will define robust architectures for microservices and distributed applications while embedding security from the ground up (Secure by Design, Shift Left). He/she will proactively identify emerging security patterns and threats guide engineering teams on DevSecOps best practices aligned with OWASP standards and ensure compliance, resilience and observability in high-stakes environments. This role bridges architecture, security and development to deliver secure high-performance solutions that align with business goals.
Key Responsibilities
- Design and implement robust Java Spring Boot applications with a strong focus on security, scalability, and maintainability.
- Own the end-to-end secure architecture: create reference models, C4 diagrams, Architecture Decision Records (ADRs) and security guardrails for Java/microservices ecosystems.
- Proactively monitor and identify emerging security patterns, vulnerabilities, and threats; evaluate risks and recommend effective mitigations to safeguard production systems.
- Lead and mentor development teams on secure coding, threat modeling, secure design reviews, and OWASP-aligned practices to foster a strong security culture.
- Architect secure-by-default systems incorporating OAuth2/OpenID Connect, JWT, mTLS, RBAC/ABAC, secrets management, encryption and zero-trust principles.
- Drive secure modernization initiatives, including monolith decomposition, Java upgrades (Java 17/21+),
virtual threads adoption, while ensuring full OWASP compliance.
- Perform architecture and security reviews, risk assessments, trade-off analyses and compliance enforcement across projects.
- Partner with security teams to enhance observability, incident response automated remediation and security-focused monitoring/logging.
- Promote DevSecOps adoption through workshops, code reviews, knowledge-sharing sessions, and evangelism of OWASP trends and secure development practices.
- Document code, processes and architectural decisions to enable seamless knowledge transfer and long-term maintainability.
Required Skills & Qualifications
Technical Expertises
- Expert-level proficiency in Core Java, Spring Boot, Spring Security and related Spring ecosystem tools.
- Deep experience with microservices architectures (REST, gRPC, GraphQL), event-driven systems, resilience patterns and secure implementations.
- Hands-on knowledge of containerization and orchestration with secure configurations.
- Strong DevSecOps and security foundation:
- Comprehensive understanding of OWASP standards (API Top 10, Secure Coding Checklist, Cheat Sheets, DevSecOps Verification Standard).
- Proven ability to identify and adopt new security patterns/threats early, driving mitigation strategies and team adoption.
- Expertise in threat modeling, secure SDLC (Shift Left, Secure by Design),
secure design reviews.
- Authentication & authorization: OAuth2/OIDC, JWT, mTLS, RBAC/ABAC.
- Secrets management, encryption and zero-trust architectures.
- Secure database and middleware configurations (PostgreSQL, MongoDB, Redis, Elasticsearch; secure API gateways).
- Nice-to-have: Reactive programming, Domain-Driven Design (DDD), hexagonal architecture, low-latency secure systems.
Leadership & Soft Skills
- Exceptional communication skills to clearly articulate security risks, architectural decisions and best practices to technical teams, product stakeholders, executives and auditors.
- Strong technical leadership: influence and guide cross-functional teams on security and development practices without formal authority; mentor juniors effectively.
- Pragmatic, business-aligned security mindset: balance rigorous security with speed, simplicity and business value avoiding over-engineering.
- Proactive ownership of risks: anticipate emerging threats and drive timely mitigations.
- Collaborative mindset in agile environments, promoting a "Secure by Design" culture across Dev, Sec, and Ops teams.
Minimum Educational Qualifications:
Minimum Experience for Consideration
- 8+ years of experience in senior Java development roles, with proven leadership in secure architecture and DevSecOps initiatives for large-scale production systems.
- Demonstrated track record of identifying emerging security patterns/threats and successfully guiding teams in OWASP/DevSecOps adoption within agile settings
Pay: ₹1,500,000.00 - ₹2,500,000.00 per year
Perks:
- Health insurance
- Paid sick time
- Paid time off
- Provident Fund
Work Location: In person
📌 Java Lead (India)
🏢 Giniminds
📍 India