Job Title: Full-Stack Software Engineer / SRE – Security Vulnerability Remediation
Location: Remote
SRE with strong hands-on expertise in security vulnerability remediation across legacy Java, Python, and JavaScript applications. This role is focused exclusively on identifying, triaging, remediating, validating, and deploying security fixes across existing application codebases and delivery pipelines. The ideal candidate must be comfortable working independently in legacy systems they did not originally develop and owning vulnerabilities through production deployment.
- Take end-to-end ownership of security vulnerabilities from initial identification and triage through remediation, testing, deployment, and production verification.
- Analyze security vulnerabilities and CVEs identified through Claude Mythos and determine severity, root cause, affected components, remediation approach, and potential application impact.
- Perform hands-on code remediation across Java, Python, and JavaScript , including legacy applications and unfamiliar codebases.
- Evaluate remediation options, including source-code changes, dependency upgrades, configuration changes, and compensating controls where appropriate.
- Personally implement and test vulnerability fixes rather than relying solely on development teams or security recommendations.
- Upgrade vulnerable third-party libraries and dependencies while assessing compatibility, transitive dependencies, build failures, runtime issues, and application regressions.
- Troubleshoot and resolve problems resulting from legacy dependency upgrades, including broken builds, compilation errors, test failures, runtime exceptions, and application behavior changes.
- Update CI/CD pipelines and build processes required to support vulnerability remediation and secure software delivery.
- Work extensively with Jenkins, GitLab, Harness, Artifactory, and ArgoCD across the software build, artifact management, release, and deployment lifecycle.
- Manage application artifacts and dependency libraries, including artifact versioning, repository management, promotion across environments, and release integrity.
- Work with Artifactory to manage artifact repositories, library versions, dependency availability, and promotion workflows.
- Develop and maintain CI/CD workflows using Jenkins and GitLab to build, test, package, scan, and release remediated applications.
- Use Harness for deployment and release orchestration and ArgoCD for GitOps-based application delivery where applicable.
- Maintain and troubleshoot GitOps deployment workflows, ensuring that approved application versions and remediation changes are correctly promoted and deployed.
- Validate security fixes through appropriate automated and manual testing before production deployment.
- Verify that vulnerabilities are fully remediated after deployment and that application functionality has not been negatively impacted.
- Collaborate with security, development, DevOps, SRE, and infrastructure teams to resolve complex vulnerability and deployment issues.
- Maintain clear documentation of vulnerability analysis, remediation decisions,
dependency upgrades, testing results, deployment activities, and production verification.
- Prioritize remediation activities based on vulnerability severity, business impact, application criticality, exploitability, and remediation complexity.
- Demonstrate a proven track record of taking a CVE/security vulnerability from flagged → triaged → remediated → tested → deployed → verified in production .
- Demonstrate hands-on development experience across Java, Python, and JavaScript , with the ability to context-switch between multiple technology stacks and legacy applications.
- Possess strong experience troubleshooting and modifying code in applications that were not originally developed by the engineer.
- Have strong hands-on experience with Jenkins, GitLab, Harness, Artifactory, and ArgoCD , including practical ownership of build, release, artifact, and deployment processes.
- Demonstrate strong understanding of software dependencies, vulnerability remediation, package/library upgrades, version compatibility, CI/CD pipelines, artifact management, and production deployments.
- Experience working with Harness and ArgoCD together in a GitOps-oriented delivery workplace is highly preferred.
- Experience resolving application or build failures caused by legacy dependency upgrades is highly preferred.
- Ability to independently manage multiple vulnerabilities across Java, Python, and JavaScript applications and consistently drive them through closure.
- Strong troubleshooting, debugging, analytical, and problem-solving skills.
- Strong understanding of secure software development practices, vulnerability remediation, and production release processes.
📌 Senior Application Security Engineer (India)
🏢 360 IDE
📍 India