15 Sep
|
innovantes it solutions
|
Chandigarh
15 Sep
innovantes it solutions
Chandigarh
Experience: 5+ Years
Employment Type: Full-time
Role: Senior Software Developer – Backend, API & Security
About the Role
We are looking for an experienced Senior Backend Developer with 5+ years of hands-on experience in software development, backend architecture, API development, and application security. The ideal candidate will have a strong track record of building and securing production-grade backend platforms and APIs , with a deep understanding of secure software development practices, DevOps, Git-based development workflows, and security standards.
This is not a role for someone whose experience is limited to writing backend code. We are looking for a developer who understands how secure platforms are designed, developed, deployed, monitored, and maintained .
The candidate should be comfortable taking ownership of backend services and APIs while ensuring that security is embedded throughout the software development lifecycle.
Key Responsibilities
1. Backend Development & Architecture
- Design, develop, and maintain scalable, reliable, and secure backend applications and services.
- Build production-grade backend systems with a strong focus on performance, reliability, maintainability, and security.
- Design appropriate application architecture, database structures, business logic, and service layers.
- Develop reusable, modular, and well-documented backend components.
- Identify and resolve performance, scalability, reliability, and security issues.
- Participate in technical design and architecture discussions and contribute to engineering best practices.
2. API Development & Integration
- Design and develop secure RESTful APIs and other API-based integrations .
- Have strong practical understanding of API authentication, authorization, validation, rate limiting, session management, and error handling.
- Implement secure API communication between applications, services, and third-party systems.
- Work extensively with API integrations and understand API lifecycle management.
- Implement appropriate controls for protecting APIs against common attacks such as unauthorized access, injection, abuse, replay attacks, and data leakage.
- Ensure APIs are properly documented, versioned, tested, monitored, and secured.
3. Application Security
Security will be a core responsibility of this role .
- Design and develop applications following Secure by Design and Secure by Default principles.
- Identify security vulnerabilities during design, development, testing, and deployment.
- Implement secure coding practices across backend applications and APIs.
- Understand and apply OWASP Top 10 and OWASP API Security Top 10 principles.
- Implement appropriate controls for:
- Authentication and authorization
- Role-Based Access Control (RBAC)
- Input validation and output encoding
- Secure session management
- Encryption and secure key management
- Protection of sensitive data
- API security
- Secrets management
- Logging and audit trails
- Secure error handling
- Rate limiting and abuse prevention
- Conduct code and architecture reviews from a security perspective.
- Work with security teams/auditors to identify, remediate,
and prevent vulnerabilities.
- Understand common application vulnerabilities such as SQL Injection, XSS, CSRF, SSRF, broken access control, insecure deserialization, authentication flaws, and API-specific vulnerabilities.
4. DevSecOps & CI/CD Security
- Integrate security into the CI/CD pipeline and software development lifecycle .
- Work extensively with Git and Git-based development workflows.
- Establish and follow secure Git practices including:
- Branch protection
- Pull/Merge request reviews
- Code ownership
- Commit hygiene
- Access controls
- Secrets protection
- Implement automated security checks within CI/CD pipelines.
- Work with tools for:
- SAST – Static Application Security Testing
- DAST – Dynamic Application Security Testing
- Software Composition Analysis (SCA)
- Dependency vulnerability scanning
- Secret scanning
- Container/image security scanning
- Ensure vulnerabilities identified through automated and manual security testing are tracked and remediated.
- Help establish security gates in CI/CD pipelines before code reaches production.
- Ensure secure configuration of development, staging, and production environments.
5. Git & Secure Development Practices
- Strong hands-on experience with Git and GitHub/GitLab/Bitbucket or equivalent .
- Establish secure source-code management practices.
- Ensure sensitive information such as passwords, API keys, tokens, certificates, and credentials are never committed to repositories.
- Implement appropriate repository permissions and branch protection mechanisms.
- Review pull requests with both code quality and security considerations.
- Understand secure software development workflows and code review practices.
6. Security Standards & Compliance
- Translate security standards and requirements into practical technical controls.
- Strong understanding of industry security standards and frameworks such as:
- OWASP
- OWASP ASVS
- OWASP API Security
- CWE
- NIST Cybersecurity Framework
- Secure SDLC / SSDLC principles
- Exposure to standards such as ISO 27001, SOC 2, PCI DSS, GDPR, or other security/compliance frameworks will be an advantage.
- Work with security assessments, vulnerability assessments, penetration testing, and security audits.
- Understand how security requirements translate into application architecture, development practices, infrastructure, and deployment processes.
Required Technical Skills
Must Have
- 5+ years of professional software development experience
- Strong backend development experience
- Extensive hands-on experience building and consuming APIs
- Strong understanding of REST APIs, HTTP/HTTPS, authentication, authorization, tokens, OAuth/OAuth2 and API security
- Strong knowledge of application security and secure coding
- Hands-on experience implementing security controls in production applications
- Strong Git/GitHub/GitLab/Bitbucket experience
- Robust understanding of CI/CD and DevSecOps
- Experience implementing security checks within development and deployment pipelines
- Strong knowledge of OWASP Top 10 and OWASP API Security Top 10
- Experience with vulnerability identification and remediation
- Strong understanding of databases and database security
- Understanding of encryption, hashing, certificates, secrets, keys, and secure communication
- Experience with code reviews and secure coding practices
- Ability to understand security requirements and translate them into working technical solutions
- Good verbal and written communication skills.
- Experience participating in client meetings, technical discussions, requirement-gathering sessions, and solution presentations.
Good to Have
- Experience with SAST tools such as Semgrep, SonarQube, Checkmarx, Fortify, etc.
- Experience with DAST tools such as OWASP ZAP, Burp Suite, etc.
- Experience with SCA/dependency scanning tools
- Experience with container security and Docker/Kubernetes security
- Cloud security experience across AWS/GCP/Azure
- Experience with API gateways and WAFs
- Experience with vulnerability management and penetration testing
- Experience working with SIEM/logging/monitoring systems
- Experience with ISO 27001/SOC 2 or similar compliance programs
Candidate Profile
We are looking for someone who:
- Is a strong hands-on developer , not purely a security or management professional.
- Has actually built and deployed backend applications and APIs in production.
- Has significant practical experience implementing security controls rather than simply knowing security terminology.
- Thinks about security during architecture and development , rather than only after development is completed.
- Understands the complete journey from code Git CI/CD deployment production monitoring vulnerability remediation .
- Can independently identify security weaknesses in applications and recommend practical solutions.
- Is comfortable challenging insecure technical approaches and proposing better alternatives.
- Has strong attention to detail and takes ownership of the security and quality of the code they develop.
What Success Looks Like
Within this role, the candidate will be expected to:
- Build secure and scalable backend services and APIs.
- Reduce application and API security vulnerabilities.
- Establish secure development and Git practices.
- Embed security testing into CI/CD pipelines.
- Ensure security vulnerabilities are identified early in the development lifecycle.
- Improve the overall security posture of backend applications and APIs.
- Work closely with engineering, DevOps, infrastructure, and security teams.
- Help create a culture of Security by Design across the development lifecycle.
Education
Bachelor's/Master's degree in Computer Science, Information Technology, Engineering, Cybersecurity, or a related field preferred.
- Application Security
- API
- Software Development
📌 Senior Backend Developer – Application Security & DevSecOps (Chandigarh)
🏢 innovantes it solutions
📍 Chandigarh