Senior Java Engineer (Hyderabad)

Senior Java Engineer (Hyderabad)

27 Sep
|
SysTechCorp
|
Hyderabad

27 Sep

SysTechCorp

Hyderabad

Role Purpose

Own the dependency version governance strategy for a 1M+ line Java/Scala codebase across 9 repositories (WS6), and own the WS8 application logging contract the JSON schema, correlation IDs, MDC implementation, PII masking rules, and code changes required in application code. The OpenSearch platform layer and QRadar integration are owned by the Cloud Platform Engineer; the Security Engineering Lead defines security-event taxonomy. This role focuses on application-level logging standards and dependency governance.

Key Responsibilities

- Triage all OWASP Dependency-Check findings across 9 repositories in discovery classify by severity, identify safe upgrade paths, flag libraries requiring major version migration (Spring 3/4 to 6, Jetty 9.4 to 12, Zookeeper 3.4 to 3.9) as scope-change candidates
- Define and maintain the master dependency version manifest for the riskcanvas-backend monolithic WAR — single authoritative source across 6 sub-modules; no sub-module deviates without Governance Lead sign-off
- Design the upgrade sequencing strategy — sub-module upgrade order, inter-module API dependencies, coordinated release constraints
- Review and approve every library upgrade pull request from the Remediation Execution Engineer before the CI/CD pipeline
- Lead the Spring 3.x/4.x to Spring 6.x migration strategy if triggered — Java 17+ migration plan, Spring Boot 3.x compatibility, breaking API changes, application code impact analysis including JPMS
- Switch OWASP Dependency-Check from audit-only to enforcement mode in Jenkins after all Critical and High findings are resolved




- Own the WS8 Application Logging Standard — define the structured JSON log schema (mandatory fields: traceId, spanId, correlationId, severity, timestamp, serviceId), PII field masking rules, log level guidelines per environment
- Own the code changes in application repositories to implement the logging standard — SLF4J MDC configuration, Logback appender configuration, correlation ID propagation patterns
- Coordinate with the Cloud Platform Engineer on OpenSearch index template design to ensure the log schema aligns with ingestion pipeline expectations
- Coordinate with the Security Engineering Lead on security-event field requirements for QRadar routing

Must-Have Skills & Experience

- 8+ years Java engineering; 4+ years as technical lead on large-scale enterprise Java with monolithic or modular architecture
- Spring Framework expert — Spring Core, MVC, Security, Boot 2.x and 3.x; comprehensive knowledge of breaking changes; Java 17+ migration requirements for Spring 6
- Maven multi-module mastery — dependency Management BOM, dependency convergence enforcement, Enforcer plugin rules, version conflict resolution, exclusion patterns
- OWASP Dependency-Check — CVE triage, CVSS scoring, secure upgrade paths, suppression file management, enforcement mode configuration in Jenkins
- Jetty 9.4 to 12.x migration — architecture changes,



Servlet API namespace changes (javax to jakarta), embedded vs standalone mode
- Jackson-databind version lifecycle — ObjectMapper migration, polymorphic type handling, security-relevant configuration
- Apache CXF and Zookeeper version lifecycle — major version migration paths, client configuration changes
- Structured logging design — JSON schema definition, SLF4J/Logback configuration, MDC for correlation IDs, PII masking at the appender level
- Application logging contract ownership — defining standards that multiple engineering teams implement consistently across 9 repositories
- JPMS awareness — Java Platform Module System impact on Spring 6 upgrade, --add-opens/--add-exports requirements

Nice-to-Have Skills

- Spring Security upgrade experience (3.x to 6.x) — SecurityFilterChain migration, OAuth2 resource server
- Log4Shell (CVE-2021-44228) and similar critical logging-framework CVE remediation
- OpenSearch index template design collaboration — ability to specify log schema requirements for the platform engineer to implement
- QRadar DSM field mapping — sufficient knowledge to specify which application log fields feed QRadar event classification
- Gradle — build script migration, version catalog, dependency locking
- Scala SBT — build definition structure, dependency management for cross-repository consistency

Tools & Platforms OWASP Dependency-Check, Maven (Enforcer, Versions, Dependency plugins), Jenkins, Bitbucket, Nexus, Spring Framework (all versions), Spring Boot 2/3, Jetty 9/12, Jackson-databind, CXF, Zookeeper, SLF4J, Logback, Java 11/17, Confluence

📌 Senior Java Engineer (Hyderabad)
🏢 SysTechCorp
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior java engineer (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: senior java engineer (hyderabad) / hyderabad