Senior Java Developer with strong Application Security Focus (m/f/d)
⚲ Łódź, Bałuty
Do uzgodnienia
Wymagania
- Java
- Spring Boot
Opis stanowiska
Nasze wymagania:
High knowledge of Secure coding, vulnerability identification
and application security
High knowledge of Java programming and scripting
High knowledge of Strong code analysis and reverse-
engineering skills
High knowledge of Impact and risk assessment of code changes
Good knowledge of Spring, Spring Boot
Good knowledge of Problem - solving and analytical thinking.
O projekcie:
The Senior Java Developer with strong Application Security Focus is a security-minded senior developer role, rather than a generic Java developer position. The role requires deep hands-on Java development experience and the ability to understand complex Java-based applications, but its primary purpose is to take ownership of application security topics and vulnerability remediation within the development context. The position is not intended to directly develop new code or make code changes.
The candidate will review existing application code, analyze security findings and potential defects, assess vulnerabilities based on severity, exploitability, business impact, and remediation urgency, and provide expert guidance on robust remediation approaches. This includes knowledge of AI-supported code analysis methods as well as application security tooling such as SAST, DAST, dependency scanning, and vulnerability management solutions. A core responsibility is to own and coordinate application security topics for the development team, drive vulnerability remediation follow-up, and support developers with experience-based recommendations while the actual implementation remains with the development teams.
By combining senior development expertise with a strong security mindset, the role helps safeguard the integrity, confidentiality, and availability of applications, strengthens secure development practices, and ensures that vulnerability remediation is understood, prioritized, tracked, and technically guided. The role acts as an advisory and review function as well as the technical interface to central security teams, for example the Cyber Hygiene team, translating centralrequirements into practical development guidance and providing technical feedback from the application teams.
Description of the cluster:
In the cluster Daily Banking Middletier, we shape the digital banking experience for millions of retail and corporate customers. With around 15 specialized cells across four locations, we are at the heart of our online and mobile banking and responsible for its core backend and middletier services delivering them securely, with high availability, and in full regulatory compliance.
What sets us apart is that we combine reliable platform ownership with genuine future-focused work. We are modernizing a complex system landscape with AI, establishing cross-channel standards, and thereby enabling new digital and AI-supported use cases across the bank. People who join us help shape critical infrastructure with visible impact on customers, operations, and the bank’s strategic evolution.
Zakres obowiązków:
Analyze static code, SAST/DAST results and dependency-scanning findings for security threats
Assess vulnerabilities based on severity, exploitability, business impact and remediation urgency
Support and track remediation activities together with Dev and Ops teams without directly implementing code changes
Act as technical counterpart for central teams in the context of Cyber / IT security.
Define and promote secure coding standards for Java/Spring applications
Support continuous improvement of Secure SDLC practices and bank-wide application security standards.
High knowledge of Secure coding, vulnerability identification
and application security
High knowledge of Java programming and scripting
High knowledge of Strong code analysis and reverse-
engineering skills
High knowledge of Impact and risk assessment of code changes
Good knowledge of Spring, Spring Boot
Good knowledge of Problem - solving and analytical thinking.
O projekcie:
The Senior Java Developer with strong Application Security Focus is a security-minded senior developer role, rather than a generic Java developer position. The role requires deep hands-on Java development experience and the ability to understand complex Java-based applications, but its primary purpose is to take ownership of application security topics and vulnerability remediation within the development context. The position is not intended to directly develop new code or make code changes.
The candidate will review existing application code, analyze security findings and potential defects, assess vulnerabilities based on severity, exploitability, business impact, and remediation urgency, and provide expert guidance on robust remediation approaches. This includes knowledge of AI-supported code analysis methods as well as application security tooling such as SAST, DAST, dependency scanning, and vulnerability management solutions. A core responsibility is to own and coordinate application security topics for the development team, drive vulnerability remediation follow-up, and support developers with experience-based recommendations while the actual implementation remains with the development teams.
By combining senior development expertise with a strong security mindset, the role helps safeguard the integrity, confidentiality, and availability of applications, strengthens secure development practices, and ensures that vulnerability remediation is understood, prioritized, tracked, and technically guided. The role acts as an advisory and review function as well as the technical interface to central security teams, for example the Cyber Hygiene team, translating centralrequirements into practical development guidance and providing technical feedback from the application teams.
Description of the cluster:
In the cluster Daily Banking Middletier, we shape the digital banking experience for millions of retail and corporate customers. With around 15 specialized cells across four locations, we are at the heart of our online and mobile banking and responsible for its core backend and middletier services delivering them securely, with high availability, and in full regulatory compliance.
What sets us apart is that we combine reliable platform ownership with genuine future-focused work. We are modernizing a complex system landscape with AI, establishing cross-channel standards, and thereby enabling new digital and AI-supported use cases across the bank. People who join us help shape critical infrastructure with visible impact on customers, operations, and the bank’s strategic evolution.
Zakres obowiązków:
Analyze static code, SAST/DAST results and dependency-scanning findings for security threats
Assess vulnerabilities based on severity, exploitability, business impact and remediation urgency
Support and track remediation activities together with Dev and Ops teams without directly implementing code changes
Act as technical counterpart for central teams in the context of Cyber / IT security.
Define and promote secure coding standards for Java/Spring applications
Support continuous improvement of Secure SDLC practices and bank-wide application security standards.
🔍 Dekoder Ogłoszenia
🔴
The position is not intended to directly develop new code or make code changes.
Rola polega głównie na analizie i przeglądzie kodu, a nie na aktywnej jego modyfikacji czy tworzeniu nowych funkcjonalności.
🔴
take ownership of application security topics and vulnerability remediation within the development context.
Oczekuje się, że kandydat przejmie pełną odpowiedzialność za bezpieczeństwo aplikacji i proces naprawy luk, co może oznaczać dużą presję i konieczność koordynacji wielu działań.
🔴
High knowledge of Secure coding, vulnerability identification and application security
Chociaż brzmi to jak standardowe wymaganie, 'High knowledge' w kontekście tej roli może oznaczać, że oczekuje się eksperckiego poziomu wiedzy i doświadczenia w tej specyficznej dziedzinie.
🔴
High knowledge of Strong code analysis and reverse-engineering skills
Wymaga to nie tylko umiejętności czytania kodu, ale głębokiego zrozumienia jego działania, co może być czasochłonne i wymagać specyficznych narzędzi.
🟡
provide expert guidance on robust remediation approaches.
Oznacza to, że kandydat będzie musiał nie tylko identyfikować problemy, ale także proponować i uzasadniać rozwiązania, co wymaga silnych umiejętności komunikacyjnych i technicznych.