Security Engineer — Application & File Security II
Role: Security Engineer — Application & File Security
Experience: 5+yrs
Notice period: Immediate - 15days
Work Mode: Remote
Background & Authorization
This is a remote role based in India. The engagement operates on a mid-day to late-night shift to align with the US client team. Working hours are approximately 1:00 PM – 10:30 PM IST during US Eastern Daylight Time (EDT) and 1:00 PM – 11:00 PM IST during US Eastern Standard Time (EST).
Role Purpose
Execute application-layer security remediation for TLS cipher hardening and file upload security controls under the direction of the Security Engineering Lead. Own the precise, tested delivery of these controls — every TLS change validated against the pre-remediation compatibility survey, every file upload control tested against a comprehensive edge-case matrix. Also contributes to the security unit test pilot components.
Key Responsibilities
- Implement load balancer cipher policy changes per Security Engineering Lead design — execute in non-production, validate against compatibility survey, then promote to production through the CI/CD pipeline
- Build and deploy a containerised file upload scanner (ClamAV) — Docker multi-stage image, ECS Fargate or Lambda integration, REST API endpoint, fail-closed error handling, and horizontal auto-scaling
- Implement path traversal protection for archive file uploads (ZipSlip pattern) — archive extraction validation, path normalisation enforcement, rejection of escaping entries
- Implement insecure PDF handling controls — magic byte validation, embedded JavaScript detection, external URL reference blocking, file size limits
- Execute TLS rollback testing — validate rollback from TLS 1.3-only to TLS 1.2 AEAD-only within a maintenance window
- Produce post-remediation cipher scan evidence — compliance report confirming no deprecated cipher suites remain on any endpoint
- Build and execute a comprehensive file upload security test matrix — EICAR test file, oversized ZIP, recursive archive, malformed PDF, MIME type spoofing, double-extension filenames
- Build two pilot security unit test components — OWASP/CWE-mapped JUnit5 test cases for nominated high-risk application components
Must-Have Skills & Experience
- 5+ years application security engineering; 3+ years hands-on Java/Spring application security on production systems
- TLS/SSL — cipher suite configuration, AWS ALB Security Policy changes, TLS debugging with OpenSSL, HTTPS and HSTS configuration
- ClamAV — daemon configuration, containerised deployment, API integration, performance tuning
- Docker — multi-stage Dockerfile authoring, image hardening, container deployment on AWS ECS or Lambda
- File upload security — MIME type validation, ZipSlip/path traversal prevention, malicious file detection, magic byte validation
- PDF security — malicious PDF structure detection, embedded JavaScript identification
- Java Spring Security — filter chain configuration, security headers, CSRF protection, input validation
- AWS Lambda — function authoring in Python or Java, execution role design, VPC connectivity
- Security test case authoring — edge case coverage with audit-quality evidence documentation
Nice-to-Have Skills
- OWASP Top 10 training, CEH, or CompTIA Security+
- AWS WAF v2 — custom rule authoring for file upload restrictions
- Fortify SAST finding remediation in Java — CWE-434, CWE-22, CWE-79
- OWASP Dependency-Check for container image vulnerability scanning
- REST API security — rate limiting, content-type enforcement, API Gateway integration
Tools & Platforms
ClamAV, Docker, AWS ECS Fargate, AWS Lambda, API Gateway, ALB/NLB (Security Policies), AWS Config, Java Spring Security, OpenSSL, OWASP ZAP, Jenkins, Bitbucket, Confluence