Security Engineer — Application & File Security II

SysTechCorp Inc
India

Role: Security Engineer — Application & File Security

Experience: 5+yrs

Notice period: Immediate - 15days

Work Mode: Remote

Background & Authorization

This is a remote role based in India. The engagement operates on a mid-day to late-night shift to align with the US client team. Working hours are approximately 1:00 PM – 10:30 PM IST during US Eastern Daylight Time (EDT) and 1:00 PM – 11:00 PM IST during US Eastern Standard Time (EST).

Role Purpose

Execute application-layer security remediation for TLS cipher hardening and file upload security controls under the direction of the Security Engineering Lead. Own the precise, tested delivery of these controls — every TLS change validated against the pre-remediation compatibility survey, every file upload control tested against a comprehensive edge-case matrix. Also contributes to the security unit test pilot components.

Key Responsibilities

  • Implement load balancer cipher policy changes per Security Engineering Lead design — execute in non-production, validate against compatibility survey, then promote to production through the CI/CD pipeline
  • Build and deploy a containerised file upload scanner (ClamAV) — Docker multi-stage image, ECS Fargate or Lambda integration, REST API endpoint, fail-closed error handling, and horizontal auto-scaling
  • Implement path traversal protection for archive file uploads (ZipSlip pattern) — archive extraction validation, path normalisation enforcement, rejection of escaping entries
  • Implement insecure PDF handling controls — magic byte validation, embedded JavaScript detection, external URL reference blocking, file size limits
  • Execute TLS rollback testing — validate rollback from TLS 1.3-only to TLS 1.2 AEAD-only within a maintenance window
  • Produce post-remediation cipher scan evidence — compliance report confirming no deprecated cipher suites remain on any endpoint
  • Build and execute a comprehensive file upload security test matrix — EICAR test file, oversized ZIP, recursive archive, malformed PDF, MIME type spoofing, double-extension filenames
  • Build two pilot security unit test components — OWASP/CWE-mapped JUnit5 test cases for nominated high-risk application components

Must-Have Skills & Experience

  • 5+ years application security engineering; 3+ years hands-on Java/Spring application security on production systems
  • TLS/SSL — cipher suite configuration, AWS ALB Security Policy changes, TLS debugging with OpenSSL, HTTPS and HSTS configuration
  • ClamAV — daemon configuration, containerised deployment, API integration, performance tuning
  • Docker — multi-stage Dockerfile authoring, image hardening, container deployment on AWS ECS or Lambda
  • File upload security — MIME type validation, ZipSlip/path traversal prevention, malicious file detection, magic byte validation
  • PDF security — malicious PDF structure detection, embedded JavaScript identification
  • Java Spring Security — filter chain configuration, security headers, CSRF protection, input validation
  • AWS Lambda — function authoring in Python or Java, execution role design, VPC connectivity
  • Security test case authoring — edge case coverage with audit-quality evidence documentation

Nice-to-Have Skills

  • OWASP Top 10 training, CEH, or CompTIA Security+
  • AWS WAF v2 — custom rule authoring for file upload restrictions
  • Fortify SAST finding remediation in Java — CWE-434, CWE-22, CWE-79
  • OWASP Dependency-Check for container image vulnerability scanning
  • REST API security — rate limiting, content-type enforcement, API Gateway integration

Tools & Platforms

ClamAV, Docker, AWS ECS Fargate, AWS Lambda, API Gateway, ALB/NLB (Security Policies), AWS Config, Java Spring Security, OpenSSL, OWASP ZAP, Jenkins, Bitbucket, Confluence

Score my resume against this job, free →

Get your ATS score for this role — free. Score my resume free →