What are the responsibilities and job description for the ONLY W2 AVAILABLE :: Java Lead with Vulnerability Remediation experience position at Ampstek?
Title: Java Lead with Vulnerability Remediation experience
Location: Cedar Rapids,IA(Hybrid mode Onsite)
Job Type: Contract
Mandatory Experience and Skills
7 – 10 Years Have played a lead role and have deep technical understanding
Java, Springboot, Angular, NodeJS, AWS
About the Role
We're hiring a developer to proactively remediate vulnerabilities across our Java/Spring Boot platform services on a twice-per-week cadence. This isn't firefighting — it's disciplined, recurring upgrade work that keeps our platform ahead of security findings before they become blockers. You'll work primarily in Java/Spring Boot codebases but will also touch Python services that live within the same platform ecosystem. You'll leverage AI-assisted tooling and CI/CD pipelines to accelerate the remediation cycle.
What You'll Do
• Remediate library vulnerabilities across platform services on a twice-weekly cycle
• Upgrade and manage dependencies (Maven BOMs, parent POMs, transitive dependencies)
• Analyze Mythos and Snyk findings, assess severity/impact, and apply fixes
• Validate upgrades don't introduce regressions (build, test, deploy)
• Maintain compatibility across shared libraries consumed by multiple services
• Work with AI-assisted remediation tooling to accelerate upgrade workflows
• Coordinate with security and release teams on vulnerability SLAs
• Occasionally remediate Python dependencies (pip/requirements.txt) in platform services
Required Skills
Primary (Must-Have)
• Java 17/21
• Maven
• Spring / Spring Boot
• GitHub
• Jenkins pipelines
Secondary
• Python 3.x
• pip / requirements.txt / Poetry
• React
• Node.js / NPM
Cloud & Infrastructure
• AWS (ECS, Lambda, IAM)
• Docker
• Terraform
• Git
AI & Automation
• AI-assisted coding (AWS Kiro or similar)
• Familiarity with LLM-driven workflows
• Automation mindset
Security & Compliance
• SCA tools (Mythos, Snyk, or similar)
• Vulnerability lifecycle management
• CVSS scoring & risk assessment
• Compliance awareness
Nice to Have
• Strong experience with SDLC, DevOps, and CI/CD pipelines
• Experience managing upgrades at scale across 10 microservices
• Familiarity with Apache Camel or integration-heavy Spring services
• Background in financial services / insurance (regulated environment)
• Experience with OpenSearch or Elasticsearch library upgrades
• Comfort with NestJS/Node.js (some platform tooling uses this)
Thanks
Aatmesh
aatmesh.singh@ampstek.com