What are the responsibilities and job description for the Java Software Engineer position at CornerStone Technology Talent Services?
This is not a traditional feature-development or reactive security role. The primary focus is disciplined, recurring vulnerability remediation and dependency modernization across enterprise platform services. You'll work primarily within Java/Spring Boot environments, with occasional Python development, using security scanning, AI-assisted development tools, and CI/CD automation to keep applications secure and current.
The ideal candidate combines strong Java engineering skills with DevOps, application security, dependency management, and automation experience.
What You'll Do
- Remediate application and library vulnerabilities across platform services on a twice-weekly release cycle.
- Upgrade and manage Java dependencies, including Maven BOMs, parent POMs, and transitive dependencies.
- Analyze vulnerability findings from Mythos, Snyk, or comparable SCA tools.
- Assess vulnerability severity, impact, CVSS scores, and remediation requirements.
- Implement upgrades and security fixes while maintaining application stability.
- Validate changes through build, automated testing, deployment, and regression processes.
- Maintain compatibility across shared libraries consumed by multiple microservices.
- Partner with Security and Release teams to meet vulnerability-remediation SLAs.
- Use AI-assisted coding and remediation tools to accelerate dependency analysis and upgrade workflows.
- Support CI/CD pipelines and identify opportunities to automate repetitive remediation activities.
- Occasionally remediate Python dependencies using pip, requirements.txt, Poetry, or similar tooling.
Required Technical Skills
Java & Application Development
- Java 17/21
- Spring / Spring Boot
- Maven
- GitHub
- Git
- Jenkins pipelines
Cloud & DevOps
- AWS, including familiarity with:
- ECS
- Lambda
- IAM
- Docker
- Terraform
- CI/CD pipelines
Application Security
- Software Composition Analysis (SCA)
- Snyk, Mythos, or comparable vulnerability-management tools
- Dependency vulnerability remediation
- CVSS scoring and risk assessment
- Vulnerability lifecycle management
- Security and compliance awareness
AI & Automation
- Experience using AI-assisted development tools, such as AWS Kiro or comparable platforms.
- Familiarity with LLM-driven development workflows.
- Strong automation mindset and ability to identify repeatable engineering processes.
Additional Technical Experience
Experience with some of the following is beneficial:
- Python 3.x
- pip / requirements.txt / Poetry
- React
- Node.js / NPM
- NestJS
- Apache Camel
- OpenSearch / Elasticsearch
Preferred Qualifications
- Strong understanding of the SDLC, DevOps, and CI/CD lifecycle.
- Experience managing dependency upgrades across 10 microservices.
- Experience maintaining shared libraries across distributed application environments.
- Familiarity with integration-heavy Spring Boot services.
- Experience upgrading OpenSearch or Elasticsearch libraries.
- Background supporting financial services, insurance, or another regulated environment.