Innovate Consulting is seeking a talented Java Engineer for one of our cybersecurity consulting clients. This position is project based and remote!
We are looking for a security-minded Java engineer who can remediate vulnerabilities in a fast-paced, government-adjacent environment. This person should understand not only how to fix an issue, but also the severity of the vulnerability, the broader risk to an internal corporate network, and the potential impact of leaving it unresolved.
Core Requirements
• Strong hands-on Java development experience in enterprise environments
• Experience reviewing, modifying, and shipping production code through pull requests
• Ability to remediate application security vulnerabilities, not simply identify them
• Understanding of vulnerability severity, exploitability, business impact, and internal network risk
• Ability to investigate root causes and implement fixes that address an entire class of vulnerabilities rather than applying one-off patches
• Experience working through Jira tickets, epics, and structured remediation backlogs
• Comfortable operating in environments with significant technical debt
• Ability to provide infrastructure or architecture recommendations when issues extend beyond the application code
• Experience partnering with engineering, infrastructure, and security teams to drive remediation through completion
• Able to work independently and move quickly in a high-pressure, fast-paced environment
Security Experience
The ideal candidate does not need to be a full-time penetration tester, but should have enough offensive security knowledge to:
• Understand how vulnerabilities may be exploited
• Validate whether a proposed fix meaningfully reduces the risk
• Think beyond the individual finding and identify similar weaknesses elsewhere in the environment
• Communicate clearly with security teams about remediation decisions and residual risk
Ideal Background
Strong candidates may come from application security engineering, product security, secure software development, vulnerability remediation, or Java engineering roles with meaningful security responsibilities.
Screening Summary
In simple terms, we are looking for a Java engineer who can “hack a little”: someone who understands how vulnerabilities work, can assess their seriousness, and can own the technical remediation from investigation through production deployment.