Node Engineer with expertise in secure coding and vulnerability remediation at Brillio. Collaborate with InfoSec, QA, and DevOps to enhance application security.
Responsibilities
Analyze, triage, and remediate vulnerabilities identified via SAST, DAST, and software composition analysis tools such as SonarQube, Veracode, Snyk, and Checkmarx.
Refactor insecure Java and Node.js codebases to mitigate vulnerabilities such as SQL Injection, XXE, XSS, CSRF, Deserialization, and Authentication flaws.
Patch and upgrade vulnerable third-party dependencies using Maven/Gradle, and validate post-remediation effectiveness.
Leverage Generative AI tools (e.g., AWS Bedrock) to build or enhance automation workflows for:
Auto-remediation of common vulnerability patterns
Code recommendations and patch generation
AI-driven security analysis and triage assistance
Automate vulnerability remediation and validation within CI/CD pipelines, improving security velocity and reducing manual effort.
Strengthen security configurations in Spring Boot, REST APIs, Node.js services, and Tomcat-based deployments.
Perform secure code reviews, provide remediation guidance, and promote secure coding best practices across development teams.
Collaborate with InfoSec and DevOps teams to validate fixes, perform re-scans, and close vulnerability tickets.
Stay current on security advisories, OWASP Top 10, CWE/SANS 25, and Java/Tomcat ecosystem updates.
Requirements
6+ years of experience
Must Have: NodeJS, vulnerability remediation, and security, Java
Strong hands-on experience with Core Java, Spring Boot, Tomcat, and REST API development
Proficiency in secure coding principles and application vulnerability remediation
Experience remediating issues identified by tools like Veracode, Checkmarx, SonarQube, or Snyk
Knowledge of dependency management and patching practices using Maven or Gradle
Familiarity with Node.js security configurations and remediation techniques
Experience with OAuth2/JWT, input validation, encryption, and secure session management
Understanding of Docker, Kubernetes, and security considerations in cloud-native applications
Preferred: Experience with automating vulnerability remediation using GenAI platforms (e.g., AWS Bedrock, Amazon CodeWhisperer)
Exposure to DevSecOps pipelines, including automated security scans and policy enforcement
Strong understanding of Spring Security, secure API design, and infrastructure hardening
Certifications such as CEH, CSSLP, GSSP-Java, or similar are a plus.
Process Technology Engineering Specialist at Solventum identifying projects to improve manufacturing processes. Collaborating with teams in robotics and data analytics for safety and productivity improvements.
Design Supervisor leading a team in developing low - voltage power supply technologies for efficient vehicles. Pioneering solutions in battery design and implementation at Ford Motor Company.
Cost Engineer/Analyst at Ford predicting and analyzing total cost of vehicle components. Utilizing technical cost modeling to evaluate expenses ensuring profitability and quality standards.
Process Engineering Intern at MAST Technologies focused on aerospace materials and engineering. Assisting with equipment qualification, process development, and documentation tasks in a collaborative environment.
Technical Director in ERM leading remediation programs across North Carolina and the Southeast. Managing project teams, enhancing technical reputation, and ensuring client success.
System and Software Engineering Intern joining BorgWarner to assist with software development and verification tasks for innovative mobility solutions. Collaborate with senior engineers and gain exposure to product development lifecycle.
Copilot Studio Developer designing, building, and deploying intelligent conversational agents using Microsoft Copilot Studio. Collaborating with stakeholders to deliver ethical and user - centric AI solutions.
Software Development Engineer developing high - performance mobile applications in React Native for Junglee Games in India. Collaborating with cross - functional teams to deliver engaging gaming experiences.
Manager of Engineering leading teams in electromechanical actuation systems for aerospace applications. Overseeing product development, design standards, and continuous improvement initiatives.