HI
NodeJS Developer with vulnerability :: St. Louis, MO/ (Hybrid – 3 days onsite)
Han IT Staffing
Location not stated
Hybrid
7 months ago
- Node.js
- Java
- Machine Learning
- AWS Bedrock
- Devops
- triage
- SAST
- DAST
- SonarQube
- Snyk
- SQL Injection
- XSS
- CSRF
- Maven
- Gradle
- AI
- CI/CD
- Spring Boot
- Tomcat
- OWASP
- REST API
- OAuth2
- JWT
- Docker
- Kubernetes
7 months ago
We are seeking a highly skilled Node Engineer with expertise in secure coding,
vulnerability remediation, and security automation.
The ideal candidate will have hands-on experience remediating vulnerabilities in
Java and Node.js applications, with a strong grasp of automation techniques,
and a proven ability to leverage Generative AI solutions such as AWS Bedrock to
accelerate security workflows.
This role requires close collaboration with InfoSec, QA, DevOps, and engineering
teams to ensure application security posture is proactively strengthened
through intelligent automation and continuous improvement.
Key Responsibilities
Analyze, triage, and remediate vulnerabilities identified via SAST, DAST, and
software composition analysis tools such as SonarQube, Veracode, Snyk, and
Checkmarx.
Refactor insecure Java and Node.js codebases to mitigate vulnerabilities such as
SQL Injection, XXE, XSS, CSRF, Deserialization, and Authentication flaws.
Patch and upgrade vulnerable third-party dependencies using Maven/Gradle,
and validate post-remediation effectiveness.
Leverage Generative AI tools (e.g., AWS Bedrock) to build or enhance
automation workflows for:
o Auto-remediation of common vulnerability patterns
o Code recommendations and patch generation
o AI-driven security analysis and triage assistance
o Automate vulnerability remediation and validation within CI/CD pipelines,
improving security velocity and reducing manual effort.
o Strengthen security configurations in Spring Boot, REST
APIs, Node.js services, and Tomcat-based deployments.
o Perform secure code reviews, provide remediation guidance, and promote
secure coding best practices across development teams.
o Collaborate with InfoSec and DevOps teams to validate fixes, perform re-
scans, and close vulnerability tickets.
o Stay current on security advisories, OWASP Top 10, CWE/SANS 25, and
Java/Tomcat ecosystem updates.
Required Skills
Strong hands-on experience with Core Java, Spring Boot, Tomcat, and REST API
development.
Proficiency in secure coding principles and application vulnerability remediation.
Experience remediating issues identified by tools like Veracode, Checkmarx,
SonarQube, or Snyk.
Knowledge of dependency management and patching practices using Maven or
Gradle.
Familiarity with Node.js security configurations and remediation techniques.
Experience with OAuth2/JWT, input validation, encryption, and secure session
management.
Understanding of Docker, Kubernetes, and security considerations in cloud-native
applications.
NodeJS Developer with vulnerability :: St. Louis, MO/ (Hybrid – 3 days onsite) · Han IT Staffing