Java Security Integration Engineer
Location: Loveland, ColoradoSchedule: Hybrid (3 days onsite)Duration: 6-12 Months (with potential for extension)Experience Level: Senior (Minimum 5+ years of relevant experience)Target Start Date: ImmediateRole SummaryWe are seeking an experienced Contract Senior Java Security Integration Engineer to join our team for a critical, high-impact engagement. In this role, you will lead the implementation and refinement of application security features, identity management systems, and monitoring integrations across our software ecosystem.The ideal candidate is a hands-on developer with 5+ years of experience who bridges the gap between core Java development and modern web application security practices. You will be responsible for developing secure integrations, implementing robust Customer Identity & Access Management (CIAM) systems, establishing secure Single Sign-On (SSO) pathways, work on legacy system refactoring, troubleshooting application behaviors behind Web Application Firewalls (WAF), and ensuring that security logging seamlessly integrates with our enterprise SIEM platforms.Key ResponsibilitiesSecurity Architecture & Feature DevelopmentSecure Coding: Design, develop, and maintain high-performance, secure Java-based backend services and APIs using modern frameworks (e.g., Spring Boot, Spring Security).AppSec Best Practices: Conduct threat modeling, perform secure code reviews, and remediate application vulnerabilities based on OWASP Top 10 standards.Identity & Access Management (IAM / CIAM)SSO Integrations: Design and configure secure Single Sign-On (SSO) workflows utilizing industry-standard protocols including SAML 2.0, OAuth 2.0, and OpenID Connect (OIDC).IdP Management: Integrate enterprise application suites with primary Identity Providers (IdPs) such as Okta, Auth0, Microsoft Entra ID (Azure AD), or Keycloak.CIAM Implementation: Lead the implementation of Customer Identity & Access Management (CIAM) systemsExperience with B2C authentication architecture.A strong understanding of modern authentication and authorization protocols to secure client-facing portals, including multi-factor authentication (MFA) and registration workflows.Perimeter Protection & Incident MonitoringWAF Integration: Partner with infrastructure and cloud engineering teams to Develop custom WAF rules to safeguard against OWASP vulnerabilities.Analyze WAF logs and fine-tune security policies to minimize false positives.SIEM Logging & Integration: Architect and implement structured, standardized logging patterns within our Java services to enable seamless event ingestion, correlation, and alerting in Security Information and Event Management (SIEM) systems (e.g., Splunk, Datadog, Microsoft Sentinel).Secure AI & API IntegrationAI & LLM Integration: Design and implement backend integrations with Large Language Models (LLMs) and AI platform endpoints (e.g., OpenAI, Azure OpenAI, AWS Bedrock).RAG Architectures: Build and maintain Retrieval-Augmented Generation (RAG) pipelines, ensuring that corporate data sources are safely queried, contextually injected, and filtered.Collaboration & ComplianceDeliver clear documentation including technical integration guides, identity flow architecture diagrams, and run books.Work collaboratively with DevOps, Cloud Infrastructure, and Compliance teams to align development practices with internal security policies and external compliance requirements.Data Sovereignty: Assist in the architectural planning, database schema split, and data migration strategies required to establish an isolated EU-specific instance to comply with GDPRRequired Skills & QualificationsCore Java Mastery: 5+ years of professional experience developing enterprise-grade software applications using Java (Spring Framework / Spring Boot).Identity Protocols: Strong hands-on experience designing and troubleshooting complex identity federation flows using SAML 2.0, OpenID Connect (OIDC), OAuth 2.0, and JWT.CIAM/IAM Expertise: Deep familiarity with integrating apps with Customer Identity systems and major IdPs (e.g., Okta, Auth0, Keycloak).Application Security (AppSec): Thorough understanding of cryptography, transport security (TLS/SSL), API security, and secure coding fundamentals.Perimeter Security: Experience coordinating and troubleshooting Web Application Firewall (WAF) rule sets, traffic filtering, and rate limiting.SIEM & Logging Infrastructure: Practical experience setting up application logging frameworks (Logback, Log4j2) to output security event formats consumable by SIEM monitoring tools.Contractor Mindset: Proven ability to work independently in a fast-paced environment with minimal supervision; highly organized and milestone-driven.Preferred QualificationsFamiliarity with containerization technologies (Docker, Kubernetes) and secure cloud deployment architectures (AWS, Azure, or OCI).Experience working with Picture Archiving and Communication Systems (PACS) for medical devices using DICOM (DICOM (Digital Imaging and Communications in Medicine) protocol.Understanding of modern regulatory frameworks (e.g., GDPR, NIS2, or HIPAA/HITRUST) as they relate to application security and data privacy.Relevant industry certifications are a plus.Benefits:At Ledgent Technology, we prioritize our contractors, whom we proudly call Ambassadors. Our commitment to you is demonstrated through a comprehensive benefits program that stands out in the temporary staffing industry. We annually review and update our vendor relationships to ensure we provide the most cost-effective benefits options. Our Ambassadors are eligible for a wide range of benefits, including:Minimum Essential Coverage (MEC) PlanBasic and enhanced hospital indemnity plansDental and vision coverageAccident and critical illness plansTerm life insuranceShort-term disability planDirect deposit/pay card optionsCredit union membershipEmployee discount clubsReferral bonusesTraining and coachingSpecialized recognition programsAll qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status. We consider all qualified applicants, including those with criminal histories, in a manner consistent with state and local laws, including the California Fair Chance Act, City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, and Los Angeles County Fair Chance Ordinance.