CIAM Developer
HybridHyderabad, Telangana, India or Noida, Uttar Pradesh, India
Job Summary
Develop and remediate security vulnerabilities in custom-built backend (Java/Spring) and frontend (React) applications across Customer Identity and Access Management (CIAM) initiatives. Execute OWASP Top 10 fixes, address third-party dependency CVEs, and refactor legacy code to align with secure coding standards. Implement OAuth 2.0, OpenID Connect, and SAML flows, including SSO, MFA, and federated identity integrations with platforms like Azure AD B2C and Okta. Embed security checks into CI/CD pipelines, conduct threat modeling, and maintain documentation for ISO and GDPR compliance. Collaborate with security teams and architects on design reviews and vulnerability management lifecycles.
Required Qualifications
- Strong hands-on experience in Java (8+) and Spring Boot / Spring Security
- Proven experience in application vulnerability remediation
- Experience with security tools: Snyk, Checkmarx, Fortify, Veracode, SonarQube
- Frontend expertise: React.js with focus on secure coding practices
- Good understanding of REST APIs, Microservices architecture
- In-depth knowledge of OWASP Top 10 vulnerabilities
- Secure coding and secure design principles
- Experience managing CVE fixes and dependency upgrades
- Strong understanding of Authentication & Authorization mechanisms
- Hands-on experience with OAuth 2.0, OpenID Connect, SAML
- Familiarity with CIAM platforms: Azure AD B2C / Okta / Ping Identity
- Strong problem-solving and analytical skills
- High attention to detail with a security-first mindset
- Ability to work independently and collaboratively
- Effective communication with cross-functional teams
- Our employees work in the office at least three (3) days per week, with flexibility to work from home two (2) days per week
Desired Qualifications
- Experience with containerization (Docker, Kubernetes)
- Exposure to API security and API gateways
- Knowledge of Zero Trust security principles
- Certifications (Good to Have): CEH / CSSLP / OAuth certifications / Cloud Security
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.