Position: Application Security Engineer Location: 9 MetroTech Brooklyn, NY 11201 Hybrid Duration: Long Term Contract Company: PruTech Solutions, Inc.
About PruTech
Founded in 1998, PruTech Solutions is a nationally recognized technology and management consulting firm delivering innovative solutions to complex business, operational, and technology challenges. Through deep client partnerships and a commitment to measurable outcomes, PruTech has earned the trust of leading public and private sector organizations across government, transportation, finance, retail, and manufacturing. Headquartered in New Jersey, with additional offices in New York City, Washington DC, and North Carolina, and nearshore delivery centers in Mexico City and India, PruTech brings over 25 years of expertise in enterprise technology, system integration, program management, and operational transformation. Our consultants are known for their hands-on leadership, strategic insight, and ability to deliver mission-critical initiatives on time and within scope.
Position Overview
The Application Security Engineer is embedded within the Application Development team and ensures security is integrated into all stages of software development. The role focuses on designing and building secure applications while working closely with application administrators who manage security tools and CI/CD pipelines. This position is responsible for enabling developers to produce secure, resilient, and compliant software for FDNY s web, mobile, API, GIS, and cloud-based systems supporting Fire, EMS, and administrative operations.
Core Responsibilities
Secure Software Development
Establish and apply secure coding practices within the development team.
Define and enforce secure coding standards for Java, .NET, Python, and JavaScript applications.
Conduct secure design and architecture reviews for new and legacy systems.
Educate developers on secure coding practices, authentication/authorization best practices, and common application vulnerabilities.
Apply protections aligned with:
OWASP Top 10
OWASP API Security Top 10
Application & API Security
Design and implement secure REST APIs and web services.
Implement secure authentication/authorization using:
SAML2
OIDC
OAuth2
Secure Java and JavaScript applications, including:
Spring Boot
React
Ensure secure handling of tokens, sessions, and secrets.
Collaborate with App Admins and Security team to integrate applications into WAFs, load balancers, and other security monitoring tools.
Mandatory Qualifications
Minimum 4+ years in secure application development.
Prior hands-on software development experience.
Strong understanding of:
Web and mobile application architecture
Internet protocols (HTTP, HTTPS, WebSockets)
REST API security
Expertise in SAST, DAST, and SCA concepts (understanding results and remediation), in collaboration with App Admins.
Familiarity with security tools such as Veracode, Burp Suite, Zimperium, Prisma, Rapid7.
Experience applying NIST 800-53 and 800-171 controls at the application design level.
Strong analytical, troubleshooting, and problem-solving skills.
Ability to work independently within a development-focused team.
Preferred Qualifications
Experience with containerized applications (Docker, Kubernetes).
Knowledge of:
Core Java, J2EE, Spring Boot
React, AngularJS, HTML5, CSS, JavaScript
Experience designing secure GIS systems.
Familiarity with public safety or emergency response systems. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.