Senior Java Software Engineer
InRhythm · Pune District, Maharashtra, India
Apply & track with Apply EdgeAbout InRhythmInRhythm is a boutique technology consulting firm based in New York City, founded in 2002, focused on product innovation and platform modernization for Fortune 500 companies. The firm partners with clients across wealth & asset management, payments, and enterprise sectors — including names like American Express, Goldman Sachs, Mastercard, and Morgan Stanley — to accelerate digital transformation through senior engineering expertise, agile delivery, and AI-driven modernization. InRhythm has been recognized on the Inc. 5000 list of America's fastest-growing companies for multiple consecutive years, including a place in the Inc. 5000 Hall of Fame.
Do you enjoy working in a fast-paced, security-critical, technically demanding environment where correctness genuinely matters?The RoleWhat You Will DoPlan, design, develop, and deliver technical solutions that meet business requirements while adhering to security standards, engineering processes, and best practices.Own substantial features end-to-end across one or more services: API contract design, domain modelling, persistence, messaging, HSM integration, tests, documentation, deployment, and post-release support.Perform significant hands-on development and high-quality code review; raise the bar for design clarity, testability, error handling, and secure coding within the team.Design and evolve service APIs in an API-first / contract-first manner, keeping changes backward compatible for consuming application teams and managing versioning and deprecation responsibly.Contribute to the architecture of the platform: partner with Corporate Security Engineering Architects and Technical Leads on solution designs, ADRs, and trade-off analysis, and challenge designs constructively.Define and refine requirements for new applications and enhancements, translating business and security needs into workable technical specifications.Drive engineering quality: meaningful unit, slice, integration, and contract tests, architecture conformance rules, static analysis, dependency hygiene, and automated build/release pipelines.Diagnose and resolve complex production and pre-production issues within your area of expertise, including cryptographic, HSM, messaging, data consistency, and multi-region behaviours; drive root cause analysis and durable fixes.Participate in a rotational on-call support rotation for escalated issues, and continuously reduce operational toil through better observability, automation, and design.Mentor and grow junior and mid-level engineers through pairing, design reviews, code reviews, and knowledge sharing; onboard new joiners to the domain.Work independently and self-directed: identify what needs doing, sequence it sensibly, communicate progress, and escalate early when blocked.Collaborate across teams and time zones — with consuming application teams, security architecture, infrastructure, HSM operations, and audit — to deliver coherent solutions.All About YouEngineering FundamentalsExpert understanding of software engineering concepts, patterns, and methodologies — clean layering (e.g., hexagonal / ports-and-adapters), domain modelling, separation of concerns, data structures, and algorithms.Extensive experience designing, building, operating, and supporting shared, multi-tenant service platforms and RESTful APIs used by many internal consumers.Strong grasp of concurrency, transactional integrity, idempotency, resilience patterns, and failure modes in distributed systems.Understands the need for quality tests and how to apply them: unit, integration, contract, and non-functional testing; comfortable with test-first and mutation/coverage-driven thinking.Core Technology StackJava (modern LTS, 21+) as the primary language — deep, current, hands-on expertise is essential.Spring Boot 3.x and the wider Spring ecosystem (Spring Web / WebFlux, Spring Security, Spring Data, Spring Cloud); reactive programming with Project Reactor is a strong plus.Gradle (Kotlin DSL), version catalogs, multi-repo / composite builds, and CI/CD pipelines (Jenkins, Git-based workflows).OpenAPI-first API design with code generation, API linting/governance, and disciplined versioning.Relational databases and schema evolution: PostgreSQL, JPA/Hibernate, Flyway migrations, query performance, and data modelling.Event-driven and asynchronous messaging: Apache Kafka, event/command-driven or CQRS-style architectures (e.g., Axon), and reliable delivery patterns such as the transactional outbox.Containerised delivery and cloud-native operations: Docker, orchestration platforms, configuration and secret management (e.g., HashiCorp Vault), 12-factor configuration.Observability in production: structured logging, metrics, tracing, dashboards, and alerting — including how to instrument systems that must never log sensitive data.Git and modern collaborative development practices (PR-based workflows, code review culture, semantic versioning).Security and CryptographyGood working knowledge of industry-standard cryptographic algorithms and primitives — symmetric (AES, 3DES), asymmetric (RSA, ECC), hashing, MAC/CMAC, key derivation, and key wrapping — and sound judgement on how, where, and when to apply them.Practical experience with key management concepts: key hierarchies, LMKs, transport/zone keys, key blocks (e.g., TR-31), key ceremonies, rotation, custody, key states, and lifecycle.Hands-on experience integrating with Hardware Security Modules (e.g., Thales payShield, Entrust nShield) and cryptographic interfaces such as PKCS#11 and JCE/JCA.PKI and certificate management: X.509, CA hierarchies, CSR/issuance flows, certificate lifecycle and validation; EMV issuer certificate concepts are a strong plus.Secure service-to-service communication: TLS/mTLS, keystores and truststores, authentication/authorisation, and policy enforcement at the gateway.Secure development mindset: threat modelling, least privilege, secure defaults, secrets handling, and an instinct for never exposing key material, PANs, cryptograms, or tokens in logs, traces, or errors.Familiarity with payments domain standards and regulatory/compliance drivers (PCI DSS / PCI PIN / PCI P2PE, EMV, ISO 8583) is highly desirable.Ways of WorkingExpert critical-thinking and problem-solving skills; able to reason from first principles about unfamiliar, high-stakes systems.Highly motivated and proactive about the success of the team and the product, not just individual deliverables.High-energy, detail-oriented, and able to handle multiple high-priority demands while driving consistent, predictable results.Excellent written and verbal communication; can explain complex cryptographic and architectural concepts to both specialist and non-specialist audiences.Comfortable working in a globally distributed team, and a demonstrated willingness to mentor, document, and share knowledge.Nice to HaveExperience with multi-region / active-active deployments and the data-consistency challenges they bring.Experience modernising or decomposing legacy security services without disrupting existing consumers.Exposure to chaos engineering, performance/load testing, or capacity planning for latency-sensitive services.Corporate Security ResponsibilityEvery person working for, or on behalf of, the organization is responsible for information security. All activities involving access to assets, information, and networks come with an inherent risk to the organisation and, therefore, it is expected that the successful candidate for this position must:Abide by the organization's security policies and practices.Ensure the confidentiality and integrity of the information being accessed.Report any suspected information security violation or breach.Complete all periodic mandatory security trainings in accordance with guidelines.