By using Java and JSF with Facelets you have a good base to build secure applications. Tobago supports additional security concepts:
X-Frame-Options
X-Content-Type-Options
tobago-config.xml