Application Security Architect - .NET / Secure SDLC
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+12 more
Job description
We’re looking for a Senior Application Security Architect to own and advance application security across our engineering organization. This is a highly visible, hands-on role where you’ll partner directly with engineering and security leadership to shape secure architecture, mature our Secure SDLC, and embed security into how software is designed and delivered. This is not a traditional security monitoring role. We’re looking for someone who combines deep Application Security expertise with a strong C#/.NET software engineering background and wants meaningful technical ownership.
What You’ll Do:
- Lead application security architecture reviews and threat modeling using STRIDE, PASTA, attack trees, or similar methodologies.
- Own and mature our Secure SDLC (SSDLC) and security-by-design standards.
- Secure modern C#/.NET and ASP.NET Core applications, APIs, microservices, and supporting technologies.
- Embed SAST, DAST, SCA, secrets scanning, SBOM/SLSA, and ASPM into CI/CD pipelines.
- Establish secure authentication and authorization patterns using OAuth/OIDC, SAML, FIDO2, and mTLS.
- Perform secure code reviews and partner directly with developers on remediation.
- Prioritize application vulnerabilities using CVSS, EPSS, exploitability, and business risk.
- Help strengthen security across GitHub/Azure DevOps/GitLab and the broader software supply chain.
- Champion secure engineering practices and mentor developers on application security.
Requirements
- 8+ years of Application Security / Product Security / Secure SDLC experience.
- 8+ years of hands-on C#/.NET development experience, including modern .NET and ASP.NET Core.
- Deep knowledge of OWASP Top 10, OWASP ASVS, CWE, secure coding, and threat modeling.
- Strong hands-on experience with SAST, DAST, SCA, DevSecOps, and CI/CD security automation.
- Strong understanding of OAuth, OIDC, SAML, APIs, microservices, authentication, and authorization.
- Experience building or significantly maturing an enterprise Secure SDLC/AppSec program.
- Experience with NIST, PCI DSS, ISO 27001, or other regulated security frameworks.
- FinTech, payments, financial services, healthcare, or other regulated-industry experience is a plus.
- CSSLP, CISSP, OSWE, GWAPT, or similar certifications are a plus.
If you’re an Application Security leader who still enjoys getting into the architecture and code-and wants real ownership rather than simply running security tools-we’d love to hear from you.
Benefits & conditions
Salary: $180,000 - $200,000 per year
A bit about us:
We’re a mission-driven fintech company building technology that helps millions of workers access the money they’ve already earned - when they need it most. Our platform integrates with employers and payroll systems to provide real-time wage access and financial wellness tools that reduce reliance on payday loans, overdraft fees, and other costly alternatives. Founded in Silicon Valley, our team is focused on using modern payment infrastructure and scalable cloud platforms to solve real financial challenges for everyday workers.
Why join us?
Company sponsored Health, Dental, and Vision insurance Health, Dental and Vision Reimbursement account 401K, traditional, and Roth with a company match Tuition Assistance or Tuition Reimbursement Unlimited Paid Time off Monthly Gym Reimbursement Paid time off to volunteer Paid Family Leave Complimentary office lunches Opportunity to work with a great team committed to making a difference
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
The 12 Best Jobs for Software Engineers
What Are The Top Skills Required For Azure Developers?
Why Upskilling And Reskilling is Important For Developers