Application Security Architect - .NET / Secure SDLC

Jobot
United States
21 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$180,000.0 - $200,000.0
Working hours
Regular working hours
Job source

Tech stack

ASP.NET .NET Framework Application Programming Interfaces (APIs) User Authentication Microsoft Azure C Sharp (Programming Language) Continuous Integration Github Information Systems Security Architecture Professional OAuth OpenID Open Web Application Security
+12 more
PCI Data Security Standards Systems Development Life Cycle Security Assertion Markup Language (SAML) Secure Coding Software Engineering Software Security Gitlab GWAPT Devsecops Static Application Security Testing Microservices Dynamic Application Security Testing

Job description

We’re looking for a Senior Application Security Architect to own and advance application security across our engineering organization. This is a highly visible, hands-on role where you’ll partner directly with engineering and security leadership to shape secure architecture, mature our Secure SDLC, and embed security into how software is designed and delivered. This is not a traditional security monitoring role. We’re looking for someone who combines deep Application Security expertise with a strong C#/.NET software engineering background and wants meaningful technical ownership.

What You’ll Do:

  • Lead application security architecture reviews and threat modeling using STRIDE, PASTA, attack trees, or similar methodologies.
  • Own and mature our Secure SDLC (SSDLC) and security-by-design standards.
  • Secure modern C#/.NET and ASP.NET Core applications, APIs, microservices, and supporting technologies.
  • Embed SAST, DAST, SCA, secrets scanning, SBOM/SLSA, and ASPM into CI/CD pipelines.
  • Establish secure authentication and authorization patterns using OAuth/OIDC, SAML, FIDO2, and mTLS.
  • Perform secure code reviews and partner directly with developers on remediation.
  • Prioritize application vulnerabilities using CVSS, EPSS, exploitability, and business risk.
  • Help strengthen security across GitHub/Azure DevOps/GitLab and the broader software supply chain.
  • Champion secure engineering practices and mentor developers on application security.

Requirements

  • 8+ years of Application Security / Product Security / Secure SDLC experience.
  • 8+ years of hands-on C#/.NET development experience, including modern .NET and ASP.NET Core.
  • Deep knowledge of OWASP Top 10, OWASP ASVS, CWE, secure coding, and threat modeling.
  • Strong hands-on experience with SAST, DAST, SCA, DevSecOps, and CI/CD security automation.
  • Strong understanding of OAuth, OIDC, SAML, APIs, microservices, authentication, and authorization.
  • Experience building or significantly maturing an enterprise Secure SDLC/AppSec program.
  • Experience with NIST, PCI DSS, ISO 27001, or other regulated security frameworks.
  • FinTech, payments, financial services, healthcare, or other regulated-industry experience is a plus.
  • CSSLP, CISSP, OSWE, GWAPT, or similar certifications are a plus.

If you’re an Application Security leader who still enjoys getting into the architecture and code-and wants real ownership rather than simply running security tools-we’d love to hear from you.

Benefits & conditions

Salary: $180,000 - $200,000 per year

A bit about us:

We’re a mission-driven fintech company building technology that helps millions of workers access the money they’ve already earned - when they need it most. Our platform integrates with employers and payroll systems to provide real-time wage access and financial wellness tools that reduce reliance on payday loans, overdraft fees, and other costly alternatives. Founded in Silicon Valley, our team is focused on using modern payment infrastructure and scalable cloud platforms to solve real financial challenges for everyday workers.

Why join us?

Company sponsored Health, Dental, and Vision insurance Health, Dental and Vision Reimbursement account 401K, traditional, and Roth with a company match Tuition Assistance or Tuition Reimbursement Unlimited Paid Time off Monthly Gym Reimbursement Paid time off to volunteer Paid Family Leave Complimentary office lunches Opportunity to work with a great team committed to making a difference

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

Videos

See all

Related articles

See all