> Markdown version of [/jobs/ext/2530421-application-security-architect-net-secure-sdlc](https://www.wearedevelopers.com/jobs/ext/2530421-application-security-architect-net-secure-sdlc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Architect - .NET / Secure SDLC - **Company:** Jobot - **Location:** United States - **Experience:** Expert - **Salary:** $180,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** ASP.NET, .NET Framework, Application Programming Interfaces (APIs), User Authentication, Microsoft Azure, C Sharp (Programming Language), Continuous Integration, Github, Information Systems Security Architecture Professional, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Systems Development Life Cycle, Security Assertion Markup Language (SAML), Secure Coding, Software Engineering, Software Security, Gitlab, GWAPT, Devsecops, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** August 15, 2026 - **Apply:** https://www.dice.com/job-detail/a86341b6-fea9-470c-a04c-55eb589bd085 ## About the Role * 8+ years of Application Security / Product Security / Secure SDLC experience. * 8+ years of hands-on C#/.NET development experience, including modern .NET and ASP.NET Core. * Deep knowledge of OWASP Top 10, OWASP ASVS, CWE, secure coding, and threat modeling. * Strong hands-on experience with SAST, DAST, SCA, DevSecOps, and CI/CD security automation. * Strong understanding of OAuth, OIDC, SAML, APIs, microservices, authentication, and authorization. * Experience building or significantly maturing an enterprise Secure SDLC/AppSec program. * Experience with NIST, PCI DSS, ISO 27001, or other regulated security frameworks. * FinTech, payments, financial services, healthcare, or other regulated-industry experience is a plus. * CSSLP, CISSP, OSWE, GWAPT, or similar certifications are a plus. If you're an Application Security leader who still enjoys getting into the architecture and code-and wants real ownership rather than simply running security tools-we'd love to hear from you. ## Description We're looking for a Senior Application Security Architect to own and advance application security across our engineering organization. This is a highly visible, hands-on role where you'll partner directly with engineering and security leadership to shape secure architecture, mature our Secure SDLC, and embed security into how software is designed and delivered. This is not a traditional security monitoring role. We're looking for someone who combines deep Application Security expertise with a strong C#/.NET software engineering background and wants meaningful technical ownership. What You'll Do: * Lead application security architecture reviews and threat modeling using STRIDE, PASTA, attack trees, or similar methodologies. * Own and mature our Secure SDLC (SSDLC) and security-by-design standards. * Secure modern C#/.NET and ASP.NET Core applications, APIs, microservices, and supporting technologies. * Embed SAST, DAST, SCA, secrets scanning, SBOM/SLSA, and ASPM into CI/CD pipelines. * Establish secure authentication and authorization patterns using OAuth/OIDC, SAML, FIDO2, and mTLS. * Perform secure code reviews and partner directly with developers on remediation. * Prioritize application vulnerabilities using CVSS, EPSS, exploitability, and business risk. * Help strengthen security across GitHub/Azure DevOps/GitLab and the broader software supply chain. * Champion secure engineering practices and mentor developers on application security. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)