> Markdown version of [/jobs/ext/2551818-cybersecurity-platform-and-identity-security-engineer](https://www.wearedevelopers.com/jobs/ext/2551818-cybersecurity-platform-and-identity-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Platform and Identity Security Engineer - **Company:** Verizon Communications Inc. - **Location:** Temple Terrace, FL, United States (Remote available) - **Experience:** Experienced - **Salary:** $111,500.0 - $194,000.0 - **Contract:** Permanent contract - **Skills:** .NET Framework, Active Directory, Application Programming Interfaces (APIs), Artificial Intelligence, Microsoft Azure, Software Bug Management, C Sharp (Programming Language), Cyber Security, Data Validation, Database Connection, Software Debugging, Dependency Injection, White-Box Testing, Identity and Access Management, Lightweight Directory Access Protocols (LDAP), NuGet, OAuth, Open Web Application Security, Secure Coding, Service-Oriented Architecture, Service Development Studio, Software Engineering, SQL Databases, Data Streaming, Cyberark, GitHub Copilot, Software Security, Apigee, Gitlab, Bug Reporting, Tenable Nessus, Restful APIs, Key Vault, Static Application Security Testing, Microservices - **Published:** August 15, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88047006/1 ## About the Role You've built enough software to have opinions about what breaks in production, and you've been around enough security incidents (or near-misses) to take credential hygiene seriously without being told twice. You can read unfamiliar code and quickly build a mental model of what it does, what it trusts, and where it could go wrong. When you find a security issue - whether it's a missing input sanitization call, an unsafe configuration value, or an inconsistently applied pattern - you don't just flag it, you fix it and make sure the fix is applied consistently across every occurrence in the codebase. You work well with a principal who sets direction: you can take a remediation roadmap or an architectural decision and execute it thoroughly, flag edge cases you find along the way, and deliver work that doesn't require rework., * Bachelor's degree or four or more years of work experience. * Four or more years of relevant work experience required, demonstrated through work experience and/or military experience. * Four or more years of software engineering experience. * .NET (C#) development skills specifically with async/await, dependency injection, REST API design, and common framework patterns. * Experience with injection vulnerabilities (SQL, LDAP), authentication/authorization patterns, and secure configuration practices. * Experience working in a microservice or service-oriented architecture. Even better if you have one or more of the following: * Comfort reading and reasoning about unfamiliar codebases - you can navigate a large repo, understand data flow, and identify where trust boundaries exist. * Working knowledge of Active Directory concepts: users, groups, OUs, permissions - enough to understand what the services you're working on actually do. * Security+ or equivalent foundational security knowledge. * Hands-on experience with OWASP Top 10 or OWASP API Security Top 10 - not just awareness, but having found or fixed examples. * Exposure to secrets scanning tools (TruffleHog, GitLeaks) or SAST tooling in CI/CD pipelines. * Experience integrating with or debugging Active Directory operations (LDAP queries, group membership, account management). * Familiarity with CyberArk or other PAM platforms. * JWT / OAuth 2.0 - understanding how tokens are issued, validated, and where they can be abused. * Azure DevOps or GitLab pipeline experience. * Experience working with shared internal NuGet packages or internal frameworks - understanding how breaking changes propagate. * EF Core, database connection management, migration patterns. * Experience using AI coding tools (GitHub Copilot, Claude Code, or similar) as a real accelerator on day-to-day engineering work. * Track record of producing clear technical documentation - not just for external audiences, but the kind that helps the next engineer understand what a service does and why ## Description Service Development & Maintenance * Build and maintain microservices within a shared .NET framework (Micro.Framework, SharedServices, WebTools). * Implement feature work, bug fixes, and platform upgrades across a large service fleet - async pattern improvements, framework version migrations, NuGet dependency updates. * Contribute to breaking-change analysis when shared libraries evolve: understand downstream impact, validate that consumer contracts hold. * Build and maintain SCIM provisioning integrations that automate identity lifecycle events (create, update, deprovision) across enterprise systems. * Develop and manage API proxies, policies, Automation, and traffic management in Apigee for services exposed internally and externally. Security Remediation & Hardening * Implement security remediations identified through assessment, spanning application-layer vulnerabilities and security configuration hardening. * Apply cloud-native secrets management patterns: Key Vault integration, Managed Identity, encrypted connections, and proper JWT validation. * Write secure code by default - parameterized queries, input validation at system boundaries, least-privilege service accounts. Security Assessment Participation * Participate in white-box security reviews of internal services - reading code with an attacker's eye, identifying common application-layer vulnerabilities. * Document findings with enough specificity to be actionable: file paths, line numbers, CVSS context, reproduction steps. * Translate security findings into working code fixes, not just recommendations. AI-Augmented Development * Use AI coding assistants actively in your daily workflow - for large refactors, codebase comprehension, documentation, and repetitive pattern application across multiple services. * Know where AI output needs validation and when to course-correct. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [How your .NET software supply chain is open to attack : and how to fix it](https://www.wearedevelopers.com/videos/938-how-your-net-software-supply-chain-is-open-to-attack-and-how-to-fix-it) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)