Назад
Company hidden
6 дней назад

.NET Developer (Application Security)

90 - 110$
Формат работы
onsite
Тип работы
project
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
.NET Developer (Application Security) (.NET/Azure): Remediating application-security vulnerabilities across .NET applications and services for a highly regulated financial institution with an accent on secure coding, dependency upgrades, and production-ready fixes. Focus on integrating security controls into CI/CD pipelines, addressing cloud and container vulnerabilities, and leading complex remediation across engineering teams.

Location: New York City, New York, United States

Hourly rate: $90–110/hour. W2 employment. Duration: 12 months.

Company

hirify.global provides on-demand talent, consulting, and outsourced services through a global network of more than 2,600 experts.

What you will do

  • Remediate application-security vulnerabilities across primarily Microsoft .NET applications and services.
  • Support security fixes in Java, Spring Boot, React, and TypeScript applications.
  • Validate security findings, identify root causes, prioritize remediation, and resolve issues involving access control, injection, secrets, encryption, APIs, and insecure configurations.
  • Upgrade vulnerable frameworks, libraries, packages, and dependencies while developing automated tests to prevent regressions.
  • Integrate security scanning and controls into CI/CD pipelines and address vulnerabilities in Azure, containers, Kubernetes, and OpenShift environments.
  • Coordinate release validation and issue closure, review code, mentor engineers, and supervise remediation work.

Requirements

  • Six or more years of software-engineering experience with strong hands-on .NET expertise.
  • Proficiency in C#, ASP.NET Core, Web API, Entity Framework, REST APIs, and microservices.
  • Experience remediating vulnerabilities using OWASP, CWE, and CVE guidance, including findings from SAST, DAST, SCA, penetration testing, and code scans.
  • Knowledge of OAuth, OIDC, JWT, RBAC, encryption, TLS, secrets management, and API security.
  • Experience with Azure services such as App Services, Functions, API Management, and Key Vault, plus familiarity with Git, Docker, Kubernetes, OpenShift, and CI/CD platforms.
  • Strong automated-testing, production-support, debugging, root-cause-analysis, communication, and technical-leadership skills; financial-services experience is required.

Culture & Benefits

  • Hands-on engineering role embedded with application-development teams at a highly regulated global financial institution.
  • Technical leadership and mentoring responsibilities without traditional people management.
  • Medical, dental, vision, life, and disability insurance.
  • 401(k) Savings Plan, Employee Stock Purchase Plan, professional development program, paid time off, and paid sick time where legally required.
  • Equal opportunity and inclusive work environment focused on continuous learning and development.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →