Role Description
- Lead upgrade and remediation efforts for .NET Framework applications, with emphasis on RESTful services and web services (ASP.NET Web API, WCF).
- Perform secure code reviews and identify vulnerability patterns in legacy and new code; implement robust remediation and secure design patterns.
- Collaborate with Application Security (AppSec), QA, and development teams to triage findings and penetration testing; track remediation backlogs in Jira/Azure DevOps.
- Remediate secure REST APIs and integration points; enforce strong authentication/authorization (OAuth 2.0, OpenID Connect, JWT, SAML), and secure data transmission (TLS, encryption).
- Conduct threat modeling (e.g., STRIDE), risk assessments, and architecture reviews to identify attack surfaces and prioritize mitigations.
- Improve the Secure Software Development Life Cycle (SSDLC); implement and maintain security gates in CI/CD pipelines (e.g., SonarQube, Fortify, Veracode, SCA tools).
- Establish secure coding standards and guidelines; mentor developers on secure practices and remediation approaches.
- Review third-party libraries and components for vulnerabilities; manage remediation or replacements; maintain an inventory of risks.
- Create and maintain runbooks, remediation playbooks, and documentation for security fixes; contribute to incident response and root-cause analyses.
Requirements
- 8-10 years hands-on software development experience in .NET Framework (C#, ASP.NET, Web API, WCF) with strong REST and web services expertise.
- Proven experience identifying and remediating security vulnerabilities in enterprise applications.
- Deep knowledge of secure coding practices and OWASP Top 10; ability to translate findings into practical fixes.
- Strong understanding of authentication/authorization mechanisms (OAuth 2.0, OpenID Connect, JWT, SAML, Windows Integrated Authentication) and secure data handling.
- Experience with threat modeling (e.g., STRIDE) and risk-based remediation.
- Familiarity with security testing tools and workflows (SAST/DAST, SCA): Fortify, Veracode, SonarQube, Burp Suite, etc.
- Proficiency with CI/CD pipelines and DevOps tooling (Git, Azure DevOps/Jenkins, Jira); ability to integrate security checks into pipelines.
- Experience deploying and troubleshooting .NET Framework apps on Windows/IIS; understanding of certificate management, TLS, and encryption at rest/in transit.
- Strong problem-solving, communication, and stakeholder-management skills; ability to lead remediation efforts in a multi-team environment.
- Bachelor's degree in Computer Science, Information Systems