Sr. Application Security Architect - .NET / Secure SDLC
$ - $ per year | Milpitas, CA | On-site | Permanent
Join a profitable, fast-growing Series C FinTech pioneer where you'll own application security architecture, shape the Secure SDLC, and secure products impacting millions of workers.
A bit about us:
We're a mission-driven fintech company building technology that helps millions of workers access the money they've already earned - when they need it most. Our platform integrates with employers and payroll systems to provide real-time wage access and financial wellness tools that reduce reliance on payday loans, overdraft fees, and other costly alternatives. Founded in Silicon Valley, our team is focused on using modern payment infrastructure and scalable cloud platforms to solve real financial challenges for everyday workers.
Why join us?
- Company sponsored Health, Dental, and Vision insurance
- Health, Dental and Vision Reimbursement account
- 401K, traditional, and Roth with a company match
- Tuition Assistance or Tuition Reimbursement
- Unlimited Paid Time off
- Monthly Gym Reimbursement
- Paid time off to volunteer
- Paid Family Leave
- Complimentary office lunches
- Opportunity to work with a great team committed to making a difference
Job Details
We're looking for a Senior Application Security Architect to own and advance application security across our engineering organization. This is a highly visible, hands-on role where you'll partner directly with engineering and security leadership to shape secure architecture, mature our Secure SDLC, and embed security into how software is designed and delivered.
This is not a traditional security monitoring role. We're looking for someone who combines deep Application Security expertise with a strong C#/.NET software engineering background and wants meaningful technical ownership.
What You'll Do:
- Lead application security architecture reviews and threat modeling using STRIDE, PASTA, attack trees, or similar methodologies.
- Own and mature our Secure SDLC (SSDLC) and security-by-design standards.
- Secure modern C#/.NET and ASP.NET Core applications, APIs, microservices, and supporting technologies.
- Embed SAST, DAST, SCA, secrets scanning, SBOM/SLSA, and ASPM into CI/CD pipelines.
- Establish secure authentication and authorization patterns using OAuth/OIDC, SAML, FIDO2, and mTLS.
- Perform secure code reviews and partner directly with developers on remediation.
- Prioritize application vulnerabilities using CVSS, EPSS, exploitability, and business risk.
- Help strengthen security across GitHub/Azure DevOps/GitLab and the broader software supply chain.
- Champion secure engineering practices and mentor developers on application security.
What We're Looking For:
- 8+ years of Application Security / Product Security / Secure SDLC experience.
- 8+ years of hands-on C#/.NET development experience, including modern .NET and ASP.NET Core.
- Deep knowledge of OWASP Top 10, OWASP ASVS, CWE, secure coding, and threat modeling.
- Strong hands-on experience with SAST, DAST, SCA, DevSecOps, and CI/CD security automation.
- Strong understanding of OAuth, OIDC, SAML, APIs, microservices, authentication, and authorization.
- Experience building or significantly maturing an enterprise Secure SDLC/AppSec program.
- Experience with NIST, PCI DSS, ISO 27001, or other regulated security frameworks.
- FinTech, payments, financial services, healthcare, or other regulated-industry experience is a plus.
- CSSLP, CISSP, OSWE, GWAPT, or similar certifications are a plus.
If you're an Application Security leader who still enjoys getting into the architecture and code—and wants real ownership rather than simply running security tools—we'd love to hear from you.
Jobot is an Equal Opportunity Employer. We provide an inclusive work environment that celebrates diversity and all qualified candidates receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, age (40 and over), disability, military status, genetic information or any other basis protected by applicable federal, state, or local laws. Jobot also prohibits harassment of applicants or employees based on any of these protected categories. It is Jobot's policy to comply with all applicable federal, state and local laws respecting consideration of unemployment status in making hiring decisions.
Sometimes Jobot is required to perform background checks with your authorization. Jobot will consider qualified candidates with criminal histories in a manner consistent with any applicable federal, state, or local law regarding criminal backgrounds, including but not limited to the Los Angeles Fair Chance Initiative for Hiring and the San Francisco Fair Chance Ordinance.
#J-18808-Ljbffr