Sr. Application Security Architect - .NET / Secure SDLC

Ts-California

Milpitas (CA)

On-site

USD 180,000 - 200,000

Full time

19 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health, Dental, Vision insurance
401K with company match
Tuition assistance
Unlimited Paid Time Off
Gym reimbursement

Job summary

Ts-California, a fintech company in Milpitas, is hiring a Senior Application Security Architect to own security across the engineering org. You will shape secure architecture, mature the Secure SDLC, and embed security into how software is designed and delivered.

This hands-on leader partners with engineering and security leadership to advance CI/CD security, perform threat modeling, code reviews, and secure coding practices in a modern .NET stack.

Qualifications

  • 8+ years in Application Security / Secure SDLC.
  • Hands-on C#/.NET development with ASP.NET Core.
  • Strong knowledge of OWASP Top 10, ASVS and threat modeling.
  • Experience with SAST/DAST/CI/CD security automation.

Responsibilities

  • Lead application security architecture reviews and threat modeling.
  • Own and mature SSDLC and security-by-design standards.
  • Secure modern C#/.NET apps, APIs, microservices, and CI/CD pipelines.
  • Embed security tooling (SAST/DAST/SCA) and SBOM in CI/CD.
  • Establish secure authentication/authorization patterns (OAuth/OIDC, SAML, mTLS).
  • Perform secure code reviews and remediation with developers.

Skills

C#/.NET development
Application Security
Threat modeling
OWASP Top 10
SAST/DAST/CI/CD
OAuth/OIDC/SAML
Secure SDLC
Security reviews

Tools

GitHub
Azure DevOps
GitLab
SBOM/SLSA

Job description

Sr. Application Security Architect - .NET / Secure SDLC

6926834

Location: Milpitas,CA, US

Date Posted: 09-19-2026

Job Description

Experience: Senior Level

Salary: $180,000 - $200,000 per year

Job Details

We’re looking for a Senior Application Security Architect to own and advance application security across our engineering organization. This is a highly visible, hands-on role where you’ll partner directly with engineering and security leadership to shape secure architecture, mature our Secure SDLC, and embed security into how software is designed and delivered. This is not a traditional security monitoring role. We’re looking for someone who combines deep Application Security expertise with a strong C#/.NET software engineering background and wants meaningful technical ownership.

What You’ll Do:
  • Lead application security architecture reviews and threat modeling using STRIDE, PASTA, attack trees, or similar methodologies.
  • Own and mature our Secure SDLC (SSDLC) and security-by-design standards.
  • Secure modern C#/.NET and ASP.NET Core applications, APIs, microservices, and supporting technologies.
  • Embed SAST, DAST, SCA, secrets scanning, SBOM/SLSA, and ASPM into CI/CD pipelines.
  • Establish secure authentication and authorization patterns using OAuth/OIDC, SAML, FIDO2, and mTLS.
  • Perform secure code reviews and partner directly with developers on remediation.
  • Prioritize application vulnerabilities using CVSS, EPSS, exploitability, and business risk.
  • Help strengthen security across GitHub/Azure DevOps/GitLab and the broader software supply chain.
  • Champion secure engineering practices and mentor developers on application security.
What We’re Looking For:
  • 8+ years of Application Security / Product Security / Secure SDLC experience.
  • 8+ years of hands-on C#/.NET development experience, including modern .NET and ASP.NET Core.
  • Deep knowledge of OWASP Top 10, OWASP ASVS, CWE, secure coding, and threat modeling.
  • Strong hands-on experience with SAST, DAST, SCA, DevSecOps, and CI/CD security automation.
  • Strong understanding of OAuth, OIDC, SAML, APIs, microservices, authentication, and authorization.
  • Experience building or significantly maturing an enterprise Secure SDLC/AppSec program.
  • Experience with NIST, PCI DSS, ISO 27001, or other regulated security frameworks.
  • FinTech, payments, financial services, healthcare, or other regulated-industry experience is a plus.
  • CSSLP, CISSP, OSWE, GWAPT, or similar certifications are a plus.

If you’re an Application Security leader who still enjoys getting into the architecture and code—and wants real ownership rather than simply running security tools,we’d love to hear from you.

A bit about us:

We’re a mission-driven fintech company building technology that helps millions of workers access the money they’ve already earned - when they need it most. Our platform integrates with employers and payroll systems to provide real-time wage access and financial wellness tools that reduce reliance on payday loans, overdraft fees, and other costly alternatives. Founded in Silicon Valley, our team is focused on using modern payment infrastructure and scalable cloud platforms to solve real financial challenges for everyday workers.

Why join us?

Company sponsored Health, Dental, and Vision insurance
Health, Dental and Vision Reimbursement account
401K, traditional, and Roth with a company match
Tuition Assistance or Tuition Reimbursement
Unlimited Paid Time off
Monthly Gym Reimbursement
Paid time off to volunteer
Paid Family Leave
Complimentary office lunches
Opportunity to work with a great team committed to making a difference

#techservices #asp-net-core #vulnerability-management #8-years-in-a-dedicated-application-security-secure-sdlc-role #penetration-testing-ethical-hacking-soc-siem-network-security-cloud-security-iam-grc-vulnerability-scanning #tier3

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Application Security Architect
Sr Application Security Architect

Dia Software Solutions • Richmond (VA)

Hybrid
USD 130,000 - 170,000
Senior Application Security Engineer
Senior Application Security Engineer

Clear Capital | CubiCasa | restb.ai • Reno (NV)

On-site
USD 111,000 - 144,400
Medical, dental, and vision insurance
401(k) with employer match
Paid time off and holidays
+3
Application Security Architect
Application Security Architect

Accord Technologies Inc • Richmond (VA)

On-site
USD 124,000 - 207,000
Sr. Application Security (AppSec) Architect - W2 Only
Sr. Application Security (AppSec) Architect - W2 Only

Saransh Inc • Maryland Heights (MO)

On-site
USD 140,000 - 190,000
Application Security Architect
Application Security Architect

Accylerate • Richmond (VA)

Hybrid
USD 140,000 - 190,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Texas City (TX)

On-site
USD 120,000 - 180,000
Professional growth
Competitive USD-based compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • New York (NY)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • San Francisco (CA)

On-site
USD 180,000 - 240,000
Professional growth
Competitive compensation
Exciting projects
+1
Senior Application Security Engineer
Senior Application Security Engineer

High Trail • Arlington (VA)

On-site
USD 140,000 - 190,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Orlando (FL)

On-site
USD 150,000 - 210,000
Professional growth
Competitive compensation
A selection of exciting projects
+1