Windows Application Security Developer

Accord Technologies Inc

Atlanta (GA)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A tech company is seeking a Windows Application Security Developer to lead the remediation of security vulnerabilities in legacy Windows applications. The role requires expertise in VB6, .NET (C# and/or VB.NET), and secure coding practices. Candidates should have extensive experience with Veracode SAST and a solid understanding of SQL and command injection vulnerabilities. This position offers a chance to work with a diverse codebase and tackle critical security challenges.

Qualifications

  • 8 to 9+ years of professional experience in Windows desktop application development (VB6 / .NET).
  • Strong hands-on experience with Visual Basic 6 (VB6) including ADO and Windows API.
  • Ability to write and execute security-focused test cases to validate fixes.

Responsibilities

  • Interpret Veracode SAST reports and triage vulnerabilities based on severity.
  • Prioritize remediation backlog and communicate status to stakeholders.
  • Maintain documentation for root cause analysis, code changes, and testing.

Skills

Visual Basic 6 (VB6)
C# or VB.NET
SQL Injection remediation
Command Injection remediation
Veracode SAST experience
Windows API
Software version control (Git/SVN)

Education

Bachelor's or Master's in Computer Science, Software Engineering, Cybersecurity

Tools

Veracode
JIRA
Azure DevOps
GitHub Issues

Job description

Overview

Windows Application Security Developer

Location: Atlanta, GA

Duration: 6-12 months

Skills needed: Windows application development & security, Veracode remediation | VB6 / C# / VB.NET | Fortran | Python | .NET Framework | SQL Server | SQL | Veracode | Windows Desktop

Role

We are seeking an experienced Application Security Developer to lead the remediation of security vulnerabilities in a legacy Windows application. The primary focus is on resolving High and Critical severity findings — specifically Command Injection and SQL Injection — across a mixed-language Windows desktop application codebase. The ideal candidate brings deep expertise in legacy VB6 development, modern .NET (C# and/or VB.NET), secure coding practices, and hands-on experience interpreting and fixing Veracode findings. This is a security-first development role requiring both strong technical skills and a methodical approach to vulnerability triage, remediation, and validation.

System & Application Context

Primary Language: Visual Basic 6 (VB6) — Legacy codebase; primary source of Veracode findings

Additional Languages: C#, VB.NET (.NET Framework) — Windows Forms modules; subject to SAST scans

Supporting Languages: Fortran, Python — Peripheral components; may have ancillary findings

UI Framework: Windows Forms (.NET Framework) — Input/output surfaces; injection risk areas

Database: SQL Server / SQL (ADO/ADO.NET) — Parameterized query remediation required

Platform: Windows OS (7 / 10 / 11) — Desktop deployment; MSI packaging

SAST Tool: Veracode — Source of all vulnerability findings for this role

Key Responsibilities
  • Interpret Veracode SAST reports — understand CWE classifications, flaw categories, and severity scoring.
  • Triage High and Critical findings by exploitability, business impact, and remediation complexity.
  • Map each Veracode finding to the relevant source code module — VB6, C#, VB.NET, SQL, Python, or Fortran.
  • Prioritize remediation backlog and communicate status to stakeholders and auditors.
  • Identify and fix OS command injection vulnerabilities across VB6 and .NET components.
  • Identify and fix SQL injection vulnerabilities in VB6, .NET, and any dynamic SQL construction patterns.
  • Work within the VB6 codebase — Windows API calls, ActiveX components, and VB6-specific security pitfalls.
  • Rebuild applications after applying patches — manage dependencies, resolve build errors, and validate successful compilation.
  • Perform unit-level and integration-level testing for each patched module.
  • Execute Veracode rescans to confirm vulnerability resolution and track flaw closure rate.
  • Conduct regression testing to ensure no functional degradation, performance impact, or breaking changes.
  • Maintain documentation: root cause analysis, code changes, testing approach, and residual risk per finding.
Required Skills & Experience
  • Strong hands-on experience with Visual Basic 6 (VB6) — including ADO, Windows API, ActiveX, and VB6 IDE.
  • Proficiency in C# and/or VB.NET on .NET Framework — Windows Forms development and data access.
  • Deep understanding of SQL injection (remediation: parameterized queries, stored procedures, input validation).
  • Proven experience fixing command injection: input sanitization, allowlisting, safe execution patterns.
  • Hands-on experience with Veracode SAST — interpreting findings, understanding CWE classifications, and driving flaw closure.
  • Knowledge of OWASP Top 10 and secure coding standards applicable to Windows desktop applications.
  • Experience with CVSS scoring, vulnerability triage, and remediation prioritization.
  • Ability to write and execute security-focused test cases to validate fixes.
  • Proficiency with Git or SVN for source code version control and patch management.
  • Experience with code review processes, pull requests, and collaborative development workflows.
  • Familiarity with issue tracking systems such as JIRA, Azure DevOps, or GitHub Issues.
  • Bachelor\'s or Master\'s degree in Computer Science, Software Engineering, Cybersecurity, or a related field.
  • 8 to 9+ years of professional experience in Windows desktop application development (VB6 / .NET).
  • Experience with additional languages in scope: Python, Fortran code review.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Windows App Security Engineer: VB6/.NET Remediation Lead
Windows App Security Engineer: VB6/.NET Remediation Lead

Accord Technologies Inc • Atlanta (GA)

On-site
USD 100,000 - 130,000
2041 Senior VB.NET Developer
2041 Senior VB.NET Developer

The Talent Advantage Group • Detroit (MI)

On-site
USD 90,000 - 135,000
Application Security Analyst
Application Security Analyst

AccruePartners • Fort Mill (SC)

Hybrid
USD 70,000 - 90,000
Ongoing investment in professional development
Exposure to modern security platforms
Collaborative team environment
Sr. Application Security Engineer
Sr. Application Security Engineer

Bridge Technologies and Solutions • Cherry Hills Village (CO)

On-site
USD 80,000 - 110,000
Sr. Application Security Engineer
Sr. Application Security Engineer

Bridge Technologies and Solutions • Montvale (NJ)

On-site
USD 80,000 - 110,000
Secure Code Remediation Engineer (Java/.NET)
Secure Code Remediation Engineer (Java/.NET)

Programmers.io • Pittsburgh

On-site
USD 80,000 - 100,000
Sr. Application Security Engineer
Sr. Application Security Engineer

Bridge Technologies and Solutions • San Francisco (CA)

On-site
USD 120,000 - 160,000
Senior Software Developer
Senior Software Developer

VT Group (VTG) • Herndon (VA)

On-site
USD 100,000 - 140,000
VB6 Developer
VB6 Developer

TechDigital Group • Secaucus (NJ)

On-site
USD 70,000 - 110,000
Application Security Analyst
Application Security Analyst

Stellantis • Auburn (AL)

On-site
USD 90,000 - 120,000