Logo

.NET AppSec Engineer (Remote)

Kforce • Birmingham, AL


No Relocation

Posted: August 27, 2026

Responsibilities
  • Work directly within .NET and Angular applications to remediate security vulnerabilities and improve application security
  • Design, develop, and secure REST APIs
  • Improve API authentication, authorization, and security controls
  • Identify and remediate security vulnerabilities in existing applications and codebases
  • Apply secure coding practices and Secure SDLC principles
  • Support remediation efforts across multiple applications and development teams
  • Work with security findings from SAST, DAST, SCA, and similar application security tools
  • Help improve API standards, governance, and security compliance
  • Support secure CI/CD and development practices using GitHub and GitHub Actions
  • Work across both legacy and modern applications and quickly adapt to new teams and environments
Requirements
  • Strong hands-on development experience with .NET/.NET Core
  • Experience developing and supporting Angular applications
  • Strong experience building and securing REST APIs
  • Demonstrated experience with API security, including authentication and authorization
  • Experience with MuleSoft or a similar API management, API gateway, or integration platform
  • Experience identifying and remediating application or API security vulnerabilities
  • Strong understanding of secure coding practices and the Secure SDLC
  • Familiarity with OWASP principles and common application security vulnerabilities
  • Experience working with security findings from SAST, DAST, SCA, or similar tools
  • Experience with GitHub, GitHub Actions, and modern CI/CD practices
  • Ability to work directly within existing codebases and make hands-on remediation changes
  • MuleSoft experience highly preferred
  • Experience with JWT validation and modern authentication and authorization frameworks
  • Experience with API governance and API security standards
  • React development experience
  • Experience with GitHub Advanced Security and Dependabot
  • Experience with secrets management technologies such as HashiCorp Vault
  • Experience with Aqua Security or similar container and application security tools.
  • Microservices and application modernization experience
  • Experience in banking, financial services, or another highly regulated industry
  • Experience working in environments with significant security and compliance requirements