Logo
.NET AppSec Engineer (Remote)
Kforce • Birmingham, AL
No Relocation
Posted: August 27, 2026
Responsibilities
- Work directly within .NET and Angular applications to remediate security vulnerabilities and improve application security
- Design, develop, and secure REST APIs
- Improve API authentication, authorization, and security controls
- Identify and remediate security vulnerabilities in existing applications and codebases
- Apply secure coding practices and Secure SDLC principles
- Support remediation efforts across multiple applications and development teams
- Work with security findings from SAST, DAST, SCA, and similar application security tools
- Help improve API standards, governance, and security compliance
- Support secure CI/CD and development practices using GitHub and GitHub Actions
- Work across both legacy and modern applications and quickly adapt to new teams and environments
Requirements
- Strong hands-on development experience with .NET/.NET Core
- Experience developing and supporting Angular applications
- Strong experience building and securing REST APIs
- Demonstrated experience with API security, including authentication and authorization
- Experience with MuleSoft or a similar API management, API gateway, or integration platform
- Experience identifying and remediating application or API security vulnerabilities
- Strong understanding of secure coding practices and the Secure SDLC
- Familiarity with OWASP principles and common application security vulnerabilities
- Experience working with security findings from SAST, DAST, SCA, or similar tools
- Experience with GitHub, GitHub Actions, and modern CI/CD practices
- Ability to work directly within existing codebases and make hands-on remediation changes
- MuleSoft experience highly preferred
- Experience with JWT validation and modern authentication and authorization frameworks
- Experience with API governance and API security standards
- React development experience
- Experience with GitHub Advanced Security and Dependabot
- Experience with secrets management technologies such as HashiCorp Vault
- Experience with Aqua Security or similar container and application security tools.
- Microservices and application modernization experience
- Experience in banking, financial services, or another highly regulated industry
- Experience working in environments with significant security and compliance requirements