Job Overview

We are building an AI-powered healthcare platform where security, privacy, and data protection are critical to the product.

We are looking for a Senior .NET Engineer with a strong focus on Application Security to take ownership of security improvements across the platform. You’ll work closely with the engineering team to strengthen secure application architecture and establish long-term security practices throughout the development lifecycle.

This is a hands-on engineering role focused on implementing security improvements—not just identifying issues.

Responsibilities

  • Own and drive the application security remediation roadmap.
  • Design and implement secure authorization architecture, including deny-by-default policies, authorization handlers, and resource-based authorization.
  • Improve security monitoring through authorization logging, proactive alerting, and security event visibility.
  • Strengthen secret management, key rotation, and encryption for sensitive application data.
  • Introduce static analysis, dependency scanning, and security gates into the CI/CD pipeline.
  • Improve Azure security posture, including Azure AD B2C, Key Vault, and application security configuration.
  • Coordinate external penetration testing and drive remediation of identified findings.
  • Collaborate with engineering teams on threat modeling, security reviews, and secure feature development.

Requirements

  • 4+ years of commercial software engineering experience with C# and ASP.NET Core.
  • Strong experience with ASP.NET Core authorization, including policies, authorization handlers, resource-based authorization, and deny-by-default architecture.
  • Experience identifying and remediating authorization and multi-tenant data isolation issues in large existing codebases.
  • Experience with secrets management, key rotation, encryption at rest, and secure data migration.
  • Experience introducing security controls into CI/CD pipelines, including static analysis, dependency scanning, and vulnerability triage.
  • Strong understanding of application security, with the ability to prioritize vulnerabilities based on exploitability and business impact.
  • Experience with Azure security services, including Azure AD B2C and Key Vault.
  • Hands-on approach to implementing security improvements, not just identifying vulnerabilities.
  • Upper-Intermediate level of English.

Nice to Have

  • Experience leading application security remediation after external security audits.
  • Experience with penetration testing or offensive security.
  • Experience securing Angular or other SPA applications.
  • Familiarity with SOC 2, HIPAA, or similar compliance frameworks.
  • Experience answering security questionnaires from partners or customers.
  • Experience with regulated healthcare data standards such as EPCIS or DSCSA.

What will you get with Exoft?

  • Probation period – 3 (three) months
  • Paid vacation – 18 days + 1 additional day for each year with us
  • Paid sick leave (14 days per year)
  • Wellness program (sports, healthcare)
  • 50% compensation for educational activities
  • Teambuildings and corporate events