Job Overview
We are building an AI-powered healthcare platform where security, privacy, and data protection are important parts of the product.
We are looking for a Backend .NET Developer to join the engineering team and work on backend development with a strong focus on application security. You’ll work with an existing .NET codebase, implement security improvements, strengthen application architecture, and contribute to secure development practices across the product. This is a hands-on engineering role where you’ll implement solutions directly in the codebase, not just identify security issues.
Responsibilities
- Develop and maintain backend functionality using C# and .NET Core.
- Design and implement secure authorization architecture, including authorization policies, handlers, and resource-based authorization.
- Implement application security improvements across the existing codebase.
- Strengthen secrets management, encryption, and protection of sensitive application data.
- Improve security monitoring, logging, and proactive alerting.
- Introduce static analysis, dependency scanning, and security controls into the CI/CD pipeline.
- Improve application security across Azure AD B2C, Key Vault, and related services.
- Collaborate with the engineering team on threat modeling, security reviews, and secure feature development.
Requirements
- 3.5 + years of commercial experience with C# and .NET Core.
- Strong knowledge of .NET Core, backend architecture, and authorization.
- Experience working with authorization policies, handlers, and resource-based authorization.
- Experience with Azure services, including Azure AD B2C and Key Vault.
- Understanding of application security principles, secrets management, encryption, and secure coding practices.
- Experience working with CI/CD pipelines and implementing security or quality controls.
- Experience working with large existing codebases.
- Upper-Intermediate level of English.
Nice to Have
- Experience identifying and fixing authorization or multi-tenant data isolation issues.
- Experience with static analysis, dependency scanning, or vulnerability management.
- Experience with key rotation and encryption at rest.
- Experience with penetration testing or security audit remediation.
- Experience securing Angular or other SPA applications.
- Familiarity with SOC 2, HIPAA, or similar compliance frameworks.
What will you get with Exoft?
- Probation period – 3 (three) months
- Paid vacation – 18 days + 1 additional day for each year with us
- Paid sick leave (14 days per year)
- Wellness program (sports, healthcare)
- 50% compensation for educational activities
- Teambuildings and corporate events