We're looking for mid-level full stack engineer to join a focused application security initiative.
This is hands-on engineering across the full stack. In a given week you might upgrade a .NET authentication library and chase down the breaking changes, remediate an XSS vulnerability in an Angular component, parameterize a SQL query to close an injection risk, and harden a Dockerfile to stop running as root.
Remediate security findings across the stack — dependency upgrades (NuGet, npm), code-level fixes (authorization, XSS, path traversal, SQL injection, weak cryptography), credential rotation, and container/Kubernetes hardening
Write tests for every fix — unit tests proving the vulnerability is closed, plus functional verification that the feature still works
Own upgrades end to end — when a major version bump breaks the build or changes behavior, you diagnose it and see it through
Document what you learn — because findings repeat, your written analysis of one upgrade saves your teammates from repeating the work
Collaborate across teams — many of these repositories are owned by other teams; you'll need their context and their review
Coordinate credential rotations — some fixes require finding every consumer of a secret and sequencing a safe rollout with DevOps
Raise judgment calls — when a suggested fix is wrong for our architecture, or a finding is a false positive, say so with reasoning
Help make it stick — set up automation so routine dependency updates never pile into a backlog again
Backend: C# / .NET 10 · ASP.NET Core Web API · REST
Frontend: TypeScript · Angular 20 · Node.js · webpack
Data: Snowflake · Microsoft SQL Server (T-SQL)
Infrastructure: Docker · Azure · AWS · CI/CD pipelines
Testing: xUnit · Moq · coverlet · Karma / Jasmine
Security tooling: Aikido Security · ESLint
We also have smaller Java and Python services in the mix. Exposure is a bonus, not a requirement.
Required
3–5 years of professional software engineering experience
Solid C# / .NET — comfortable in ASP.NET Core web applications
Solid TypeScript and a modern frontend framework — Angular preferred; strong React or Vue experience transfers well
Working SQL knowledge — writing queries, understanding parameterization, using an ORM or data access layer
You write tests as a matter of habit — unit tests, and ideally some integration or end-to-end experience
Git fluency — branching, rebasing, clean commits, useful pull requests
Comfort reading unfamiliar code — much of this work is in codebases you didn't write
Clear written and spoken English — you'll collaborate daily with engineers, Security, and QA
Genuine interest in security — you don't need a security background, but you should want to build one
Nice to have
Any prior security remediation, secure code review, or vulnerability triage work
Docker familiarity, especially security configuration
Experience with authentication and authorization — OAuth 2.0, OIDC, JWT
Dependency management experience: lockfiles, transitive dependencies, resolving upgrade conflicts
Exposure to Java, Python
Effective use of AI coding tools — Claude Code, Codex, Cursor, Copilot, or similar. We use them and we're glad when candidates do too. What we're interested in is judgment: using AI to move quickly through repetitive work like dependency bumps and test scaffolding, while reviewing every suggestion critically — especially on security-sensitive code, where a plausible-looking fix that doesn't actually close the vulnerability is worse than no fix at all.
You don't need: a security certification · prior Aikido experience · every technology listed above · a public-sector background.
We want to be direct about this, because it shapes the daily work.
You'll be changing authentication logic, database queries, file handling, and dependency versions in production systems. A fix we can't verify isn't a fix — it's an untested change to security-critical code. So every fix ships with tests.
If you've ever refused to ship a fix you couldn't prove worked, you'll fit in well here.