Punch Agency logo

Senior ASP.NET Developer, Security

Punch Agency

On-site
San Francisco, CA
Full-time
Senior
6+ yrs
Salary not listedPosted 3mo ago

Real job — pulled straight from Punch Agency’s careers page · Verified May 24, 2026 · No reposts.

Job description

Punch Agency is hiring a Senior ASP.NET Developer, Security — a full-time, based in San Francisco, CA role. Apply directly on Punch Agency's careers page below.

Senior ASP.NET Developer (Security Expert)

Location: San Francisco, CA, us

Company Description

Punch is a full service digital agency based out of New York, Silicon Valley, LA, Boston, Stockholm and Phuket, Thailand. Here at Punch, we take pride in tackling our clients’ most challenging tasks. Founded by a group of former Google Engineers and now with over 75 staff, Punch is now leading the way in creating new cutting-edge technology.

We're looking for innovative thinkers with a hunger to expand their knowledge!
We are building a more technical world.Go ahead and check out some of our work here: www.punch-agency.com


Job Description

Responsibilities:

• Responsible for implementing a product security framework supporting existing and future software. (Will implement security requirements and secure coding standards, e.g., NIST SP 800-53, ISO/IEC 27001, OWASP, SEI CERT, and MS Secure Coding Standards.)

• Evaluates product designs and provide solutions to remediate security vulnerabilities through product security risk assessments, vulnerability scans, and static code analysis.

• In addition to security solutions for new product development, the role requires remediating vulnerabilities with existing products which requires detailed attention to implementation and product risk.

• Leads product security risk assessments, hazard analysis, and provide vulnerability remediation guidance and mentoring to product development software engineers

• Implements software security solutions and architect/design products in accordance with industry accepted standards for security including: encryption, recovery, authentication, audit logging, hardening measures, patch management, vulnerability monitoring, and anti-virus/anti-malware

• Develops and administers software engineering procedures and training for vulnerability scans and static code analysis (C#.NET, ASP, JavaScript, MVC, Angular, Bootstrap, HTML, SQL Server, Entity Framework, CSS)

• Assists product development teams in creating Incident and Vulnerability Management Plans and Product Security White Papers.

Qualifications

Qualification (Required)

• 6+ years of software development using C#.NET, ASP (working on large multi-tier applications)

• Knowledge of secure coding practices and development specifically related to implementation of security requirements and secure coding standards (e.g., NIST SP 800-53, ISO/IEC 27001, OWASP, SEI CERT, and MS Secure Coding Standards)

•Able to evaluate product designs and provide solutions to remediate security vulnerabilities through product security risk assessments, vulnerability scans, and static code analysis Knowledge of Windows networking fundamentals (IP protocol, switch, and router basics)

• Strong knowledge of cyber/network security from training/education or experience

Qualifications (Preferred)

• 6+ years of C# Development

• 6+ years of cyber/network security experience

• Experience with SAST static code analysis tools such as HP Fortify, SonarQube, Veracode, Coverity, LLVM clang-analyzer, etc.

• SQL and SQL Server experience

• BS degree or higher in Computer Science, Computer Engineering, Electrical Engineering, or other related engineering field

• Experience with TCP/IP, encryption, and socket developmento ISC2: CISSP, CSSLP, CCFP, HCISPPo Offensive Security: OSCP, OSCE, OSEEo EC Council: GPEN, CEH, CHFI, ECSA, LPT, ESCP.NET, ECSP-JAVA, ECSSo SANS / GIAC: GSEC, GCIA, GWEB, GSSP-JAVA, GSSP-NET, GNFA, GREM, GXPN, GSEo ISACA: CSXF, CSXP, CRISCo Others: Security+, CCNA – Security

Additional Information

We are a team of former Google Engineers and Designers based in Silicon Valley, New York and Phuket, Thailand.

All of our core engineers are paid in the $150,000 range or greater and we also provide our engineers the opportunity to work, all expenses paid, from our Phuket, Thailand office one month a year as a creative outlet to work and enjoy life to the fullest.

In this role you will work with some of the most exciting projects in the industry today with a team of fast moving engineers and designers who have a passion for building disruptive products. 


Get Asp.net Developer jobs like this

New roles from thousands of companies land hourly, straight from their careers pages. Get the freshest matches by email so you never miss one.

Email me new jobs
Bosch logo

Senior Full Stack Developer

Budapest, hu
✓ From careers page· 2h ago
Contour Software logo

Trainee Software Developer

Karachi, PK
✓ From careers page· 2h ago
Softwaremind logo

AI-Driven Software Engineer Intern

Remote · Poland-eligible
✓ From careers page· 4h ago
Sequoia Connect logo

C# Full Stack Engineer

Remote · Mexico-eligible
✓ From careers page· 7h ago

Frequently asked questions

What skills are required for Senior ASP.NET Developer, Security at Punch Agency?

The required skills for Senior ASP.NET Developer, Security at Punch Agency include: ASP.NET, C#, JavaScript, HTML, SQL Server, CSS, SQL, ASP.

What is the seniority level for Senior ASP.NET Developer, Security at Punch Agency?

Senior ASP.NET Developer, Security at Punch Agency is a Senior level position.

How do I apply for Senior ASP.NET Developer, Security at Punch Agency?

You can view the full description and apply for Senior ASP.NET Developer, Security at Punch Agency on EchoJobs: https://echojobs.io/job/punch-agency-senior-asp-net-developer-security-expert-nr8oy.