Truelogic·about 4 hours ago
At Truelogic we are a leading provider of nearshore staff augmentation services headquartered in New York. For over two decades, we’ve been delivering top-tier technology solutions to companies of all sizes, from innovative startups to industry leaders, helping them achieve their digital transformation goals.
Our team of 600+ highly skilled tech professionals, based in Latin America, drives digital disruption by partnering with U.S. companies on their most impactful projects. Whether collaborating with Fortune 500 giants or scaling startups, we deliver results that make a difference.
By applying for this position, you’re taking the first step in joining a dynamic team that values your expertise and aspirations. We aim to align your skills with opportunities that foster exceptional career growth and success while contributing to transformative projects that shape the future.
A cloud-based software platform specifically designed to help public sector organizations and agencies manage the entire employee lifecycle.
The platform enables Human Resources teams to centralize and streamline processes such as recruitment, onboarding, employee development, and workforce management, while also supporting diversity initiatives and automating various HR processes.
These solutions provide a centralized platform that enables public sector organizations to manage their talent processes and employee experience more efficiently.
We're looking for mid-level full stack engineer to join a focused application security initiative.
This is hands-on engineering across the full stack. In a given week you might upgrade a .NET authentication library and chase down the breaking changes, remediate an XSS vulnerability in an Angular component, parameterize a SQL query to close an injection risk, and harden a Dockerfile to stop running as root.
Remediate security vulnerabilities across the stack: dependency upgrades (NuGet, npm), code-level fixes (authorization, XSS, path traversal, SQL injection, weak cryptography), credential rotation, and container/Kubernetes hardening.
Write tests for every fix: unit tests that prove the vulnerability has been addressed, along with functional verification to ensure the feature continues to work correctly.
Own upgrades end to end: when a major version upgrade breaks the build or changes application behavior, diagnose the issue and drive the resolution through completion.
Document what you learn: since certain findings tend to repeat, document the analysis and solution from each upgrade to prevent teammates from having to repeat the same work.
Collaborate across teams: many of these repositories are owned by other teams, so you'll need to gather context, coordinate with them, and work through their reviews.
Coordinate credential rotations: some fixes require identifying every service or application consuming a secret and coordinating a safe, sequenced rollout with DevOps.
Make sound technical judgments: when a suggested fix is not appropriate for the architecture, or when a finding is a false positive, raise the concern and provide the technical reasoning behind it.
Help prevent issues from accumulating: set up automation so routine dependency updates are handled continuously instead of piling up in the backlog.
3–5 years of professional software engineering experience.
Strong C# / .NET skills, with solid experience working with ASP.NET Core web applications.
Strong TypeScript skills and experience with a modern frontend framework. Angular is preferred; strong React or Vue experience is highly transferable.
Working knowledge of SQL, including writing queries, understanding parameterization, and using an ORM or data access layer.
Testing is part of your regular development practice: unit testing, ideally with some integration or end-to-end testing experience.
Strong Git skills, including branching, rebasing, clean commits, and useful pull requests.
Comfortable reading and understanding unfamiliar code, as much of the work will involve codebases you did not originally develop.
Clear written and spoken English, as you will collaborate daily with engineers, Security, and QA teams.
Genuine interest in security. A security background is not required, but you should be interested in building your knowledge in this area.
Tech Stack:
Backend: C# / .NET 10 · ASP.NET Core Web API · RES
Frontend: TypeScript · Angular 20 · Node.js · webpack
Data: Snowflake · Microsoft SQL Server (T-SQL)
Infrastructure: Docker · Azure · AWS · CI/CD pipelines
Testing: xUnit · Moq · coverlet · Karma / Jasmine
Security tooling: Aikido Security · ESLint
100% Remote Work: Enjoy the freedom to work from the location that helps you thrive. All it takes is a laptop and a reliable internet connection.
Highly Competitive USD Pay: Earn an excellent, market-leading compensation in USD, that goes beyond typical market offerings.
Paid Time Off: We value your well-being. Our paid time off policies ensure you have the chance to unwind and recharge when needed.
Work with Autonomy: Enjoy the freedom to manage your time as long as the work gets done. Focus on results, not the clock.
Work with Top American Companies: Grow your expertise working on innovative, high-impact projects with Industry-Leading U.S. Companies.
A Culture That Values You: We prioritize well-being and work-life balance, offering engagement activities and fostering dynamic teams to ensure you thrive both personally and professionally.
Diverse, Global Network: Connect with over 600 professionals in 25+ countries, expand your network, and collaborate with a multicultural team from Latin America.
Team Up with Skilled Professionals: Join forces with senior talent. All of our team members are seasoned experts, ensuring you're working with the best in your field.
Apply now!