Windows Application Developer

Marvel Infotech

Not Interested
Bookmark
Report This Job

profile Job Location:

Atlanta, GA - USA

profile Monthly Salary: Not Disclosed
Posted on: 7 hours ago
Vacancies: 1 Vacancy

Job Summary

Job Title: Application Security Developer (Windows Desktop/VB6/.NET)

Location: Atlanta GA (Onsite)

Experience: 9 Years in Windows Application Development & Security

About the role:

We are seeking an experienced Application Security Developer to lead the remediation of security vulnerabilities in legacy windows application.

The primary focus is on resolving High and Critical severity findings - specifically Command Injection and SQL Injection - across a mixed-language Windows desktop application codebase.

The ideal candidate brings deep expertise in legacy VB6 development (C# and/or ) secure coding practices and hands-on experience interpreting and fixing Veracode findings.

This is a security-first development role requiring both strong technical skills and a methodical approach to vulnerability triage remediation and validation.

KEY RESPONSIBILITIES:

Interpret Veracode SAST reports - understand CWE classifications flaw categories and severity scoring.

Triage High and Critical findings by exploitability business impact and remediation complexity.

Map each Veracode finding to the relevant source code module - VB6 C# SQL Python or Fortran.

Prioritize remediation backlog and communicate status to stakeholders and auditors.

Identify and fix OS command injection vulnerabilities across VB6 components.

Identify and fix SQL injection vulnerabilities in and any dynamic SQL construction patterns.

Work within the VB6 codebase - Windows API calls ActiveX components and VB6-specific security pitfalls.

Rebuild applications after applying patches - manage dependencies resolve build errors and validate successful compilation.

Perform unit-level and integration-level testing for each patched module.

Execute Veracode rescans to confirm vulnerability resolution and track flaw closure rate.

Conduct regression testing to ensure no functional degradation performance impact or breaking changes.

Maintain documentation: root cause analysis code changes testing approach and residual risk per finding.

REQUIRED SKILLS & EXPERIENCE:

Strong hands-on experience with Visual Basic 6 (VB6) - including ADO Windows API ActiveX and VB6 IDE.

Proficiency in C# and/or Framework - Windows Forms development and data access.

Deep understanding of SQL injection (remediation: parameterized queries stored procedures input validation.

Proven experience fixing command injection: input sanitization allowlisting safe execution patterns.

Hands-on experience with Veracode SAST - interpreting findings understanding CWE classifications and driving flaw closure.

Knowledge of OWASP Top 10 and secure coding standards applicable to Windows desktop applications.

Experience with CVSS scoring vulnerability triage and remediation prioritization.

Ability to write and execute security-focused test cases to validate fixes.

Proficiency with Git or SVN for source code version control and patch management.

Experience with code review processes pull requests and collaborative development workflows.

Familiarity with issue tracking systems such as JIRA Azure DevOps or GitHub Issues.

PREFERRED QUALIFICATIONS:

Bachelors or Masters degree in Computer Science Software Engineering Cybersecurity or a related field.

5 years of professional experience in Windows desktop application development (VB6 / .NET).

Experience with additional languages in scope: Python Fortran code review.

Job Title: Application Security Developer (Windows Desktop/VB6/.NET) Location: Atlanta GA (Onsite) Experience: 9 Years in Windows Application Development & Security About the role: We are seeking an experienced Application Security Developer to lead the remediation of security vulnerabilities in...
View more view more

Key Skills

  • APIs
  • MVC
  • SQL
  • Spring
  • .NET
  • ASP.NET
  • Microsoft SQL Server
  • C#
  • Angular
  • Application Development
  • JavaScript
  • Java