Security Architect
Summary
A Security Architect / Principal Security Engineer with a .NET development background will lead application security across SaaS platforms in Wellington — building auth features, threat modelling, designing identity systems (Duende IdentityServer, SAML, OIDC, OAuth 2.0, MFA), automating security in GitHub Actions CI/CD, and mentoring teams toward ISO 27001 compliance.
Salary: $170,000 – $190,000 per year + Benefits + KS
A collaborative software group in Wellington is looking for a Security Architect / Principal Security Engineer with a development background to lead and shape application security across its SaaS platforms.
This role brings together hands-on software development and security architecture. Working closely alongside engineers, architects, and product teams, you will focus on building secure-by-design systems, creating identity frameworks, and fostering application security best practices.
Key Responsibilities
Application Security & Engineering: Help shape and execute the application security roadmap, build authentication and authorisation features, and embed security practices directly into architecture templates and shared codebases.
Architecture & Threat Modelling: Partner with development teams to conduct threat modelling, review designs, and establish clear, reusable security standards.
Identity & Edge Protections: Design and maintain modern identity systems (Duende IdentityServer, SAML, OIDC, OAuth 2.0, MFA) while putting effective edge controls in place, including WAF rules, bot mitigation, and API protection.
CI/CD Pipeline Integration: Integrate automated security tooling (SAST, DAST, SCA, secret scanning) directly into GitHub Actions and deployment workflows to identify improvements early.
Remediation & Incident Support: Work alongside teams to resolve vulnerability findings, guide security incident responses calmly, and establish clear remediation priorities.
Mentorship & Collaboration: Support and mentor team members, share technical updates with the Security Steering Group, and prepare for ISO 27001 compliance activities.
Technical Requirements
Strong .NET / C# Background: Proven experience in software development with deep .NET/C# capability to navigate technical discussions and development workflows.
7+ Years of Relevant Experience: Background spanning software engineering, security design, and technical initiative leadership.
Identity & Access Management: Practical experience working with identity standards such as SAML, OIDC, OAuth 2.0, MFA, and Duende IdentityServer.
CI/CD Security Automation: Hands-on experience securing deployment pipelines with GitHub Actions, secret scanning, and automated testing tools.
Threat Modelling & Compliance Standards: Demonstrated experience conducting threat modelling, coordinating penetration test remediations, and applying security standards such as ISO 27001 and OWASP Top 10.
Desirable Skills
Experience with TypeScript / React
Knowledge of Cloudflare, AWS, and Infrastructure as Code (Terraform)
Hands-on experience with Docker, MySQL, and securing AI/LLM features
Note: To apply for this position, you must currently hold a valid New Zealand work visa, and be a NZ Resident or Citizen. We are unable to consider applicants who do not meet these criteria.
Please do apply if you're currently based in New Zealand, happy to live and work in Wellington, and have a .NET Development background. We'll come back to you with an update on next steps within 24 hours during the working week.
About placeMe IT
placeMe IT is all about connecting the right candidate with the right job in IT. We promote diversity in the workplace and have a human-first approach, striving for meaningful connections. If you feel like you don't cover every base for this role, that's fine and natural; we encourage you to apply anyway. It's rare that somebody ticks every box!