Must to have
10+ years, with genuine dual-track experience - you have both owned an architecture & run the
delivery around it, not held one & observed the other.
• Has personally carried a solution design through a bank&'s or insurer&'s formal architecture & security
approval boards, & can describe what those reviewers actually push on.
• Able to read & reason about an existing production application&'s code & session model. You are not
delegating the current-state assessment.
• Fixed-price delivery experience with a working change-control instinct. This is the single most commercially
important trait in the role.
• Experience inserting authentication or authorisation controls into live customer-facing transactional
systems.
• Client-facing credibility at senior level. You will be the supplier's face in every forum.
• Written communication strong enough that your design document survives formal review without a rewrite.
Nice to have
• Insurance, payments or other regulated financial-services delivery.
• Familiarity with NIST SP 800-63B & how an email-delivered factor positions against it.
• Experience operating alongside an incumbent managed-service provider on a shared codebase.
Languages
C# 10+, .NET 8 (or 4.8)
ASP.NET Core MVC / Razor Pages
ASP.NET Core Identity, Data Protection API, custom middleware pipeline
Entity Framework Core, Dapper, ADO.NET
IDistributedCache over Redis or SQL Server
ASP.NET Core Rate Limiting middleware (.NET 7+)
Razor, H&lebars.NET
Serilog or NLog with destructuring policies & redaction
IIS / Kestrel
xUnit or NUnit, RestSharp, SpecFlow
SQL (T-SQL, PL/SQL or DB2)
Git; branching & PR workflow on a shared repository under enterprise change control
Azure DevOps or Jira; RAID, decision & dependency tracking
Architecture practice
C4 model or UML - context, container, component & sequence diagrams
Data-flow diagrams
Architecture decision records
Visio, Lucidchart, draw.io or Miro
Security architecture
Threat modelling - STRIDE, abuse-case analysis
NIST SP 800-63B - AAL levels & out-of-b& authenticator position
OWASP ASVS as an architectural control set