About the Role
We are seeking a Senior Software Engineer (.NET) to join our Never-Ending Support (NES) team. This role focuses on our “NES for .NET” product line, where you will produce critical security patches for CVEs affecting end-of-life versions of .NET and other NuGet packages, as well as build the tooling and automation that makes that work scale.
Key Responsibilities
- Analyze CVEs and upstream security fixes in .NET Runtime, ASP.NET Core, SDK, and related packages, and apply them to end-of-life .NET versions
- Build, test, and reproduce end-of-life .NET versions on modern and legacy toolchains, including resurrecting build environments and pinning dependencies that no longer resolve
- Build and utilize AI-assisted automation for triage, patch analysis, backport drafting, and regression verification, to scale the product securing process.
- Build and maintain test harnesses that validate CVE patch correctness and backwards compatibility
- Provide support to customers' engineering teams on compatibility issues, and upgrade paths
Required Qualifications
- Deep expertise in C#, and the .NET ecosystem. Low-level experience with the .NET Runtime, .NET SDK and other .NET ecosystem projects
- Demonstrated ability to read and reason about unfamiliar low-level code: understanding a security patch well enough to reimplement it against a different code baseline
- Experience building and debugging complex software from source, including toolchain and build-system archaeology
- Experience building software for multiple platforms (Windows, macOS, Linux distributions including RHEL, etc.)
- Strong ownership of correctness and quality – rigorous testing, regression coverage, and an instinct for what a patch might break
- Practical experience using LLMs to automate real engineering work, with judgment about where automation helps and where it can't be trusted
- Comfortable in a small, high-autonomy team where you help shape the process, as much as follow it
- Ability to communicate with customers in early product iterations, or in tier-3 support capacities
Preferred Qualifications
- Contributions to .NET open source projects – dotnet/runtime, dotnet/aspnetcore, or widely used NuGet packages
- Strong grasp of security fundamentals – CVEs, CVSS, common vulnerability classes (deserialization, path traversal, cryptographic misuse, DoS via resource exhaustion), and how to assess exploitability
- Familiarity with container image hardening, SBOMs, artifact signing, and supply chain security
- Experience building and deploying services built on .NET in Microsoft Azure
- Experience as either a technical lead or team lead
- Experience running production services on Azure, AWS and Kubernetes
- Background in security research, vulnerability triage, or product security
Skills Required
- Deep expertise in C# and the .NET ecosystem, including low-level experience with the .NET Runtime, .NET SDK, and related projects
- Ability to analyze unfamiliar low-level code and reimplement security patches against different code baselines
- Experience building and debugging complex software from source, including toolchain and build-system archaeology
- Experience building software for Windows, macOS, and Linux distributions including RHEL
- Strong ownership of correctness and quality, including rigorous testing and regression coverage
- Practical experience using LLMs to automate engineering work
- Ability to work effectively in a small, high-autonomy team
- Ability to communicate with customers or provide tier-3 support
- Contributions to .NET open source projects or widely used NuGet packages
- Strong understanding of security fundamentals, CVEs, CVSS, vulnerability classes, and exploitability assessment
- Familiarity with container image hardening, SBOMs, artifact signing, and supply chain security
- Experience building and deploying .NET services in Microsoft Azure
- Experience as a technical lead or team lead
- Experience running production services on Azure, AWS, and Kubernetes
- Background in security research, vulnerability triage, or product security
What We Do
HeroDevs is a trusted leader providing secure, never-ending support for deprecated open-source software. Its mission is to keep critical technologies running smoothly, securely, and in compliance long after their official end-of-life. The company offers a platform for engineering and security teams to manage risks associated with unsupported open source through ongoing security patches, compatibility updates, and comprehensive compliance maintenance for various frameworks.









