Staff Software Engineer, Application Modernization

HCVTFort Worth, TexasOn-siteFull-timeStaff, 8–12 yearsListed 3 hours ago

Apply now

About this role

About the Role
We are building a new Azure cloud platform to support a multi-year modernization program. This role will lead application engineering on the program, architecting and coding new solutions while modernizing legacy applications onto the platform.
You will set the technical direction, establish reusable patterns, and raise the engineering bar as the team grows. Our largest application footprint is C#/.NET on Azure, but the role requires sound judgment across modern cloud languages and frameworks.
You will partner with the Azure Cloud Engineer and the firm's IT, security, and network teams. The platform team owns the landing zone, guardrails, and infrastructure; you will build and modernize applications on that paved path and turn shared standards into working code, patterns, and documentation. 
Tools and Stack You'll Work In
Various Azure services including Azure App Service and Container Apps, Key Vault, Service Bus, Azure Monitor/Application Insights, managed identity, Azure SQL, C# .NET Core, plus other modern cloud languages as workloads require.
The existing environment includes older .NET Framework, WCF, and SQL workloads that will be modernized to cloud-native services. Infrastructure is provisioned by the platform team in Terraform; this role consumes, rather than authors, that infrastructure.

As the Staff Software Engineer, you will be responsible for, but not limited to, the following:

- Own the target-state architecture for the new platform: a single front door replacing today's separate client-facing and internal portals, balancing scalability, security, reliability, and supportability while setting the patterns others follow.

- Own the canonical work model (client, engagement, project, task, workflow, status) and a composable module architecture in which some modules are built end to end and others orchestrate third-party processing, with every module plugging into one shell that owns identity, tenant context, navigation, and telemetry.

- Design and enforce multi-tenant isolation for external client users, authorizing each request by person, client tenant, engagement permissions, and action, with isolation holding across documents, search, exports, background jobs, and third-party integrations.

- Establish reusable API and integration patterns and build the integration layer to third-party platforms through versioned contracts and anti-corruption adapters, mapping platform identity to the correct downstream account so that clients never hold vendor credentials or see a vendor's interface.

- Keep the platform correct and resilient across systems the firm does not own: idempotent write-back, reconciliation and drift detection, circuit breakers, cached reads, and graceful degradation so that a single vendor outage does not take the front door down.

- Assess and incrementally modernize on-premises and monolithic applications, including older .NET Framework, WCF, and SQL workloads, without disrupting business operations.

- Build cloud-native applications on Azure PaaS, including the application and business-logic layer of a new data and analytics platform, using managed identity, Key Vault, Service Bus, managed databases, App Service, and Container Apps.

- Select appropriate languages and frameworks for each workload and guide team adoption.

- Own application delivery within the platform team's paved path: ship changes through CI/CD, maintain meaningful quality and security gates, and partner with the Staff Azure Cloud Engineer to shape the paved path from the application side.

- Lead application data design and legacy data migration, with strong controls for data quality, auditability, reconciliation, and safe deployment, which matter in a tax and accounting data context.

- Lead application security design, including authentication and authorization, client identity, input validation, encryption, and secrets management through Key Vault and managed identity, ensuring changes pass automated security and policy gates and build for relevant SOC 2 controls from the outset.

- Set engineering standards for coding, testing, quality gates, code review, observability, and incident response, and provide hands-on technical leadership through design decisions, code reviews, mentoring, and architecture decision records as the team grows.

We expect that our Staff Software Engineer will have the following qualifications:

- 10+ years building and operating production applications and services, including architecture ownership and cross-functional delivery leadership, designing and implementing scalable, secure, reliable, and supportable systems.

- Demonstrated experience architecting multi-tenant applications serving both internal staff and external customers, with provable data isolation between customers, customer identity such as Entra External ID, Auth0, or Okta alongside workforce identity, fine-grained authorization, and row-level security.

- Experience building an experience or orchestration layer over third-party systems of record, including API facades, backend-for-frontend, anti-corruption layers, canonical domain models, versioned contracts, event-driven synchronization, idempotent write-back, and resilience against dependencies outside your control.

- Deep expertise in at least one modern cloud language, with C#/.NET as our largest footprint, and production fluency in others such as Java, Go, Python, or Node.js/TypeScript.

- Experience incrementally modernizing monolithic, on-premises, or legacy applications to cloud-native patterns without a big-bang rewrite, and consolidating or replacing existing applications with a unified platform.

- Hands-on Azure PaaS application development using services such as App Service or Container Apps, managed identity, Key Vault, and Service Bus or equivalent messaging.

- Full-stack capability, including a modern component-based TypeScript web UI, a shared design system, and a plugin or micro-frontend model that lets multiple modules deliver one consistent experience.

- Strong relational data modeling and migration experience, with attention to data quality, auditability, and reconciliation.

- Leadership in secure application development, including authentication, authorization, input validation, encryption, secrets management, OWASP practices, and working knowledge of SOC 2 controls.

- Experience delivering through CI/CD using GitHub Actions, GitHub Enterprise, or equivalent tools, including pull requests, automated testing, and quality and security gates.

- Demonstrated technical leadership without formal authority, and comfort serving as the first and lead application engineer in a program spanning both greenfield development and legacy modernization.

Preferred Qualifications

- Experience with plugin-based platform architectures, where capabilities extend the platform through defined interfaces.

- Familiarity with policy engines for fine-grained authorization where enforcement belongs in the services themselves.

- Experience with data-dense client-facing interfaces at scale, including grids, grouping, virtualized rendering, and export.

- Experience integrating professional-services, tax, or accounting platforms, document management systems, and practice-management systems.

- Sound build-versus-buy judgment, including open-source license diligence.

- Hands-on experience with incremental modernization patterns such as strangler fig, anti-corruption layers, and event-driven decomposition.

- Experience operating through an audit cycle in a compliance-driven environment such as SOC 2 or HIPAA.

- Experience in tax, accounting, financial services, or professional services.

- Microsoft AZ-204 and/or AZ-305 certification, or relevant language, framework, or database certifications.

You Matter - HCVT provides a variety of benefits and perks that help sustain a healthy and thriving work environment.

- Visit the Benefits (https://www.hcvt.com/careers-move-forward-your-way) section to learn more.

Connect with us: 
LinkedIn, Instagram, Facebook, HCVT Website
 
#LI-GC1
#LI-Hybrid

The ordinance requires employers to state, in all job solicitations, postings and advertisements, that the employer will consider applicants in a manner consistent with the requirements of the Fair Chance Initiative.