This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

Applied Intellect
Posted 3w ago

Web Developer Security Engineer

Applied Intellect
Chantilly or United States
$120k-$135k/yrOnsiteFull Time
Responsibilities
  • identifying vulnerabilities
  • implementing remediation
  • monitoring logs
Requirements
  • 3+ years in web application or application security
  • Proficiency with .NET/C#
  • Modern web stacks
  • WAF/FIM
  • Log analysis
  • DevSecOps automation, and current AppSec/offensive/foundational certifications
  • Bachelor\u0002s degree required
Technical tools mentioned
.NETC#MVCWCFHTML5CSS3JavaScriptREST APIsSQLGitHub CopilotOpenAI API/CodexPythonNode.jsJavaReact.jsTypeScriptOWASP Top 10WAFFIMWiresharkSIEMIDS/IPSNDREDRDockerKubernetesAWS

Job description

OVERVIEW


Clearance: Public Trust Tier 2 or higher preferred

Applied Intellect is seeking a Web Developer Security Engineer to support federal contracts, by playing a pivotal role in protecting mission-critical web applications, APIs and sensitive data. The objectives are to embed robust security principles throughout the software development lifecycle (SDLC) to build security as a proactive, foundational pillar.

Key Responsibilities

The Key Responsibilities include, but is not limited to, the following activities:

Web Application Security

  • Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations
  • Drive the end-to-end vulnerability lifecycle - integrating proactive threat modeling and advanced security assessments, ensuring remediation integrity through rigorous technical validation
  • Support integration of security controls into application architectures, APIs, and supporting services, advising on secure design patterns; data protection mechanisms; and secure communication protocols to ensure applications are secure by design and resilient to evolving threats

Monitoring, Logging, Incident Response and Automation

  • Obtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise
  • Implement automation scripts for threat intelligence integration to optimize alert accuracy and actively support the end-to-end response to web application security events.
  • Maintain documentation of findings, remediation steps, and security controls

Compliance & Governance

  • Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks, including NIST SP 800‑53, FISMA, and FedRAMP (as applicable)
  • Participate in audits, risk assessments, and security authorization processes

Required Skills/Knowledge/Expertise

  • Extensive hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation. 
  • Proficiency in logs analysis, file integrity monitoring (FIM), and managing web application firewalls (WAF) to defend against emerging threats. 
  • Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec) or secure software development life cycle (SSDLC) 
  • Proven developing with modern web technologies and frameworks not limited to .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL 
  • Ability to leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript) to automate security monitoring and compliance audits 
  • Strong understanding of Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, and proactive mitigation of common web vulnerabilities. 
  • Experience deploying, tuning, and maintaining Web Application Firewalls (WAFs) solutions tailored to custom-developed applications and traffic patterns. 
  • Strong track record in configuring and managing File Integrity Monitoring (FIM) solutions for web content directories, to detect and alert on unauthorized change. 
  • Familiar with security testing tools such as Wireshark, SIEM, IDS/IPS, NDR, or EDR 
  • Evaluates, recommends, and implements security controls for mobile device solutions and mobile-web interface. 
  • Ability to perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and their dependencies 
  • Proven ability to implement DevSecOps principles, seamlessly integrating security controls throughout the CI/CD pipeline 
  • Experience developing security metrics, managing compliance reporting, and auditing systems against established security baselines 
  • Collaborate effectively across multidisciplinary teams, and work independently as well as in a team 
  • Experience providing Tier II support for security operations and recommending continue security enhancements for existing infrastructure. 

Desired Skills

  • In-depth experience at Federal cybersecurity frameworks (NIST SP 800‑53, FISMA, FedRAMP) authorization process
  • Proven background in threat modeling, risk assessment, and designing resilient security architecture
  • Advanced experience implementing secure DevOps/DevSecOps practices, specifically focus on CI/CD pipeline and automating security gates
  • Knowledge of cloud security AWS and container security (Docker, Kubernetes)

Required Education & Credentials 

  • Bachelor’s degree (or higher) in computer science, Cybersecurity, Information Systems, Engineering, or a related field. 

The candidate also must have at least one of the following current credentials/certification for each category: 

  • Specialized AppSec: 
    • Certified Secure Software Lifecyle Professional (CSSLP) 
    • GIAC Certified Web Application Defender (GWEB) 
    • EC-Council Certified Application Security Engineer (CASE) 
  • Offensive Security: 
    • OffSec Web Expert (OSWE) 
    • Offensive Security Certified Professional (OSCP) 
  • Foundational Security: 
    • Security+ 
    • GSEC 

These (or their equivalent prior certifications) should have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.

 PHYSICAL DEMANDS 

  • Use of manual dexterity, tactile, visual, and audio acuity;
  • Use of repetitive motion, prolonged periods of sitting and standing, and sustained visual and mental applications and demands;
  • Occasional lifting (up to 25 pounds), bending, pulling, and carrying; and
  • Quantitative/mathematical ability (addition, subtraction, multiplication, division, standard measurements).


Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

EQUAL EMPLOYMENT OPPORTUNITY

Applied Intellect is an equal opportunity employer. 

The above-listed duties and responsibilities are essential job functions. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. All job duties indicated are not to be an exhaustive statement, and other job-related duties may be assigned as required by the supervisor(s).


About Applied Intellect

Provides professional, technical, and human services to government agencies.

Similar jobs

Web Developer Security Engineer roles near Chantilly, Virginia
1w
Save
Mark Applied
Hide
Web Developer Security Engineer (DC, Washington)
Washington, District of Columbia, United States
$145k-$175k/yr OnsiteFull Time
RiVidium
RiVidium: Provides cybersecurity software and IT services to federal agencies.
5+ YOERequires 5+ years of secure software or application security engineering, 3+ years of web application security or SSDLC, a bachelor's degree or equivalent, and active Top Secret clearance.
OWASP Top 10, WAF, FIM, CI/CD, DevSecOps
1mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
CMT Services
CMT Services: Provides management and technology consulting to government entities.
3+ YOE3+ years in web application security/AppSec/SSDLC, hands-on secure development, DevSecOps automation, WAF and FIM management, log/SIEM analysis, OWASP Top 10 mitigation, scripting for automation, and compliance with NIST/FedRAMP.
GitHub Copilot, OpenAI API/Codex, Python, JavaScript/Node.js, Java, React.js, TypeScript, .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, SQL, Wireshark, SIEM, IDS/IPS, NDR, EDR, WAF, File Integrity Monitoring (FIM)
1mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Nationwide IT Services
Nationwide IT Services: Provides IT and management consulting services to federal government agencies.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
C#, ASP.NET MVC, WCF, HTML5, CSS3, JavaScript, React, TypeScript, REST APIs, SQL, Python, Node.js, Java, GitHub Copilot, WAF, File Integrity Monitoring (FIM), SIEM, IDS/IPS, NDR, EDR, AWS, Docker, Kubernetes
2mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Spry Methods
Spry Methods: Providing cybersecurity and intelligence solutions for federal government agencies.
3+ YOE3+ years in web application security or secure software development; hands-on experience with .NET, HTML5, CSS3, JavaScript, REST APIs, and SQL; DevSecOps automation, vulnerability remediation, OWASP Top 10 knowledge, and relevant security certifications.
.NET, HTML5, CSS3, JavaScript, REST APIs, SQL, OWASP Top 10, WAFs
2mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Ardent
Ardent: Provides geospatial and digital transformation services to federal agencies.
5+ YOEBachelor’s in CS/Cybersecurity/IS/Engineering; 5+ years in App/Web security; OWASP knowledge; WAFs; DevSecOps; strong communication.
.NET, C#, HTML5, CSS3, JavaScript, REST APIs, SQL, WAFs, FIM, SIEM, IDS/IPS, EDR, NDR, DevSecOps
1mo
Save
Mark Applied
Hide
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
This job has expired