Nationwide IT Services
Posted 2mo ago

Web Developer Security Engineer

Nationwide IT Services
Washington, District of Columbia, United States
HybridFull Time
Responsibilities
  • reviewing applications
  • conducting assessments
  • implementing controls
Requirements
  • 3+ years in application security/SSDLC
  • Strong OWASP knowledge
  • Vulnerability lifecycle management
  • DevSecOps/CI-CD integration
  • WAF and FIM experience
  • Tier II security operations
  • Relevant application/offensive/foundational security certification
Technical tools mentioned
C#ASP.NET MVCWCFHTML5CSS3JavaScriptReactTypeScriptREST APIsSQLPythonNode.jsJavaGitHub CopilotWAFFile Integrity Monitoring (FIM)SIEMIDS/IPSNDREDRAWSDockerKubernetes

Job description

Position Title: Web Developer Security Engineer
Clearance Requirement: Public Trust (Tier 2)
Location: Remote/Hybrid (as approved by customer)

Position Overview: Nationwide IT Services (NIS) is seeking a Web Developer Security Engineer to support application security initiatives across web applications, APIs, and the software development lifecycle (SDLC). The selected candidate will be responsible for secure application design, vulnerability management, DevSecOps integration, security monitoring, WAF administration, File Integrity Monitoring (FIM), and Tier II security operations support.

Required Experience:
  • Minimum 3 years of experience in Application Security and Secure Software Development Lifecycle (SSDLC).
  • Strong knowledge of web application security principles and OWASP Top 10 vulnerabilities.
  • Experience managing the full vulnerability lifecycle, including threat modeling, security assessments, remediation, and validation.
  • Experience with secure application design, architecture reviews, data protection, and secure communications.
  • Hands-on experience with Web Application Firewall (WAF) deployment, configuration, and tuning.
  • Experience with File Integrity Monitoring (FIM), log analysis, Indicators of Compromise (IOC) detection, and threat intelligence automation.
  • Experience supporting Tier II Security Operations.
  • Experience implementing DevSecOps practices and automated security controls within CI/CD pipelines.
Technical Skills:
  • .NET Technologies: C#, ASP.NET MVC, WCF
  • Front-End: HTML5, CSS3, JavaScript, React, TypeScript
  • APIs & Databases: REST APIs, SQL
  • Programming/Scripting: Python, Node.js, Java
  • AI-Assisted Development Tools (e.g., GitHub Copilot)
  • Security Tools: SIEM, IDS/IPS, NDR, EDR
  • Cloud & Container Security: AWS, Docker, Kubernetes
Compliance & Governance:
  • Experience supporting environments governed by NIST SP 800-53, FISMA, and FedRAMP.
  • Experience participating in audits, security assessments, and authorization activities.
Education:
  • Bachelor’s degree or higher in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.
Required Certifications:
Application Security (One Required):
  • CSSLP, OR
  • GIAC Web Application Penetration Tester (GWEB), OR
  • CASE
Offensive Security (One Required):
  • OSWE, OR
  • OSCP
Foundational Security (One Required):
  • Security+, OR
  • GSEC
Preferred Qualifications:
  • Experience securing federal government applications and systems.
  • Experience integrating security controls into modern CI/CD pipelines.
  • Strong understanding of cloud-native and containerized application security.
Key Responsibilities:
  • Perform application security reviews and threat modeling.
  • Conduct vulnerability assessments and oversee remediation efforts.
  • Implement and maintain security controls within CI/CD pipelines.
  • Configure and tune WAF and File Integrity Monitoring solutions.
  • Analyze logs, investigate security events, and support incident response activities.
  • Collaborate with development teams to ensure secure coding practices.
  • Support compliance, audit, and security authorization requirements.

Working at NIS means being part of a company grounded in purpose, resilience,
and a genuine commitment to people. Since its founding in 2006, NIS has focused not only
on delivering exceptional services to our government customers, but also supporting our
nation, taxpayers, and citizens—while consistently prioritizing the well-being and growth of
its employees. Today, NIS continues to evolve by embracing remote work, enhancing
wellness initiatives, and investing in modern technology, all while staying true to its
mission.

 

About Nationwide IT Services

Service-disabled veteran-owned IT and management consulting firm serving federal agencies with technology, cybersecurity, and mission support.

Similar jobs

Web Developer Security Engineer roles near Washington, District of Columbia
3w
Save
Mark Applied
Hide
Web Developer Security Engineer (DC, Washington)
Washington, District of Columbia, United States
$145k-$175k/yr OnsiteFull Time
RiVidium
RiVidium: RiVidium is a privately held federal contractor providing cybersecurity, IT, human-capital, and intelligence services to government agencies.
5+ YOERequires 5+ years of secure software or application security engineering, 3+ years of web application security or SSDLC, a bachelor's degree or equivalent, and active Top Secret clearance.
OWASP Top 10, WAF, FIM, CI/CD, DevSecOps
2mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Spry Methods, Inc.
Spry Methods, Inc.: Minority-owned federal contractor providing cybersecurity, national-security, and IT modernization services to government and commercial clients.
3+ YOE3+ years in web application security or secure software development; hands-on experience with .NET, HTML5, CSS3, JavaScript, REST APIs, and SQL; DevSecOps automation, vulnerability remediation, OWASP Top 10 knowledge, and relevant security certifications.
.NET, HTML5, CSS3, JavaScript, REST APIs, SQL, OWASP Top 10, WAFs
2mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Ardent Management Consulting
Ardent Management Consulting: Private technology and management consulting firm providing data science, digital transformation, and geospatial intelligence to government agencies.
5+ YOEBachelor’s in CS/Cybersecurity/IS/Engineering; 5+ years in App/Web security; OWASP knowledge; WAFs; DevSecOps; strong communication.
.NET, C#, HTML5, CSS3, JavaScript, REST APIs, SQL, WAFs, FIM, SIEM, IDS/IPS, EDR, NDR, DevSecOps
2mo
Save
Mark Applied
Hide
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions
Essnova Solutions: Minority-owned Alabama small-business government contractor delivering IT, professional, geospatial, healthcare, and environmental services to public and commercial clients.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP