Spry Methods, Inc.
Posted 2mo ago

Web Developer Security Engineer

Spry Methods, Inc.
Washington, District of Columbia, United States
HybridFull Time
Responsibilities
  • remediating vulnerabilities
  • monitoring applications
  • conducting assessments
Requirements
  • 3+ years in web application security or secure software development
  • Hands-on experience with .NET, HTML5, CSS3
  • JavaScript
  • REST APIs, and SQL
  • DevSecOps automation
  • Vulnerability remediation
  • OWASP Top 10 knowledge, and relevant security certifications
Technical tools mentioned
.NETHTML5CSS3JavaScriptREST APIsSQLOWASP Top 10WAFs

Job description

Who We’re Looking For (Position Overview):
The Web Developer Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.   


Who We’re Looking For (Position Overview):
The Web Developer Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.   


Who We’re Looking For (Position Overview):
The Web Developer Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.   


Final compensation will be based on experience, qualifications, certifications, clearance level, and contract requirements. This position is contingent upon contract award.


What Your Day-To-Day Looks Like (Position Responsibilities):
  • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs. 

  • Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions. 

  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services. 

  • Review and analyze web server and application logs to detect anomalies and indicators of compromise. 

  • Implement automation scripts for threat intelligence integration and application security monitoring. 

  • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks. 



What You Need to Succeed (Minimum Requirements):
  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work. 

  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation. 

  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL). 

  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts. 

  • Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools. 

  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies. 

  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field. 

  • Ability to meet federal screening and suitability requirements prior to start. 

  • Current security certifications maintained for a minimum of five years: 

    • Specialized AppSec:
      • Certified Secure Software Lifecyle Professional (CSSLP)
      • GIAC Certified Web Application Defender (GWEB)
      • EC-Council Certified Application Security Engineer (CASE)
      • Offensive Security:
        • OffSec Web Expert (OSWE)
        • Offensive Security Certified Professional (OSCP)
        • Foundational Security:
          • Security+
          • GSEC


Ideally, You Also Have (Preferred Qualifications):
  • In-depth experience with federal cybersecurity frameworks and authorization processes. 

  • Experience with threat modeling, resilient security architecture, cloud security, and container security. 

About Spry Methods, Inc.

Minority-owned federal contractor providing cybersecurity, national-security, and IT modernization services to government and commercial clients.

Similar jobs

Web Developer Security Engineer roles near Washington, District of Columbia
3w
Save
Mark Applied
Hide
Web Developer Security Engineer (DC, Washington)
Washington, District of Columbia, United States
$145k-$175k/yr OnsiteFull Time
RiVidium
RiVidium: RiVidium is a privately held federal contractor providing cybersecurity, IT, human-capital, and intelligence services to government agencies.
5+ YOERequires 5+ years of secure software or application security engineering, 3+ years of web application security or SSDLC, a bachelor's degree or equivalent, and active Top Secret clearance.
OWASP Top 10, WAF, FIM, CI/CD, DevSecOps
2mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Nationwide IT Services
Nationwide IT Services: Service-disabled veteran-owned IT and management consulting firm serving federal agencies with technology, cybersecurity, and mission support.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
C#, ASP.NET MVC, WCF, HTML5, CSS3, JavaScript, React, TypeScript, REST APIs, SQL, Python, Node.js, Java, GitHub Copilot, WAF, File Integrity Monitoring (FIM), SIEM, IDS/IPS, NDR, EDR, AWS, Docker, Kubernetes
2mo
Save
Mark Applied
Hide
Web Developer Security Engineer
Washington, District of Columbia, United States
HybridFull Time
Ardent Management Consulting
Ardent Management Consulting: Private technology and management consulting firm providing data science, digital transformation, and geospatial intelligence to government agencies.
5+ YOEBachelor’s in CS/Cybersecurity/IS/Engineering; 5+ years in App/Web security; OWASP knowledge; WAFs; DevSecOps; strong communication.
.NET, C#, HTML5, CSS3, JavaScript, REST APIs, SQL, WAFs, FIM, SIEM, IDS/IPS, EDR, NDR, DevSecOps
2mo
Save
Mark Applied
Hide
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions
Essnova Solutions: Minority-owned Alabama small-business government contractor delivering IT, professional, geospatial, healthcare, and environmental services to public and commercial clients.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP