HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
4+ YOE4+ years troubleshooting systems and security issues, experience identifying vulnerabilities and remediation, mentoring or tech lead experience; threat modeling and service/microservices security preferred.
Marriott InternationalNASDAQ: MAR: Operates and franchises a global network of hotels and resorts.
7+ YOE4+ Mgmt7+ years IT/security experience with 4+ years security leadership, bachelor\u0002s degree or equivalent, experience with AppSec testing (SAST/DAST/IAST), SCA, release management, and GitHub/JIRA/ServiceNow/Jenkins/Harness.
MicroTech: Provider of IT integration, cloud, and managed services.
3+ YOEBachelor's degree, 3+ years in web application or application security engineering, experience with AppSec tooling, DevSecOps, WAF/FIM, vulnerability management, and federal compliance (NIST/FISMA/FedRAMP).
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years in product/security/appsec roles; experience with architecture/design reviews, threat modeling, secure-by-design principles; ability to obtain Secret clearance; Bachelor's degree required; strong communication and tracking skills.
Washington or Cleveland or California or Colorado or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or New Jersey or New York or Vermont or Virginia or Washington
$135k-$279k/yrOnsiteFull Time
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
12+ YOE12+ years progressive cybersecurity experience with leadership across SOC, incident response, detection, vulnerability management, engineering, and AppSec; enterprise security program experience; US citizenship and clearance eligibility; up to 25% travel.
NIST, RMF, Zero Trust, AWS, Microsoft Azure, GCP, SOAR, AI, ML
CMT Services: Provides management and technology consulting to government entities.
3+ YOE3+ years in web application security/AppSec/SSDLC, hands-on secure development, DevSecOps automation, WAF and FIM management, log/SIEM analysis, OWASP Top 10 mitigation, scripting for automation, and compliance with NIST/FedRAMP.
MicroTech: Provides IT, network, and cybersecurity solutions for government agencies.
3+ YOE3+ years in web application security or AppSec, bachelor's degree, experience with secure SDLC/DevSecOps, web dev tech (.NET, C#, HTML5, JavaScript), scripting (Python, Node.js), WAF/FIM, SIEM/EDR, and federal compliance knowledge.
Atlanta or Boston or Charlotte or Miami or New York or Washington
$177k-$236k/yrOnsiteFull Time
Slalom: Provides business and technology consulting and software engineering services.
2+ YOE2+ years working on AI/ML and generative AI; advanced degree or relevant technical background preferred; experience with regulated industries, AI risk management, privacy/security, and ML/Generative AI pipelines; strong communication and critical thinking.
Base-2 Solutions: Delivers engineering and technology services for national security.
6+ YOEActive TS/SCI with CI polygraph eligibility, DoD 8570 IA SAE Level II cert (CISSP family or CASP+), bachelor’s or 6+ yrs experience (or +3 yrs in lieu), RMF/DoDI/NIST/SP800-53 experience, STIG/SCAP/ACAS scanning and vulnerability analysis, Windows/Linux knowledge.
Hewlett Packard EnterpriseNYSE: HPE: Providing global edge-to-cloud infrastructure and IT solutions for businesses.
3+ YOEBachelor's in CS/Engineering/hard sciences (Master's/PhD preferred), deep AI and data-security experience, 3+ years development experience, extensive security architecture experience with US federal/state compliance frameworks.
Bellevue or Chicago or New York City or San Francisco or Washington
$161k-$248k/yrHybridFull Time
OktaNASDAQ: OKTA: Provide secure identity management and authentication for enterprises.
8+ YOE8+ years in security engineering or backend development, expertise in AI threat landscape, strong coding in Python or Go, cloud (AWS/GCP) experience, and leadership/mentorship ability.
Python, Go, LangChain, Strands, Claude Agent SDK, AWS, GCP, OWASP, MITRE ATLAS, NIST AI RMF
Ad Hoc: Builds user-centered digital services and platforms for government agencies.
5+ YOEBachelor's degree and 5+ years software engineering experience; strong React, TypeScript, JavaScript, accessibility, REST API, testing, Git, and US citizenship with DHS Public Trust eligibility.
eSimplicity: Provides digital and data services to federal government agencies.
8+ YOEBachelor’s degree in Computer Science or Engineering, or 10+ years of relevant experience; 8+ years DevOps; strong AWS, IaC (Terraform/Terragrunt), GitHub Actions; DevSecOps focus; containerization (Docker); Python or Bash; U.S. citizenship or Green Card with ability to obtain Public Trust clearance.
JRAD: Provides technical research and defense support to federal agencies.
0+ YOEBachelor's in CS or related, 0-3 years software development experience, Java/Spring preferred, proficiency with OOP, data structures, REST/microservices, databases, containerization, Agile, and security standards; able to pass DHS suitability screening.
Java, C#, C++, ASP.Net, Python, JavaScript, Spring MVC, Spring Boot, SSO, Scala, Http4s, ETL, Node.js, React, Angular, Vue.js, PostgreSQL, MySQL, MongoDB, RESTful APIs, microservices, Docker, Kubernetes, Git, Github, JIRA, SAFe, AWS, Microsoft Azure, Google Cloud Platform, Jenkins, GitLab CI/CD, GitHub Actions, JUnit, PyTest, Jest, OWASP, Section 508, NIST