HiringCafe: Building a 100× better job search engine to take on Indeed and LinkedIn.
Own the crawlers, pipelines, and infrastructure powering a real-time job search engine. Strong Node.js and Python fundamentals; bonus points for security and reverse-engineering chops.
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions: Provides professional and technical services to government entities.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
4+ YOE4+ years troubleshooting systems and security issues, experience identifying vulnerabilities and remediation, mentoring or tech lead experience; threat modeling and service/microservices security preferred.
Marriott InternationalNASDAQ: MAR: Operates and franchises a global network of hotels and resorts.
7+ YOE4+ Mgmt7+ years IT/security experience with 4+ years security leadership, bachelor\u0002s degree or equivalent, experience with AppSec testing (SAST/DAST/IAST), SCA, release management, and GitHub/JIRA/ServiceNow/Jenkins/Harness.
MicroTech: Provider of IT integration, cloud, and managed services.
3+ YOEBachelor's degree, 3+ years in web application or application security engineering, experience with AppSec tooling, DevSecOps, WAF/FIM, vulnerability management, and federal compliance (NIST/FISMA/FedRAMP).
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years in product/security/appsec roles; experience with architecture/design reviews, threat modeling, secure-by-design principles; ability to obtain Secret clearance; Bachelor's degree required; strong communication and tracking skills.
Washington or Cleveland or California or Colorado or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or New Jersey or New York or Vermont or Virginia or Washington
$135k-$279k/yrOnsiteFull Time
Accenture Federal ServicesNYSE: ACN: Provides technology and consulting services to U.S. federal agencies.
12+ YOE12+ years progressive cybersecurity experience with leadership across SOC, incident response, detection, vulnerability management, engineering, and AppSec; enterprise security program experience; US citizenship and clearance eligibility; up to 25% travel.
NIST, RMF, Zero Trust, AWS, Microsoft Azure, GCP, SOAR, AI, ML
CMT Services: Provides management and technology consulting to government entities.
3+ YOE3+ years in web application security/AppSec/SSDLC, hands-on secure development, DevSecOps automation, WAF and FIM management, log/SIEM analysis, OWASP Top 10 mitigation, scripting for automation, and compliance with NIST/FedRAMP.
MicroTech: Provides IT, network, and cybersecurity solutions for government agencies.
3+ YOE3+ years in web application security or AppSec, bachelor's degree, experience with secure SDLC/DevSecOps, web dev tech (.NET, C#, HTML5, JavaScript), scripting (Python, Node.js), WAF/FIM, SIEM/EDR, and federal compliance knowledge.
Ad Hoc: Builds user-centered digital services and platforms for government agencies.
5+ YOEBachelor's degree and 5+ years software engineering experience; strong React, TypeScript, JavaScript, accessibility, REST API, testing, Git, and US citizenship with DHS Public Trust eligibility.
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
9+ YOEAdvanced RMF expertise, experience with Xacta/STIGs/OWASP/ACAS/Nessus, DoD 8140-aligned certs (CISSP/CCSP/GSE/CASP+), and 9+ years of relevant experience (varies by degree).
SOSi: Provides technology and mission solutions for national security.
5+ YOE5-7 years pentest experience; red team; IoT/mobile/cloud testing; MITRE ATT&CK, OSSTMM, OWASP, NIST, PTES, ISSAF; Bachelor's; Certifications: GPEN or GXPN; CISA with AES HVA Lead/Technical Lead plus one of GRTP/CRTL/OSCP/CRTP/CMWAPT/CEPT/CPT/LPT; Secret clearance.
Modern Technology Solutions, Inc.: Provides engineering, technology, and cybersecurity services for national security.
10+ YOE10+ years technical leadership in semiconductor R&D; experience in integrated circuit and embedded system design, micro-electronics analysis, system security, cryptography/key management, testing and evaluation; current TS/SCI clearance and MS in related field.
WalmartNYSE: WMT: Multinational retail operating discount stores and supermarkets.
4+ YOE4+ years application security experience with bachelor's degree or 6+ years without; expertise in OWASP, SAST/SCA tooling, threat modeling, secure architecture, and audit-ready governance.
SAST, SCA, OWASP, Web Content Accessibility Guidelines (WCAG) 2.2