224 web application security developer jobs at 164 companies in United States
2mo
Save
Mark Applied
Hide
2mo
Web Application Developer
McLean or United States
OnsiteFull Time
J5 Consulting: Minority-owned cybersecurity and IT consulting firm serving commercial businesses and government and defense organizations.
Experience developing modern web applications with JavaScript/TypeScript frameworks, Node.js, RESTful APIs, SQL databases (PostgreSQL/MySQL), containerization (Docker/Podman), AWS, Git, Agile, and strong security and problem-solving skills. US citizenship and active Top Secret clearance with Full Scope Polygraph required.
Quevera: Veteran-owned custom software engineering firm serving government customers with mission-critical IT solutions.
7+ YOERequires active TS/SCI clearance with polygraph, 7 years of software engineering experience, a bachelor's in computer science or equivalent experience, IAM certification, and web development, Linux, API, database, and secure coding skills.
IntelliDyne: Government IT consulting firm delivering technology services to federal and commercial clients.
5+ YOE5+ years Python development, Flask experience, web app deployment and security, authentication and certificate management, REST API and database integration, Git, strong debugging and communication skills.
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions: Minority-owned Alabama small-business government contractor delivering IT, professional, geospatial, healthcare, and environmental services to public and commercial clients.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
IntelliDyne: Government IT consulting firm delivering technology services to federal and commercial clients.
5+ YOE5+ years Python development, Flask experience, web app deployment and security, authentication and certificate management, REST APIs, relational DBs, Git, HTML/CSS/JavaScript, strong debugging and communication skills.
SME Web Application Developer — Data Visualization
McLean, Virginia, United States
OnsiteFull Time
Data Intelligence: Private U.S. government contractor providing systems engineering, software development, cybersecurity, and logistics support to federal clients.
15+ YOE15+ years web/software development, expert JavaScript and Vue.js, strong data visualization competency, ability to obtain/maintain security clearance, self-driven and able to mentor.
Spry Methods, Inc.: Minority-owned federal contractor providing cybersecurity, national-security, and IT modernization services to government and commercial clients.
3+ YOE3+ years in web application security or secure software development; hands-on experience with .NET, HTML5, CSS3, JavaScript, REST APIs, and SQL; DevSecOps automation, vulnerability remediation, OWASP Top 10 knowledge, and relevant security certifications.
Nationwide IT Services: Service-disabled veteran-owned IT and management consulting firm serving federal agencies with technology, cybersecurity, and mission support.
3+ YOE3+ years in application security/SSDLC, strong OWASP knowledge, vulnerability lifecycle management, DevSecOps/CI-CD integration, WAF and FIM experience, Tier II security operations, relevant application/offensive/foundational security certification.
The Amatriot Group: Service-disabled veteran-owned talent and technology solutions firm serving federal and commercial sectors.
8+ YOERequires 8+ years of IT experience, 3+ years in application security engineering, 5+ years in software development, Java/web development, secure coding, RHEL, JBoss, and application scanning.
AMERICAN SYSTEMS: Government services contractor delivering IT and engineering solutions.
8+ YOEActive TS/SCI clearance, Security+ CE (or ability within 90 days), Bachelor’s in CS or equivalent, 8–10 years experience, proficiency with React.js, Node.js, JavaScript, HTML, CSS, SQL, RESTful APIs, Git, and Linux (RHEL).
Vannevar Labs: Labs is a private defense technology building agentic AI software for government national-security missions.
5+ YOERequires 5+ years in application or product security, web application security, AppSec automation, DevSecOps, container security, GitHub Actions, Python, and TypeScript/JavaScript. Security clearance is preferred.
Veilant: Creates control. Advance Undetected in the digital domain.
2+ YOERequires 2+ years of Java development, application security testing, source-code review, web security, CI/CD, containers, cloud platforms, and strong technical communication; must be able to obtain security clearance.
One Federal Solution: Professional services firm providing contract support to government agencies.
6+ YOEBachelor's in CS/IS/Software Eng, 6+ years building enterprise web apps, 3–4 years with open-source tools, Azure migration experience, API and containerization skills, security and accessibility knowledge.
JavaScript, Angular, SQL Server, MySQL, PostgreSQL, Python, Entity Framework, GraphQL, RESTful API, Linux, Microsoft Azure, Git, GitHub, Docker, HTML, XHTML, CSS, U.S. Web Design System (USWDS)
CACINYSE: CACI: Provider of specialized IT and mission-critical government services.
10+ YOEActive Top Secret/SCI with Polygraph, Bachelor's in Computer Science or related, 10+ years web development experience, Oracle SQL/PLSQL, ASP.NET, JavaScript/Angular/node.js/TypeScript, C#, MVC, SAML/OIDC, CI/CD, secure environment experience.
RiVidium: RiVidium is a privately held federal contractor providing cybersecurity, IT, human-capital, and intelligence services to government agencies.
5+ YOERequires 5+ years of secure software or application security engineering, 3+ years of web application security or SSDLC, a bachelor's degree or equivalent, and active Top Secret clearance.
Virtru: Private data security platform providing encryption and access controls for enterprises and government agencies.
4+ YOE4+ years in application security or secure development, strong cryptography and web security knowledge, experience with Node.js and Go, SAST/DAST/IAST/SCA tooling, vulnerability programs (bug bounty, pentest), and familiarity with cloud infra (GCP/AWS) and Kubernetes preferred.
Node.js, Go, Trusted Data Format (TDF), SAST, DAST, IAST, SCA, Burp, ZAP, Qualys, Nessus, GCP, AWS, Kubernetes, Slack, Zoom
LNO, Inc.: Native American-owned, service-disabled-veteran-owned defense contractor providing IT, cybersecurity, engineering, logistics, and training services to federal customers.
3+ YOEActive Secret security clearance required, 3+ years web/app development experience, proficiency with front-end (HTML,CSS,JavaScript/TypeScript), back-end APIs, relational and non-relational databases, and secure coding practices; Bachelor’s degree preferred.
Reltio: Cloud-native master-data-management SaaS provider helping enterprises unify, govern, and activate data across SAP and non-SAP systems.
8+ YOE8+ years in application security or software development in cloud-native/SaaS environments; expertise in secure SDLC, CI/CD security, SAST/SCA/DAST, API and AI security; strong cloud and web technology knowledge.
Georgia-Pacific: Privately owned U.S. forest-products manufacturer serving households, businesses, builders, packaging, hygiene, pulp and recycling markets.
Experience securing web applications, analyzing SAST/SCA/DAST findings, programming in listed languages, cloud security in AWS or Azure, and collaborating across teams. Permanent U.S. work authorization required.