Jobs · Engineering · Virginia

Web Developer Security Engineer

Stralynn Consulting Services, Inc · Ashburn, VA · 3 wk ago
On-siteEngineeringFull-time

About the Role

We are seeking an experienced Web Developer Security Engineer to serve as Key Personnel in protecting mission-critical web applications, APIs, and sensitive data. In this critical role, you will embed robust security principles throughout the Software Development Lifecycle (SDLC) to build security as a proactive, foundational pillar. You will act as the bridge between application development and cybersecurity, ensuring our applications are secure by design, compliant with federal frameworks, and resilient against evolving threats.

Responsibilities

  • Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations
  • Drive the end-to-end vulnerability lifecycle by integrating proactive threat modeling and advanced security assessments
  • Actively support the end-to-end response to web application security events
  • Deploy, tune, and maintain Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions
  • Maintain meticulous documentation of findings, remediation steps, and security controls
  • Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks (NIST SP 800-53, FISMA, and FedRAMP)
  • Perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and dependencies
  • Evaluate, recommend, and implement security controls for mobile device solutions and mobile-web interfaces
  • Participate in audits and security authorization processes

Qualifications

Experience & Technical Skills:

  • Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC)
  • Proven development experience with modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL
  • Proficiency with scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript)
  • Strong understanding of the OWASP Top 10, secure coding standards, and vulnerability mitigation
  • Hands-on experience with security testing and monitoring tools (Wireshark, SIEM, IDS/IPS, NDR, EDR)
  • Experience providing Tier II support for security operations

Education & Mandatory Credentials:

  • Education: Bachelor’s degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field
  • Certifications: Candidates must hold at least one of the following current certifications:
    • Specialized AppSec: CSSLP, GWEB, or EC-Council CASE
    • Offensive Security: OSWE or OSCP
    • Foundational Security: Security+ or GSEC

    CRITICAL REQUIREMENT: The required certification (or its prior equivalent) must have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.

Preferred Qualifications

  • In-depth experience with Federal cybersecurity authorization processes (NIST SP 800-53, FISMA, FedRAMP)
  • Proven background in threat modeling, risk assessment, and designing resilient security architecture
  • Advanced experience automating security gates within CI/CD pipelines
  • Knowledge of cloud security (AWS) and container security (Docker, Kubernetes)

Similar jobs

Web Security Engineer

Brown Brothers HarrimanPhiladelphia, PA· 2 days ago
$100k–$130k/yrapply on bbh.wd5.myworkdayjobs.com

SECURITY DEVELOPER

Beam WalletIndiana, United States· 1 mo ago
Information Technologyapply on beamwallet.com