Web Developer Security Engineer
About the Role
We are seeking an experienced Web Developer Security Engineer to serve as Key Personnel in protecting mission-critical web applications, APIs, and sensitive data. In this critical role, you will embed robust security principles throughout the Software Development Lifecycle (SDLC) to build security as a proactive, foundational pillar. You will act as the bridge between application development and cybersecurity, ensuring our applications are secure by design, compliant with federal frameworks, and resilient against evolving threats.
Responsibilities
- Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations
- Drive the end-to-end vulnerability lifecycle by integrating proactive threat modeling and advanced security assessments
- Actively support the end-to-end response to web application security events
- Deploy, tune, and maintain Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions
- Maintain meticulous documentation of findings, remediation steps, and security controls
- Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks (NIST SP 800-53, FISMA, and FedRAMP)
- Perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and dependencies
- Evaluate, recommend, and implement security controls for mobile device solutions and mobile-web interfaces
- Participate in audits and security authorization processes
Qualifications
Experience & Technical Skills:
- Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC)
- Proven development experience with modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL
- Proficiency with scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript)
- Strong understanding of the OWASP Top 10, secure coding standards, and vulnerability mitigation
- Hands-on experience with security testing and monitoring tools (Wireshark, SIEM, IDS/IPS, NDR, EDR)
- Experience providing Tier II support for security operations
Education & Mandatory Credentials:
- Education: Bachelor’s degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field
- Certifications: Candidates must hold at least one of the following current certifications:
- Specialized AppSec: CSSLP, GWEB, or EC-Council CASE
- Offensive Security: OSWE or OSCP
- Foundational Security: Security+ or GSEC
CRITICAL REQUIREMENT: The required certification (or its prior equivalent) must have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.
Preferred Qualifications
- In-depth experience with Federal cybersecurity authorization processes (NIST SP 800-53, FISMA, FedRAMP)
- Proven background in threat modeling, risk assessment, and designing resilient security architecture
- Advanced experience automating security gates within CI/CD pipelines
- Knowledge of cloud security (AWS) and container security (Docker, Kubernetes)