
Posted 3 months ago
Web Developer Security Engineer
AI Summary
The Web Developer Security Engineer identifies, analyzes, and remediates vulnerabilities in web applications and APIs, embedding security across the development lifecycle and supporting compliance.
About this role
What Your Day-To-Day Looks Like (Position Responsibilities):
-
Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.
-
Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions.
-
Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services.
-
Review and analyze web server and application logs to detect anomalies and indicators of compromise.
-
Implement automation scripts for threat intelligence integration and application security monitoring.
-
Participate in audits, risk assessments, and security authorization activities tied to federal frameworks.
What You Need to Succeed (Minimum Requirements):
-
Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work.
-
Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation.
-
Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL).
-
Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts.
-
Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools.
-
Ability to perform risk assessments and provide remediation guidance for core systems and dependencies.
-
Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field.
-
Ability to meet federal screening and suitability requirements prior to start.
-
Current security certifications maintained for a minimum of five years, spanning application security (such as CSSLP, GWEB, or CASE), offensive security (such as OSWE or OSCP), and foundational security (such as Security+ or GSEC); expired or never-used certifications will not be considered.
Ideally, You Also Have (Preferred Qualifications):
-
In-depth experience with federal cybersecurity frameworks and authorization processes.
-
Experience with threat modeling, resilient security architecture, cloud security, and container security.
Skills
Explore related jobs
More jobs at Spry Methods
Information System Security Officer (ISSO)Washington, DC (Remote)
Acquisition Program Analyst, JourneymanQuantico, VA
Acquisition Program Analyst, SeniorQuantico, VA
SharePoint Developer / AdministratorQuantico, VA
Operations Analyst, Journeyman (On-Site)Quantico, VA
Business Analyst, JourneymanQuantico, VA
Similar CSS3 jobs
Jobs in Washington
- Customer Service Rep(03991) - 16 W Washington Ave.Domino's · Washington, NJ
- Assistant Manager(03991) - 16 W Washington Ave.Domino's · Washington, NJ
- Delivery Driver(09124) - 328 E Maiden stDomino's · Washington, PA
- Customer Service Rep(09124) - 328 E Maiden StDomino's · Washington, PA
Parent EducatorGeneration Hope · Washington, District of Columbia
ControllerThe Brand Guild · Washington, District of Columbia
Browse these categories
Market data for security engineer roles
All reports →- SeriesRole reportsOne role family at a time: how many openings, what changed this week, who is hiring, what it pays.
- SeriesSalary reportsWhat employers publish in job postings, by level and workplace. Not self-reported pay.
- Market overviewState of tech hiring, September 2026: up 4.8%Tech hiring rose 4.8% month over month in September 2026, with 411,122 new listings. Customer support and account executive roles led the growth.