J

Web Application Security Engineer

JLGOVLLC · Washington, District of Columbia, United States · $115K–$120K/yr

Computer and Network Security · 11-50 employees

Jul 25
Mid (2-5 yrs) Contractor United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Web Application Security Engineer will identify, analyze, and remediate application vulnerabilities while integrating security controls into architectures and cloud environments. They will also support compliance with federal standards like NIST and FISMA while developing automation to improve security monitoring.

What they look for

Web Application Security Secure Code Review Threat Modeling Python JavaScript NIST SP 800-53 FISMA FedRAMP DevSecOps CI/CD OWASP Top 10 Vulnerability Remediation SQL React TypeScript Cloud Security

Requirements

Candidates must have a bachelor's degree and at least 3 years of experience in application security or secure software development. Proficiency in languages like Python, JavaScript, and .NET, along with knowledge of OWASP and federal compliance frameworks, is required.

Benefits

Professional growth support Certification support

Full description

PLEASE READ IN IT'S ENTIRITY -  This is a Web Security Engineer Role.  The interview will be scenario based to ensure you can successfully complete the job. 

Location: Remote (U.S.) may be expected to visit site for meeting and stakeholder engagement when requested. Candidate must be within 75 miles of the Washington DC area.

Employment: Contractor - Full-Time Salary: Starting at $115,000 - $120,050 annually (commensurate with experience and certifications) Clearance: Must be a U.S. Citizenship (required per government requirement). Ability to obtain or maintain a Federal security clearance preferred.  No Visa or Citizenship sponsorship

Key Responsibilities

Web Application Security

  • Identify, analyze, and remediate application vulnerabilities and security weaknesses.
  • Perform threat modeling, secure code reviews, and security assessments.
  • Integrate security controls into application architectures, APIs, and cloud environments.
  • Implement secure-by-design principles and OWASP best practices.

Monitoring, Incident Response & Automation

  • Analyze web server and application logs for threats and indicators of compromise.
  • Develop automation using Python, JavaScript, or AI-assisted tools to improve security monitoring and response.
  • Maintain documentation, remediation records, and security baselines.

Compliance & Governance

  • Support compliance with NIST SP 800-53, FISMA, and FedRAMP requirements.
  • Participate in risk assessments, audits, and security authorization activities.
  • Develop security metrics and compliance reporting.

Minimum Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or related field.
  • 3+ years of experience in Web Application Security, Application Security Engineering, or Secure Software Development.
  • Experience with secure software development, DevSecOps, CI/CD security, and vulnerability remediation.
  • Proficiency with:
  • .NET (C#), HTML5, CSS3, JavaScript, REST APIs, SQL
  • Python, JavaScript/Node.js, Java, React, or TypeScript
  • GitHub Copilot, OpenAI, or similar AI-assisted development tools
  • Strong knowledge of:
  • OWASP Top 10
  • Secure coding practices
  • Web Application Firewalls (WAF)
  • File Integrity Monitoring (FIM)
  • Security testing tools (Wireshark, SIEM, IDS/IPS, NDR, EDR)
  • Experience performing risk assessments and implementing security controls throughout the software development lifecycle.
  • Ability to work independently and collaboratively within multidisciplinary teams.

Preferred Qualifications

  • Experience supporting Federal cybersecurity programs.
  • Knowledge of NIST SP 800-53, FISMA, and FedRAMP authorization processes.
  • Experience with AWS, Docker, Kubernetes, and container security.
  • Experience designing resilient application security architectures and threat models.

Preferred Certifications

Candidates should possess one or more of the following (or equivalent):

  • CSSLP
  • GWEB
  • CASE
  • OSWE
  • OSCP
  • Security+
  • GSEC

Federal cybersecurity experience and certifications maintained through professional practice are highly desirable.

Why Join JLGOV?

  • Competitive salary
  • Remote work environment
  • Federal mission-focused projects
  • Professional growth and certification support
  • Opportunity to work with advanced cybersecurity and AI-enabled technologies

Equal Employment Opportunity

JLGOV is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law. We are committed to fostering an inclusive workplace where all qualified individuals are encouraged to apply.