Web Developer Security Engineer
Stralynn Consulting Services, Inc. · Ashburn, Virginia, United States
IT Services and IT Consulting · 11-50 employees
About the role
The role involves identifying and neutralizing critical web application vulnerabilities while integrating security principles throughout the software development lifecycle. You will also manage security tools like WAFs and FIM while ensuring compliance with federal cybersecurity frameworks such as NIST and FISMA.
What they look for
Requirements
Candidates must have at least 3 years of experience in application security and proficiency in modern web development technologies. A bachelor's degree and a valid, long-term maintained security certification like CSSLP, GWEB, OSWE, or Security+ are mandatory.
Full description
About the Role
We are seeking an experienced Web Developer Security Engineer to serve as Key Personnel in protecting mission-critical web applications, APIs, and sensitive data. In this critical role, you will embed robust security principles throughout the Software Development Lifecycle (SDLC) to build security as a proactive, foundational pillar. You will act as the bridge between application development and cybersecurity, ensuring our applications are secure by design, compliant with federal frameworks, and resilient against evolving threats.
Key Responsibilities
- Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.
- Drive the end-to-end vulnerability lifecycle by integrating proactive threat modeling and advanced security assessments.
- Actively support the end-to-end response to web application security events.
- Deploy, tune, and maintain Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions.
- Maintain meticulous documentation of findings, remediation steps, and security controls.
- Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks (NIST SP 800-53, FISMA, and FedRAMP).
- Perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and dependencies.
- Evaluate, recommend, and implement security controls for mobile device solutions and mobile-web interfaces.
- Participate in audits and security authorization processes.
Required Qualifications
Experience & Technical Skills:
- Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC).
- Proven development experience with modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL.
- Proficiency with scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript).
- Strong understanding of the OWASP Top 10, secure coding standards, and vulnerability mitigation.
- Hands-on experience with security testing and monitoring tools (Wireshark, SIEM, IDS/IPS, NDR, EDR).
- Experience providing Tier II support for security operations.
Education & Mandatory Credentials:
- Education: Bachelor’s degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.
- Certifications: Candidates must hold at least one of the following current certifications:• Specialized AppSec: CSSLP, GWEB, or EC-Council CASE
- Offensive Security: OSWE or OSCP
- Foundational Security: Security+ or GSEC
- CRITICAL REQUIREMENT: The required certification (or its prior equivalent) must have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.
Preferred Qualifications
- In-depth experience with Federal cybersecurity authorization processes (NIST SP 800-53, FISMA, FedRAMP).
- Proven background in threat modeling, risk assessment, and designing resilient security architecture.
- Advanced experience automating security gates within CI/CD pipelines.
- Knowledge of cloud security (AWS) and container security (Docker, Kubernetes).