Stralynn Consulting Services, Inc.

Web Developer Security Engineer

Stralynn Consulting Services, Inc. · Ashburn, Virginia, United States

IT Services and IT Consulting · 11-50 employees

19 h ago
Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The role involves identifying and neutralizing critical web application vulnerabilities while integrating security principles throughout the software development lifecycle. You will also manage security tools like WAFs and FIM while ensuring compliance with federal cybersecurity frameworks such as NIST and FISMA.

What they look for

Web Application Security AppSec SSDLC .NET C# HTML5 CSS3 JavaScript REST APIs SQL Python Node.js React.js TypeScript OWASP Top 10 Vulnerability Mitigation

Requirements

Candidates must have at least 3 years of experience in application security and proficiency in modern web development technologies. A bachelor's degree and a valid, long-term maintained security certification like CSSLP, GWEB, OSWE, or Security+ are mandatory.

Full description

About the Role

We are seeking an experienced Web Developer Security Engineer to serve as Key Personnel in protecting mission-critical web applications, APIs, and sensitive data. In this critical role, you will embed robust security principles throughout the Software Development Lifecycle (SDLC) to build security as a proactive, foundational pillar. You will act as the bridge between application development and cybersecurity, ensuring our applications are secure by design, compliant with federal frameworks, and resilient against evolving threats.

Key Responsibilities

  • Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.
  • Drive the end-to-end vulnerability lifecycle by integrating proactive threat modeling and advanced security assessments.
  • Actively support the end-to-end response to web application security events.
  • Deploy, tune, and maintain Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions.
  • Maintain meticulous documentation of findings, remediation steps, and security controls.
  • Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks (NIST SP 800-53, FISMA, and FedRAMP).
  • Perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and dependencies.
  • Evaluate, recommend, and implement security controls for mobile device solutions and mobile-web interfaces.
  • Participate in audits and security authorization processes.

Required Qualifications

Experience & Technical Skills:

  • Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC).
  • Proven development experience with modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL.
  • Proficiency with scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript).
  • Strong understanding of the OWASP Top 10, secure coding standards, and vulnerability mitigation.
  • Hands-on experience with security testing and monitoring tools (Wireshark, SIEM, IDS/IPS, NDR, EDR).
  • Experience providing Tier II support for security operations.

Education & Mandatory Credentials:

  • Education: Bachelor’s degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.
  • Certifications: Candidates must hold at least one of the following current certifications:• Specialized AppSec: CSSLP, GWEB, or EC-Council CASE
  • Offensive Security: OSWE or OSCP
  • Foundational Security: Security+ or GSEC
  • CRITICAL REQUIREMENT: The required certification (or its prior equivalent) must have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.

Preferred Qualifications

  • In-depth experience with Federal cybersecurity authorization processes (NIST SP 800-53, FISMA, FedRAMP).
  • Proven background in threat modeling, risk assessment, and designing resilient security architecture.
  • Advanced experience automating security gates within CI/CD pipelines.
  • Knowledge of cloud security (AWS) and container security (Docker, Kubernetes).