{"schemaVersion":"jobsearcher.job.v1","id":"1d81e0f5f5c0c37ba075ff3f","url":"https://jobsearcher.com/jobs/1d81e0f5f5c0c37ba075ff3f","canonicalUrl":"https://jobsearcher.com/jobs/1d81e0f5f5c0c37ba075ff3f","title":"Security Software Engineers","description":"Summary\nEvurge Solutions is seeking is a Security Software Engineer with the following experiences and requirements to test, advise and consult on application security for internal and external web systems and applications.\nVerify findings as needed with application development team\nPerform manual source code review for security vulnerabilities\nWrite formal security assessment report for each application\nPerform bug hunting/penetration testing, threat modeling, risk analysis and thorough reporting to Security, Dev and Ops teams\nIdentify and remediate XSS, CSRF, SSRF, RCE and other attack surfaces\nDemonstrated ability to meet deliverables, timetables, and deadlines.\nKnowledge of current and emerging security and information technology standards and practices.\nExperience conducting vulnerability assessments and articulating security issues to technical and non-technical audience.\nOther activities to ensure performance and the information security program\nPosition Type\nFull-time\nLocation\nChantilly, VA\nQualifications\nUnderstanding of web service technologies such as XML, JSON, SOAP, and REST\nThorough understanding of security methodologies and frameworks like SSDLC, MITRE ATT&CK, NIST CSF and OWASP Testing Guide v4\nStrong coding skills in multiple common languages such as C#, Python, Ruby, Perl, Go, PHP and SQL and working knowledge of network and web related protocols TCP/IP, UDP, IPSEC, HTTP/S and BGP\nIdentify and remediate XSS, CSRF, SSRF, RCE and other attack surfaces\nSecurity compliance regimes: NIST, PCI-DSS, ISO 27000, CIS, etc.\nBackground in J2EE, web frameworks, and .NET is a plus\nRequirements\nMust be able to obtain a Public Trust Clearence.\nExperience\nHands-on experience working with application security in the realms of smoke testing, error handling, static code analysis, pre commit hooks, attack mapping, container security, continuous monitoring, authentication, session management and dependency mapping as well as penetration test tooling like Burp Suite, Metasploit and WebInspect\nVulnerability Management, Threat Vector Analysis, Intrusion Detection and Prevention, Incident Management and Response, Web Application Security, Risk Assessment and Mitigation Methodologies\nProficiency in building and automating efficient and effective scripts from scratch with languages such as Python, Node.js, sh, Perl, etc.\nExperience applying knowledge of information security concepts and theories through technical and non-technical methods.\nSolid understanding of cyber security threats, risks, vulnerabilities, and attacks, giving insight into threat actor motives, capabilities, and techniques.\nExperience with WebInspect, AppScan Source, Fortify, Veracode, Sonatype or Blackduck platform\nKnowledge of tools and processes used to expose common vulnerabilities and implement countermeasures is expected.\nExpectations","company":"Evurgesolutions","rawCompany":"evurgesolutions","city":"Gaithersburg","state":"MD","isRemote":false,"isActive":false,"createdAt":"2026-04-12T20:19:24.981Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Software Engineers","description":"Summary\nEvurge Solutions is seeking is a Security Software Engineer with the following experiences and requirements to test, advise and consult on application security for internal and external web systems and applications.\nVerify findings as needed with application development team\nPerform manual source code review for security vulnerabilities\nWrite formal security assessment report for each application\nPerform bug hunting/penetration testing, threat modeling, risk analysis and thorough reporting to Security, Dev and Ops teams\nIdentify and remediate XSS, CSRF, SSRF, RCE and other attack surfaces\nDemonstrated ability to meet deliverables, timetables, and deadlines.\nKnowledge of current and emerging security and information technology standards and practices.\nExperience conducting vulnerability assessments and articulating security issues to technical and non-technical audience.\nOther activities to ensure performance and the information security program\nPosition Type\nFull-time\nLocation\nChantilly, VA\nQualifications\nUnderstanding of web service technologies such as XML, JSON, SOAP, and REST\nThorough understanding of security methodologies and frameworks like SSDLC, MITRE ATT&CK, NIST CSF and OWASP Testing Guide v4\nStrong coding skills in multiple common languages such as C#, Python, Ruby, Perl, Go, PHP and SQL and working knowledge of network and web related protocols TCP/IP, UDP, IPSEC, HTTP/S and BGP\nIdentify and remediate XSS, CSRF, SSRF, RCE and other attack surfaces\nSecurity compliance regimes: NIST, PCI-DSS, ISO 27000, CIS, etc.\nBackground in J2EE, web frameworks, and .NET is a plus\nRequirements\nMust be able to obtain a Public Trust Clearence.\nExperience\nHands-on experience working with application security in the realms of smoke testing, error handling, static code analysis, pre commit hooks, attack mapping, container security, continuous monitoring, authentication, session management and dependency mapping as well as penetration test tooling like Burp Suite, Metasploit and WebInspect\nVulnerability Management, Threat Vector Analysis, Intrusion Detection and Prevention, Incident Management and Response, Web Application Security, Risk Assessment and Mitigation Methodologies\nProficiency in building and automating efficient and effective scripts from scratch with languages such as Python, Node.js, sh, Perl, etc.\nExperience applying knowledge of information security concepts and theories through technical and non-technical methods.\nSolid understanding of cyber security threats, risks, vulnerabilities, and attacks, giving insight into threat actor motives, capabilities, and techniques.\nExperience with WebInspect, AppScan Source, Fortify, Veracode, Sonatype or Blackduck platform\nKnowledge of tools and processes used to expose common vulnerabilities and implement countermeasures is expected.\nExpectations","datePosted":"2026-04-12T20:19:24.981Z","dateModified":"2026-04-12T20:19:24.981Z","hiringOrganization":{"@type":"Organization","name":"Evurgesolutions","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Gaithersburg","addressRegion":"MD","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"1d81e0f5f5c0c37ba075ff3f"},"url":"https://jobsearcher.com/jobs/1d81e0f5f5c0c37ba075ff3f"}}