{"schemaVersion":"jobsearcher.job.v1","id":"249dcded98208e606fed88ef","url":"https://jobsearcher.com/jobs/249dcded98208e606fed88ef","canonicalUrl":"https://jobsearcher.com/jobs/249dcded98208e606fed88ef","title":"Web Developer Security Engineer","description":"OVERVIEW\n\nClearance: Public Trust Tier 2 or higher preferred\nApplied Intellect is seeking a Web Developer Security Engineer to support federal contracts, by playing a pivotal role in protecting mission-critical web applications, APIs and sensitive data. The objectives are to embed robust security principles throughout the software development lifecycle (SDLC) to build security as a proactive, foundational pillar.\nKey Responsibilities\nThe Key Responsibilities include, but is not limited to, the following activities:\nWeb Application Security\nIdentify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations\nDrive the end-to-end vulnerability lifecycle - integrating proactive threat modeling and advanced security assessments, ensuring remediation integrity through rigorous technical validation\nSupport integration of security controls into application architectures, APIs, and supporting services, advising on secure design patterns; data protection mechanisms; and secure communication protocols to ensure applications are secure by design and resilient to evolving threats\nMonitoring, Logging, Incident Response and Automation\nObtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise\nImplement automation scripts for threat intelligence integration to optimize alert accuracy and actively support the end-to-end response to web application security events.\nMaintain documentation of findings, remediation steps, and security controls\nCompliance & Governance\nEnsure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks, including NIST SP 800‑53, FISMA, and FedRAMP (as applicable)\nParticipate in audits, risk assessments, and security authorization processes\nRequired Skills/Knowledge/Expertise\nExtensive hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation.\nProficiency in logs analysis, file integrity monitoring (FIM), and managing web application firewalls (WAF) to defend against emerging threats.\nMinimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec) or secure software development life cycle (SSDLC)\nProven developing with modern web technologies and frameworks not limited to .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL\nAbility to leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript) to automate security monitoring and compliance audits\nStrong understanding of Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, and proactive mitigation of common web vulnerabilities.\nExperience deploying, tuning, and maintaining Web Application Firewalls (WAFs) solutions tailored to custom-developed applications and traffic patterns.\nStrong track record in configuring and managing File Integrity Monitoring (FIM) solutions for web content directories, to detect and alert on unauthorized change.\nFamiliar with security testing tools such as Wireshark, SIEM, IDS/IPS, NDR, or EDR\nEvaluates, recommends, and implements security controls for mobile device solutions and mobile-web interface.\nAbility to perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and their dependencies\nProven ability to implement DevSecOps principles, seamlessly integrating security controls throughout the CI/CD pipeline\nExperience developing security metrics, managing compliance reporting, and auditing systems against established security baselines\nCollaborate effectively across multidisciplinary teams, and work independently as well as in a team\nExperience providing Tier II support for security operations and recommending continue security enhancements for existing infrastructure.\nDesired Skills\nIn-depth experience at Federal cybersecurity frameworks (NIST SP 800‑53, FISMA, FedRAMP) authorization process\nProven background in threat modeling, risk assessment, and designing resilient security architecture\nAdvanced experience implementing secure DevOps/DevSecOps practices, specifically focus on CI/CD pipeline and automating security gates\nKnowledge of cloud security AWS and container security (Docker, Kubernetes)\nRequired Education & Credentials\nBachelor’s degree (or higher) in computer science, Cybersecurity, Information Systems, Engineering, or a related field.\nThe candidate also must have at least one of the following current credentials/certification for each category:\nSpecialized AppSec:\nCertified Secure Software Lifecyle Professional (CSSLP)\nGIAC Certified Web Application Defender (GWEB)\nEC-Council Certified Application Security Engineer (CASE)\nOffensive Security:\nOffSec Web Expert (OSWE)\nOffensive Security Certified Professional (OSCP)\nFoundational Security:\nSecurity+\nGSEC\nThese (or their equivalent prior certifications) should have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.\nPHYSICAL DEMANDS\nUse of manual dexterity, tactile, visual, and audio acuity;\nUse of repetitive motion, prolonged periods of sitting and standing, and sustained visual and mental applications and demands;\nOccasional lifting (up to 25 pounds), bending, pulling, and carrying; and\nQuantitative/mathematical ability (addition, subtraction, multiplication, division, standard measurements).\n\nReasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.\nEQUAL EMPLOYMENT OPPORTUNITY\nApplied Intellect is an equal opportunity employer.\nThe above-listed duties and responsibilities are essential job functions. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. All job duties indicated are not to be an exhaustive statement, and other job-related duties may be assigned as required by the supervisor(s).","company":"Appliedintellectll","rawCompany":"appliedintellectll","city":"Gaithersburg","state":"MD","isRemote":false,"isActive":false,"createdAt":"2026-08-04T22:49:20.663Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1254.00","title":"Web Developers","slug":"web-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Web Developer Security Engineer","description":"OVERVIEW\n\nClearance: Public Trust Tier 2 or higher preferred\nApplied Intellect is seeking a Web Developer Security Engineer to support federal contracts, by playing a pivotal role in protecting mission-critical web applications, APIs and sensitive data. The objectives are to embed robust security principles throughout the software development lifecycle (SDLC) to build security as a proactive, foundational pillar.\nKey Responsibilities\nThe Key Responsibilities include, but is not limited to, the following activities:\nWeb Application Security\nIdentify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations\nDrive the end-to-end vulnerability lifecycle - integrating proactive threat modeling and advanced security assessments, ensuring remediation integrity through rigorous technical validation\nSupport integration of security controls into application architectures, APIs, and supporting services, advising on secure design patterns; data protection mechanisms; and secure communication protocols to ensure applications are secure by design and resilient to evolving threats\nMonitoring, Logging, Incident Response and Automation\nObtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise\nImplement automation scripts for threat intelligence integration to optimize alert accuracy and actively support the end-to-end response to web application security events.\nMaintain documentation of findings, remediation steps, and security controls\nCompliance & Governance\nEnsure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks, including NIST SP 800‑53, FISMA, and FedRAMP (as applicable)\nParticipate in audits, risk assessments, and security authorization processes\nRequired Skills/Knowledge/Expertise\nExtensive hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation.\nProficiency in logs analysis, file integrity monitoring (FIM), and managing web application firewalls (WAF) to defend against emerging threats.\nMinimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec) or secure software development life cycle (SSDLC)\nProven developing with modern web technologies and frameworks not limited to .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL\nAbility to leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript) to automate security monitoring and compliance audits\nStrong understanding of Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, and proactive mitigation of common web vulnerabilities.\nExperience deploying, tuning, and maintaining Web Application Firewalls (WAFs) solutions tailored to custom-developed applications and traffic patterns.\nStrong track record in configuring and managing File Integrity Monitoring (FIM) solutions for web content directories, to detect and alert on unauthorized change.\nFamiliar with security testing tools such as Wireshark, SIEM, IDS/IPS, NDR, or EDR\nEvaluates, recommends, and implements security controls for mobile device solutions and mobile-web interface.\nAbility to perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and their dependencies\nProven ability to implement DevSecOps principles, seamlessly integrating security controls throughout the CI/CD pipeline\nExperience developing security metrics, managing compliance reporting, and auditing systems against established security baselines\nCollaborate effectively across multidisciplinary teams, and work independently as well as in a team\nExperience providing Tier II support for security operations and recommending continue security enhancements for existing infrastructure.\nDesired Skills\nIn-depth experience at Federal cybersecurity frameworks (NIST SP 800‑53, FISMA, FedRAMP) authorization process\nProven background in threat modeling, risk assessment, and designing resilient security architecture\nAdvanced experience implementing secure DevOps/DevSecOps practices, specifically focus on CI/CD pipeline and automating security gates\nKnowledge of cloud security AWS and container security (Docker, Kubernetes)\nRequired Education & Credentials\nBachelor’s degree (or higher) in computer science, Cybersecurity, Information Systems, Engineering, or a related field.\nThe candidate also must have at least one of the following current credentials/certification for each category:\nSpecialized AppSec:\nCertified Secure Software Lifecyle Professional (CSSLP)\nGIAC Certified Web Application Defender (GWEB)\nEC-Council Certified Application Security Engineer (CASE)\nOffensive Security:\nOffSec Web Expert (OSWE)\nOffensive Security Certified Professional (OSCP)\nFoundational Security:\nSecurity+\nGSEC\nThese (or their equivalent prior certifications) should have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.\nPHYSICAL DEMANDS\nUse of manual dexterity, tactile, visual, and audio acuity;\nUse of repetitive motion, prolonged periods of sitting and standing, and sustained visual and mental applications and demands;\nOccasional lifting (up to 25 pounds), bending, pulling, and carrying; and\nQuantitative/mathematical ability (addition, subtraction, multiplication, division, standard measurements).\n\nReasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.\nEQUAL EMPLOYMENT OPPORTUNITY\nApplied Intellect is an equal opportunity employer.\nThe above-listed duties and responsibilities are essential job functions. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. All job duties indicated are not to be an exhaustive statement, and other job-related duties may be assigned as required by the supervisor(s).","datePosted":"2026-08-04T22:49:20.663Z","dateModified":"2026-08-04T22:49:20.663Z","hiringOrganization":{"@type":"Organization","name":"Appliedintellectll","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Gaithersburg","addressRegion":"MD","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"249dcded98208e606fed88ef"},"url":"https://jobsearcher.com/jobs/249dcded98208e606fed88ef"}}