{"schemaVersion":"jobsearcher.job.v1","id":"620f4498c029a2e0eb959638","url":"https://jobsearcher.com/jobs/620f4498c029a2e0eb959638","canonicalUrl":"https://jobsearcher.com/jobs/620f4498c029a2e0eb959638","title":"Web Developer Security Engineer","description":"ABOUT US:\n\nCMT Services Inc. is a dynamic and small business supporting Federal, State, and Local government agencies. As an SBA-certified HUBZone, Woman Owned Small Business (WOSB), we deliver quality, professional services to support the missions and strategic business goals of our clients.\n\nPosition Title: Web Developer Security Engineer\n\nLocation:\nUS Congressional Budget Office\nFord House Office Building, 4th floor\n2nd St SW, 441 D St SW\nWashington, DC 20024\n\nPeriod of Performance:\n08/15/2026 - 08/14/2031\n\nPlace of Performance:\nRemote work; however, at CBO’s discretion employees may be required to work on-site at CBO facilities\n\nPosition Summary:\nProtects CBO’s mission-critical web applications, APIs, and sensitive data by embedding strong security throughout the software development lifecycle — making security a proactive, built-in part of design and delivery.\n\nKey Responsibilities:\nIdentify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.\nDrive the end-to-end vulnerability lifecycle — proactive threat modeling, advanced security assessments, and remediation validation.\nSupport integration of security controls into application architectures, APIs, and services; advise on secure design patterns, data protection, and secure communication protocols.\nObtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise.\nImplement automation scripts for threat-intelligence integration; support end-to-end response to web application security events.\nMaintain documentation of findings, remediation steps, and security controls.\nEnsure web applications and cloud infrastructure comply with NIST SP 800-53, FISMA, and FedRAMP (as applicable); participate in audits, risk assessments, and authorization.\n\nRequired Qualifications:\nExtensive hands-on secure software development, DevSecOps automation, and vulnerability remediation.\nProficiency in log analysis, file integrity monitoring (FIM), and managing web application firewalls (WAF).\nMinimum 3 years in Web Application Security, AppSec, or secure SDLC (SSDLC).\nDevelopment with modern web technologies and frameworks including .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL.\nAbility to leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting (Python, JavaScript/Node.js, Java, React.js, TypeScript) to automate security monitoring and compliance audits.\nStrong understanding of OWASP Top 10, secure coding standards, and mitigation of common web vulnerabilities.\nDeploying, tuning, and maintaining WAF solutions tailored to custom applications and traffic patterns.\nConfiguring/managing File Integrity Monitoring (FIM) for web content directories.\nFamiliarity with security testing tools — Wireshark, SIEM, IDS/IPS, NDR, or EDR.\nEvaluating/recommending/implementing security controls for mobile device and mobile-web interfaces.\n\nPerforming complex risk assessments, analyzing cyber threats, and providing remediation guidance for core systems and dependencies.\nImplementing DevSecOps principles — integrating security controls throughout the CI/CD pipeline.\nDeveloping security metrics, managing compliance reporting, and auditing systems against baselines.\nEffective cross-team collaboration and independent work; providing Tier II support for security operations.\n\nEducation:\nBachelor’s degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.\n\nCertification:\nSpecialized AppSec: CSSLP (Certified Secure Software Lifecycle Professional); GWEB (GIAC Certified Web Application Defender); CASE (EC-Council Certified Application Security Engineer).\nOffensive Security: OSWE (OffSec Web Expert); OSCP (Offensive Security Certified Professional).\nFoundational Security: Security+; GSEC.\n\nJoin Our Team:\n\nAt CMT Services, we believe that extraordinary results come from empowering exceptional people. If you're ready to lead innovative projects, solve complex challenges, and contribute to meaningful infrastructure development while advancing your career in a supportive, collaborative environment, we want to hear from you.\n\nDisclaimer:\nBy submitting your resume for this job posting, you authorize CMT Services, Inc. to forward your resume to all applicable internal and external managers, agencies, and recruitment personnel for review and consideration to hire.","company":"Cmt Services","rawCompany":"cmt services","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-08-03T18:57:35.687Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1254.00","title":"Web Developers","slug":"web-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Web Developer Security Engineer","description":"ABOUT US:\n\nCMT Services Inc. is a dynamic and small business supporting Federal, State, and Local government agencies. As an SBA-certified HUBZone, Woman Owned Small Business (WOSB), we deliver quality, professional services to support the missions and strategic business goals of our clients.\n\nPosition Title: Web Developer Security Engineer\n\nLocation:\nUS Congressional Budget Office\nFord House Office Building, 4th floor\n2nd St SW, 441 D St SW\nWashington, DC 20024\n\nPeriod of Performance:\n08/15/2026 - 08/14/2031\n\nPlace of Performance:\nRemote work; however, at CBO’s discretion employees may be required to work on-site at CBO facilities\n\nPosition Summary:\nProtects CBO’s mission-critical web applications, APIs, and sensitive data by embedding strong security throughout the software development lifecycle — making security a proactive, built-in part of design and delivery.\n\nKey Responsibilities:\nIdentify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.\nDrive the end-to-end vulnerability lifecycle — proactive threat modeling, advanced security assessments, and remediation validation.\nSupport integration of security controls into application architectures, APIs, and services; advise on secure design patterns, data protection, and secure communication protocols.\nObtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise.\nImplement automation scripts for threat-intelligence integration; support end-to-end response to web application security events.\nMaintain documentation of findings, remediation steps, and security controls.\nEnsure web applications and cloud infrastructure comply with NIST SP 800-53, FISMA, and FedRAMP (as applicable); participate in audits, risk assessments, and authorization.\n\nRequired Qualifications:\nExtensive hands-on secure software development, DevSecOps automation, and vulnerability remediation.\nProficiency in log analysis, file integrity monitoring (FIM), and managing web application firewalls (WAF).\nMinimum 3 years in Web Application Security, AppSec, or secure SDLC (SSDLC).\nDevelopment with modern web technologies and frameworks including .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL.\nAbility to leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting (Python, JavaScript/Node.js, Java, React.js, TypeScript) to automate security monitoring and compliance audits.\nStrong understanding of OWASP Top 10, secure coding standards, and mitigation of common web vulnerabilities.\nDeploying, tuning, and maintaining WAF solutions tailored to custom applications and traffic patterns.\nConfiguring/managing File Integrity Monitoring (FIM) for web content directories.\nFamiliarity with security testing tools — Wireshark, SIEM, IDS/IPS, NDR, or EDR.\nEvaluating/recommending/implementing security controls for mobile device and mobile-web interfaces.\n\nPerforming complex risk assessments, analyzing cyber threats, and providing remediation guidance for core systems and dependencies.\nImplementing DevSecOps principles — integrating security controls throughout the CI/CD pipeline.\nDeveloping security metrics, managing compliance reporting, and auditing systems against baselines.\nEffective cross-team collaboration and independent work; providing Tier II support for security operations.\n\nEducation:\nBachelor’s degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.\n\nCertification:\nSpecialized AppSec: CSSLP (Certified Secure Software Lifecycle Professional); GWEB (GIAC Certified Web Application Defender); CASE (EC-Council Certified Application Security Engineer).\nOffensive Security: OSWE (OffSec Web Expert); OSCP (Offensive Security Certified Professional).\nFoundational Security: Security+; GSEC.\n\nJoin Our Team:\n\nAt CMT Services, we believe that extraordinary results come from empowering exceptional people. If you're ready to lead innovative projects, solve complex challenges, and contribute to meaningful infrastructure development while advancing your career in a supportive, collaborative environment, we want to hear from you.\n\nDisclaimer:\nBy submitting your resume for this job posting, you authorize CMT Services, Inc. to forward your resume to all applicable internal and external managers, agencies, and recruitment personnel for review and consideration to hire.","datePosted":"2026-08-03T18:57:35.687Z","dateModified":"2026-08-03T18:57:35.687Z","hiringOrganization":{"@type":"Organization","name":"Cmt Services","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"620f4498c029a2e0eb959638"},"url":"https://jobsearcher.com/jobs/620f4498c029a2e0eb959638"}}