{"schemaVersion":"jobsearcher.job.v1","id":"7cbbac9751874c8b05d95fe0","url":"https://jobsearcher.com/jobs/7cbbac9751874c8b05d95fe0","canonicalUrl":"https://jobsearcher.com/jobs/7cbbac9751874c8b05d95fe0","title":"Web Developer Security Engineer","description":"About the Role\nWe are seeking an experienced Web Developer Security Engineer to serve as Key Personnel in protecting mission-critical web applications, APIs, and sensitive data. In this critical role, you will embed robust security principles throughout the Software Development Lifecycle (SDLC) to build security as a proactive, foundational pillar. You will act as the bridge between application development and cybersecurity, ensuring our applications are secure by design, compliant with federal frameworks, and resilient against evolving threats.\nKey Responsibilities\nIdentify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.\nDrive the end-to-end vulnerability lifecycle by integrating proactive threat modeling and advanced security assessments.\nActively support the end-to-end response to web application security events.\nDeploy, tune, and maintain Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions.\nMaintain meticulous documentation of findings, remediation steps, and security controls.\nEnsure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks (NIST SP 800-53, FISMA, and FedRAMP).\nPerform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and dependencies.\nEvaluate, recommend, and implement security controls for mobile device solutions and mobile-web interfaces.\nParticipate in audits and security authorization processes.\nRequired Qualifications\nExperience & Technical Skills:\nMinimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC).\nProven development experience with modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL.\nProficiency with scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript).\nStrong understanding of the OWASP Top 10, secure coding standards, and vulnerability mitigation.\nHands-on experience with security testing and monitoring tools (Wireshark, SIEM, IDS/IPS, NDR, EDR).\nExperience providing Tier II support for security operations.\nEducation & Mandatory Credentials:\nEducation: Bachelor’s degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.\nCertifications: Candidates must hold at least one of the following current certifications:\nSpecialized AppSec: CSSLP, GWEB, or EC-Council CASE\nOffensive Security: OSWE or OSCP\nFoundational Security: Security+ or GSEC\nCRITICAL REQUIREMENT: The required certification (or its prior equivalent) must have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.\nPreferred Qualifications\nIn-depth experience with Federal cybersecurity authorization processes (NIST SP 800-53, FISMA, FedRAMP).\nProven background in threat modeling, risk assessment, and designing resilient security architecture.\nAdvanced experience automating security gates within CI/CD pipelines.\nKnowledge of cloud security (AWS) and container security (Docker, Kubernetes).\n\nuNOtPN27RM","company":"Stralynn Consulting Services","rawCompany":"stralynn consulting services","city":"Ashburn","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-08-06T09:45:27.656Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1254.00","title":"Web Developers","slug":"web-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Web Developer Security Engineer","description":"About the Role\nWe are seeking an experienced Web Developer Security Engineer to serve as Key Personnel in protecting mission-critical web applications, APIs, and sensitive data. In this critical role, you will embed robust security principles throughout the Software Development Lifecycle (SDLC) to build security as a proactive, foundational pillar. You will act as the bridge between application development and cybersecurity, ensuring our applications are secure by design, compliant with federal frameworks, and resilient against evolving threats.\nKey Responsibilities\nIdentify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.\nDrive the end-to-end vulnerability lifecycle by integrating proactive threat modeling and advanced security assessments.\nActively support the end-to-end response to web application security events.\nDeploy, tune, and maintain Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions.\nMaintain meticulous documentation of findings, remediation steps, and security controls.\nEnsure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks (NIST SP 800-53, FISMA, and FedRAMP).\nPerform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and dependencies.\nEvaluate, recommend, and implement security controls for mobile device solutions and mobile-web interfaces.\nParticipate in audits and security authorization processes.\nRequired Qualifications\nExperience & Technical Skills:\nMinimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC).\nProven development experience with modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL.\nProficiency with scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript).\nStrong understanding of the OWASP Top 10, secure coding standards, and vulnerability mitigation.\nHands-on experience with security testing and monitoring tools (Wireshark, SIEM, IDS/IPS, NDR, EDR).\nExperience providing Tier II support for security operations.\nEducation & Mandatory Credentials:\nEducation: Bachelor’s degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.\nCertifications: Candidates must hold at least one of the following current certifications:\nSpecialized AppSec: CSSLP, GWEB, or EC-Council CASE\nOffensive Security: OSWE or OSCP\nFoundational Security: Security+ or GSEC\nCRITICAL REQUIREMENT: The required certification (or its prior equivalent) must have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.\nPreferred Qualifications\nIn-depth experience with Federal cybersecurity authorization processes (NIST SP 800-53, FISMA, FedRAMP).\nProven background in threat modeling, risk assessment, and designing resilient security architecture.\nAdvanced experience automating security gates within CI/CD pipelines.\nKnowledge of cloud security (AWS) and container security (Docker, Kubernetes).\n\nuNOtPN27RM","datePosted":"2026-08-06T09:45:27.656Z","dateModified":"2026-08-06T09:45:27.656Z","hiringOrganization":{"@type":"Organization","name":"Stralynn Consulting Services","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Ashburn","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"7cbbac9751874c8b05d95fe0"},"url":"https://jobsearcher.com/jobs/7cbbac9751874c8b05d95fe0"}}