> Markdown version of [/jobs/ext/1275359-web-developer-security-engineer](https://www.wearedevelopers.com/jobs/ext/1275359-web-developer-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Web Developer Security Engineer - **Company:** Cmt Services, Inc. - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Web Interfaces, Java (Programming Language), JavaScript (Programming Language), Multitier Architecture, Application Programming Interfaces (APIs), Application Firewall, Cloud Computing, Cyber Security, Information Systems, System Configuration, Continuous Integration, Custom Software, Web Servers, Intrusion Detection Systems, Python (Programming Language), Log Analysis, Node.Js, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Web Application Security, Security Information and Event Management, Software Engineering, Wireshark, TypeScript, Software Vulnerability Management, Web Applications, Scripting, GitHub Copilot, ReactJS, Software Security, Web Content, Information Technology, Cybercrime, Api Design, Devsecops - **Published:** July 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0927c2d9913b6a8c ## About the Role * Extensive hands-on secure software development, DevSecOps automation, and vulnerability remediation. * Proficiency in log analysis, file integrity monitoring (FIM), and managing web application firewalls (WAF). * Minimum 3 years in Web Application Security, AppSec, or secure SDLC (SSDLC)., * Bachelor's degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field. ## Description Protects CBO's mission-critical web applications, APIs, and sensitive data by embedding strong security throughout the software development lifecycle - making security a proactive, built-in part of design and delivery., * Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations. * Drive the end-to-end vulnerability lifecycle - proactive threat modeling, advanced security assessments, and remediation validation. * Support integration of security controls into application architectures, APIs, and services; advise on secure design patterns, data protection, and secure communication protocols. * Obtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise. * Implement automation scripts for threat-intelligence integration; support end-to-end response to web application security events. * Maintain documentation of findings, remediation steps, and security controls. * Ensure web applications and cloud infrastructure comply with NIST SP 800-53, FISMA, and FedRAMP (as applicable); participate in audits, risk assessments, and authorization., * Ability to leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting (Python, JavaScript/Node.js, Java, React.js, TypeScript) to automate security monitoring and compliance audits. * Strong understanding of OWASP Top 10, secure coding standards, and mitigation of common web vulnerabilities. * Deploying, tuning, and maintaining WAF solutions tailored to custom applications and traffic patterns. * Configuring/managing File Integrity Monitoring (FIM) for web content directories. * Familiarity with security testing tools - Wireshark, SIEM, IDS/IPS, NDR, or EDR. * Evaluating/recommending/implementing security controls for mobile device and mobile-web interfaces. * Performing complex risk assessments, analyzing cyber threats, and providing remediation guidance for core systems and dependencies. * Implementing DevSecOps principles - integrating security controls throughout the CI/CD pipeline. * Developing security metrics, managing compliance reporting, and auditing systems against baselines. * Effective cross-team collaboration and independent work; providing Tier II support for security operations., * Specialized AppSec: CSSLP (Certified Secure Software Lifecycle Professional); GWEB (GIAC Certified Web Application Defender); CASE (EC-Council Certified Application Security Engineer). * Offensive Security: OSWE (OffSec Web Expert); OSCP (Offensive Security Certified Professional). * Foundational Security: Security+; GSEC. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)