Web Developer Security Engineer (SMA 4)

E-Logic INC
Washington, DC, United States
29 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Java (Programming Language) JavaScript (Programming Language) .NET Framework Application Programming Interfaces (APIs) Amazon Web Services Application Firewall HTML5 C Sharp (Programming Language) Cascading Style Sheets (CSS) Cloud Computing Security Cyber Security
+32 more
Information Systems Continuous Integration DevOps Web Servers Windows Communication Foundation Intrusion Detection Systems Python (Programming Language) Model View Controller (MVC) Node.Js Open Web Application Security Systems Development Life Cycle Standard Sql Secure Coding Web Application Security Security Information and Event Management Software Engineering Wireshark TypeScript Web Applications Scripting Cloud Platform System GitHub Copilot ReactJS Software Security Kubernetes Information Technology Sentry Web Technologies Api Design Restful APIs Devsecops Docker

Job description

We are looking for a highly skilled and proactive Web Developer Security Engineer to join our team supporting the Congressional Budget Office (CBO) under the SENTRY Blanket Purchase Agreement (BPA). As a Web Developer Security Engineer, you will play a pivotal role in protecting mission-critical web applications, APIs, and sensitive data. You will embed robust security principles throughout the software development lifecycle (SDLC) to build security as a proactive, foundational pillar. You will identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations, and drive the end-to-end vulnerability lifecycle., * Web Application Security: Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.

  • Vulnerability Lifecycle: Drive the end-to-end vulnerability lifecycle-integrating proactive threat modeling and advanced security assessments, ensuring remediation integrity through rigorous technical validation.
  • Secure Design: Support integration of security controls into application architectures, APIs, and supporting services; advise on secure design patterns, data protection mechanisms, and secure communication protocols.
  • Monitoring & Incident Response: Obtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise; support the end-to-end response to web application security events.
  • Automation: Implement automation scripts for threat intelligence integration to optimize alert accuracy; leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting languages (Python, JavaScript/Node.js) to automate security monitoring and compliance audits.
  • Compliance: Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks, including NIST SP 800-53, FISMA, and FedRAMP (as applicable); participate in audits, risk assessments, and security authorization processes.

Requirements

  • Certifications: Must hold at least one certification from each of the following three categories:
  • Specialized AppSec: CSSLP, GWEB, or CASE
  • Offensive Security: OSWE or OSCP
  • Foundational Security: Security+ or GSEC
  • Certifications must have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.
  • Clearance: Must be eligible to obtain and maintain a Public Trust Tier 2 clearance (background check conducted through U.S. Capitol Police).
  • Experience: Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC).
  • Technical Proficiency: Demonstrated hands-on experience with:
  • Modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL
  • AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex)
  • Scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript)
  • Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions
  • Security testing tools (Wireshark, SIEM, IDS/IPS, NDR, EDR)
  • Security Knowledge: Strong understanding of OWASP Top 10, secure coding standards, and proactive mitigation of common web vulnerabilities.

Desired Experience:

  • Bachelor’s degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.
  • In-depth experience with federal cybersecurity frameworks (NIST SP 800-53, FISMA, FedRAMP) authorization processes.
  • Proven background in threat modeling, risk assessment, and designing resilient security architecture.
  • Experience implementing secure DevOps/DevSecOps practices, specifically CI/CD pipeline and automating security gates.
  • Knowledge of cloud security (AWS) and container security (Docker, Kubernetes).

Clearance Requirement: Must be eligible for a Public Trust Tier 2

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:44 min

Playing synthesized backend audio objects in browsers

Lee Boonstra · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:22 min

Overview of the Sentry error and performance monitoring platform

Priscila Oliveira · World Congress 2023

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

3:21 min

Installing and configuring the Sentry JavaScript SDK for applications

Priscila Oliveira · World Congress 2023

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

Videos

See all

Related articles

See all