Web Developer Security Engineer

Stralynn Consulting Services, Inc.
Ashburn, VA, United States
about 1 month ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Web Interfaces Kubernetes Security Java (Programming Language) JavaScript (Programming Language) .NET Framework Multitier Architecture Application Programming Interfaces (APIs) Amazon Web Services Application Firewall HTML5 C Sharp (Programming Language) Cascading Style Sheets (CSS)
+30 more
Cloud Computing Security Cyber Security Information Systems Monitoring of Systems Windows Communication Foundation Intrusion Detection Systems Python (Programming Language) Model View Controller (MVC) Node.Js Open Web Application Security Systems Development Life Cycle Secure Coding Web Application Security Security Information and Event Management Software Engineering SQL Databases Wireshark TypeScript Software Vulnerability Management Web Applications Scripting Cloud Platform System ReactJS Software Security Kubernetes Information Technology Cybercrime Web Technologies Restful APIs Docker

Job description

We are seeking an experienced Web Developer Security Engineer to serve as Key Personnel in protecting mission-critical web applications, APIs, and sensitive data. In this critical role, you will embed robust security principles throughout the Software Development Lifecycle (SDLC) to build security as a proactive, foundational pillar. You will act as the bridge between application development and cybersecurity, ensuring our applications are secure by design, compliant with federal frameworks, and resilient against evolving threats., + Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.

  • Drive the end-to-end vulnerability lifecycle by integrating proactive threat modeling and advanced security assessments.

  • Actively support the end-to-end response to web application security events.

  • Deploy, tune, and maintain Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions.

  • Maintain meticulous documentation of findings, remediation steps, and security controls.

  • Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks (NIST SP 800-53, FISMA, and FedRAMP).

  • Perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and dependencies.

  • Evaluate, recommend, and implement security controls for mobile device solutions and mobile-web interfaces.

  • Participate in audits and security authorization processes.

Requirements

Experience & Technical Skills:

  • Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC).

  • Proven development experience with modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL.

  • Proficiency with scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript).

  • Strong understanding of the OWASP Top 10, secure coding standards, and vulnerability mitigation.

  • Hands-on experience with security testing and monitoring tools (Wireshark, SIEM, IDS/IPS, NDR, EDR).

  • Experience providing Tier II support for security operations.

Education & Mandatory Credentials:

  • Education: Bachelor’s degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.

  • Certifications: Candidates must hold at least one of the following current certifications:

  • Specialized AppSec: CSSLP, GWEB, or EC-Council CASE

  • Offensive Security: OSWE or OSCP

  • Foundational Security: Security+ or GSEC

  • CRITICAL REQUIREMENT: The required certification (or its prior equivalent) must have been maintained for a minimum of 5 years . Expired certifications or certifications never used professionally will not be considered.

Preferred Qualifications

  • In-depth experience with Federal cybersecurity authorization processes (NIST SP 800-53, FISMA, FedRAMP).

  • Proven background in threat modeling, risk assessment, and designing resilient security architecture.

  • Advanced experience automating security gates within CI/CD pipelines.

  • Knowledge of cloud security (AWS) and container security (Docker, Kubernetes).

Powered by JazzHR

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:44 min

Playing synthesized backend audio objects in browsers

Lee Boonstra · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:21 min

Exploring the target application for front end tests

Anna Mcdougall · JS Congress

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:03 min

Building robust applications with standard web platforms

Dennie Declercq · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all