> Markdown version of [/jobs/ext/2580338-web-developer-security-engineer](https://www.wearedevelopers.com/jobs/ext/2580338-web-developer-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Web Developer Security Engineer - **Company:** Stralynn Consulting Services, Inc. - **Location:** Ashburn, VA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Web Interfaces, Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), .NET Framework, Multitier Architecture, Application Programming Interfaces (APIs), Amazon Web Services, Application Firewall, HTML5, C Sharp (Programming Language), Cascading Style Sheets (CSS), Cloud Computing Security, Cyber Security, Information Systems, Monitoring of Systems, Windows Communication Foundation, Intrusion Detection Systems, Python (Programming Language), Model View Controller (MVC), Node.Js, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Web Application Security, Security Information and Event Management, Software Engineering, SQL Databases, Wireshark, TypeScript, Software Vulnerability Management, Web Applications, Scripting, Cloud Platform System, ReactJS, Software Security, Kubernetes, Information Technology, Cybercrime, Web Technologies, Restful APIs, Docker - **Published:** August 3, 2026 - **Apply:** https://www.juju.com/job/00000000glsnz4 ## About the Role Experience & Technical Skills: + Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC). + Proven development experience with modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL. + Proficiency with scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript). + Strong understanding of the OWASP Top 10, secure coding standards, and vulnerability mitigation. + Hands-on experience with security testing and monitoring tools (Wireshark, SIEM, IDS/IPS, NDR, EDR). + Experience providing Tier II support for security operations. Education & Mandatory Credentials: + Education: Bachelor's degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field. + Certifications: Candidates must hold at least one of the following current certifications: + Specialized AppSec: CSSLP, GWEB, or EC-Council CASE + Offensive Security: OSWE or OSCP + Foundational Security: Security+ or GSEC + CRITICAL REQUIREMENT: The required certification (or its prior equivalent) must have been maintained for a minimum of 5 years . Expired certifications or certifications never used professionally will not be considered. Preferred Qualifications + In-depth experience with Federal cybersecurity authorization processes (NIST SP 800-53, FISMA, FedRAMP). + Proven background in threat modeling, risk assessment, and designing resilient security architecture. + Advanced experience automating security gates within CI/CD pipelines. + Knowledge of cloud security (AWS) and container security (Docker, Kubernetes). Powered by JazzHR ## Description We are seeking an experienced Web Developer Security Engineer to serve as Key Personnel in protecting mission-critical web applications, APIs, and sensitive data. In this critical role, you will embed robust security principles throughout the Software Development Lifecycle (SDLC) to build security as a proactive, foundational pillar. You will act as the bridge between application development and cybersecurity, ensuring our applications are secure by design, compliant with federal frameworks, and resilient against evolving threats., + Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations. + Drive the end-to-end vulnerability lifecycle by integrating proactive threat modeling and advanced security assessments. + Actively support the end-to-end response to web application security events. + Deploy, tune, and maintain Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions. + Maintain meticulous documentation of findings, remediation steps, and security controls. + Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks (NIST SP 800-53, FISMA, and FedRAMP). + Perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and dependencies. + Evaluate, recommend, and implement security controls for mobile device solutions and mobile-web interfaces. + Participate in audits and security authorization processes. ## Related Videos - [Watch Tests Go Brrrr! : Getting Started with Cypress in ReactJS](https://www.wearedevelopers.com/videos/282-watch-tests-go-brrrr-getting-started-with-cypress-in-reactjs) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)