Web Developer Security Engineer

Nationwide IT Service, Inc.
Washington, DC, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) .NET Framework Multitier Architecture Application Programming Interfaces (APIs) Amazon Web Services Application Firewall ASP.NET MVC Framework HTML5 C Sharp (Programming Language) Cascading Style Sheets (CSS) Cloud Computing
+33 more
Cloud Engineering Cyber Security Information Systems Computer Programming Databases Windows Communication Foundation Intrusion Detection Systems Python (Programming Language) Log Analysis Node.Js Open Web Application Security Performance Tuning Systems Development Life Cycle Standard Sql Secure Coding Web Application Security Security Software Security Information and Event Management Software Engineering Systems Integration TypeScript Software Vulnerability Management Web Applications GitHub Copilot ReactJS Software Security Kubernetes Information Technology Front End Software Development Restful APIs Devsecops Docker Vulnerability Analysis

Job description

Position Overview: Nationwide IT Services (NIS) is seeking a Web Developer Security Engineer to support application security initiatives across web applications, APIs, and the software development lifecycle (SDLC). The selected candidate will be responsible for secure application design, vulnerability management, DevSecOps integration, security monitoring, WAF administration, File Integrity Monitoring (FIM), and Tier II security operations support., * Perform application security reviews and threat modeling.

  • Conduct vulnerability assessments and oversee remediation efforts.
  • Implement and maintain security controls within CI/CD pipelines.
  • Configure and tune WAF and File Integrity Monitoring solutions.
  • Analyze logs, investigate security events, and support incident response activities.
  • Collaborate with development teams to ensure secure coding practices.
  • Support compliance, audit, and security authorization requirements.

Requirements

  • Minimum 3 years of experience in Application Security and Secure Software Development Lifecycle (SSDLC).
  • Strong knowledge of web application security principles and OWASP Top 10 vulnerabilities.
  • Experience managing the full vulnerability lifecycle, including threat modeling, security assessments, remediation, and validation.
  • Experience with secure application design, architecture reviews, data protection, and secure communications.
  • Hands-on experience with Web Application Firewall (WAF) deployment, configuration, and tuning.
  • Experience with File Integrity Monitoring (FIM), log analysis, Indicators of Compromise (IOC) detection, and threat intelligence automation.
  • Experience supporting Tier II Security Operations.
  • Experience implementing DevSecOps practices and automated security controls within CI/CD pipelines.

Technical Skills:

  • .NET Technologies: C#, ASP.NET MVC, WCF
  • Front-End: HTML5, CSS3, JavaScript, React, TypeScript
  • APIs & Databases: REST APIs, SQL
  • Programming/Scripting: Python, Node.js, Java
  • AI-Assisted Development Tools (e.g., GitHub Copilot)
  • Security Tools: SIEM, IDS/IPS, NDR, EDR
  • Cloud & Container Security: AWS, Docker, Kubernetes

Compliance & Governance:

  • Experience supporting environments governed by NIST SP 800-53, FISMA, and FedRAMP.
  • Experience participating in audits, security assessments, and authorization activities.

Education:

  • Bachelor’s degree or higher in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field. *, * Experience securing federal government applications and systems.

  • Experience integrating security controls into modern CI/CD pipelines.
  • Strong understanding of cloud-native and containerized application security.

About the company

Working at NIS means being part of a company grounded in purpose, resilience, and a genuine commitment to people. Since its founding in 2006, NIS has focused not only on delivering exceptional services to our government customers, but also supporting our nation, taxpayers, and citizens-while consistently prioritizing the well-being and growth of its employees. Today, NIS continues to evolve by embracing remote work, enhancing wellness initiatives, and investing in modern technology, all while staying true to its mission.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:44 min

Playing synthesized backend audio objects in browsers

Lee Boonstra · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

45 sec

Working securely with Node.js path application programming interfaces

Sonya Moisset · WWC 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:03 min

Building robust applications with standard web platforms

Dennie Declercq · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all