> Markdown version of [/jobs/ext/611220-web-developer-security-engineer](https://www.wearedevelopers.com/jobs/ext/611220-web-developer-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Web Developer Security Engineer - **Company:** Nationwide IT Service, Inc. - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), .NET Framework, Multitier Architecture, Application Programming Interfaces (APIs), Amazon Web Services, Application Firewall, ASP.NET MVC Framework, HTML5, C Sharp (Programming Language), Cascading Style Sheets (CSS), Cloud Computing, Cloud Engineering, Cyber Security, Information Systems, Computer Programming, Databases, Windows Communication Foundation, Intrusion Detection Systems, Python (Programming Language), Log Analysis, Node.Js, Open Web Application Security, Performance Tuning, Systems Development Life Cycle, Standard Sql, Secure Coding, Web Application Security, Security Software, Security Information and Event Management, Software Engineering, Systems Integration, TypeScript, Software Vulnerability Management, Web Applications, GitHub Copilot, ReactJS, Software Security, Kubernetes, Information Technology, Front End Software Development, Restful APIs, Devsecops, Docker, Vulnerability Analysis - **Published:** June 24, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8992739/web-developer-security-engineer ## About the Role * Minimum 3 years of experience in Application Security and Secure Software Development Lifecycle (SSDLC). * Strong knowledge of web application security principles and OWASP Top 10 vulnerabilities. * Experience managing the full vulnerability lifecycle, including threat modeling, security assessments, remediation, and validation. * Experience with secure application design, architecture reviews, data protection, and secure communications. * Hands-on experience with Web Application Firewall (WAF) deployment, configuration, and tuning. * Experience with File Integrity Monitoring (FIM), log analysis, Indicators of Compromise (IOC) detection, and threat intelligence automation. * Experience supporting Tier II Security Operations. * Experience implementing DevSecOps practices and automated security controls within CI/CD pipelines. Technical Skills: * .NET Technologies: C#, ASP.NET MVC, WCF * Front-End: HTML5, CSS3, JavaScript, React, TypeScript * APIs & Databases: REST APIs, SQL * Programming/Scripting: Python, Node.js, Java * AI-Assisted Development Tools (e.g., GitHub Copilot) * Security Tools: SIEM, IDS/IPS, NDR, EDR * Cloud & Container Security: AWS, Docker, Kubernetes Compliance & Governance: * Experience supporting environments governed by NIST SP 800-53, FISMA, and FedRAMP. * Experience participating in audits, security assessments, and authorization activities. Education: * Bachelor's degree or higher in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field. *, * Experience securing federal government applications and systems. * Experience integrating security controls into modern CI/CD pipelines. * Strong understanding of cloud-native and containerized application security. ## Description Position Overview: Nationwide IT Services (NIS) is seeking a Web Developer Security Engineer to support application security initiatives across web applications, APIs, and the software development lifecycle (SDLC). The selected candidate will be responsible for secure application design, vulnerability management, DevSecOps integration, security monitoring, WAF administration, File Integrity Monitoring (FIM), and Tier II security operations support., * Perform application security reviews and threat modeling. * Conduct vulnerability assessments and oversee remediation efforts. * Implement and maintain security controls within CI/CD pipelines. * Configure and tune WAF and File Integrity Monitoring solutions. * Analyze logs, investigate security events, and support incident response activities. * Collaborate with development teams to ensure secure coding practices. * Support compliance, audit, and security authorization requirements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Stop Using Node.js Like It’s 2020! - Alfonso Graziano](https://www.wearedevelopers.com/videos/1863-stop-using-node-js-like-it-s-2020-alfonso-graziano) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)