> Markdown version of [/jobs/ext/640465-web-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/640465-web-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Web Application Security Engineer - **Company:** Essnova Solutions, Inc. - **Location:** Washington, United States - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Application Firewall, Microsoft Azure, DevOps, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Web Application Security, Software Engineering, Systems Integration, Software Vulnerability Management, Web Applications, Spring Cloud, Software Security, Cybercrime, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 25, 2026 - **Apply:** https://www.dice.com/job-detail/fd699b7f-c221-481e-9ff1-bdde16f9bb3f ## About the Role * Experience in Application Security (AppSec), Web Application Security, or Product Security. * Strong knowledge of secure software development practices and Secure SDLC. * Experience performing vulnerability assessments, threat modeling, and application security testing. * Knowledge of OWASP Top 10, common web application vulnerabilities, and remediation techniques. * Experience implementing or supporting Web Application Firewalls (WAF). * Experience integrating security into CI/CD pipelines and DevSecOps environments. * Familiarity with federal cybersecurity frameworks including NIST and FedRAMP. * Excellent analytical, troubleshooting, and communication skills. Preferred Qualifications * Experience with SAST, DAST, Software Composition Analysis (SCA), or similar application security tools. * Experience with secure code reviews and developer security training. * Experience supporting cloud-native applications within AWS and/or Microsoft Azure. * Experience supporting federal government or highly regulated environments. * Relevant security certifications such as: * CSSLP * OSCP * OSWE * GWEB * CASE * Security+ * GSEC Clearance * Public Trust (Tier 2) clearance or the ability to obtain and maintain one.* ## Description Essnova Solutions is seeking an experienced Web Application Security Engineer to support a federal customer by integrating security throughout the software development lifecycle (SDLC) and protecting enterprise web applications and APIs from evolving cyber threats. The ideal candidate has experience with application security, secure software development, vulnerability management, DevSecOps, and federal cybersecurity frameworks. Key Responsibilities * Embed security throughout the Software Development Lifecycle (SDLC). * Perform web application vulnerability assessments, penetration support, and threat modeling activities. * Identify, prioritize, and remediate application security vulnerabilities. * Implement secure coding standards aligned with OWASP Top 10 and industry best practices. * Configure and maintain Web Application Firewalls (WAF) and application security controls. * Integrate application security tools into CI/CD pipelines and DevSecOps workflows. * Monitor application logs and investigate security events affecting web applications and APIs. * Collaborate with software developers, DevOps engineers, and cybersecurity teams to improve application security posture. * Support compliance with NIST, FISMA, FedRAMP, and other federal cybersecurity standards. * Develop security documentation, technical recommendations, and remediation guidance. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)