Web Developer Security Engineer

Elegant Enterprise Wide Solutions
Washington, United States of America
4 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate

Job location

Washington, United States of America

Tech stack

Kubernetes Security
Java
JavaScript
.NET
Multitier Architecture
Amazon Web Services (AWS)
Application Firewall
HTML5
C Sharp (Programming Language)
CSS
Cloud Computing Security
Computer Security
Information Systems
Continuous Integration
DevOps
Human-Computer Interaction
Windows Communication Foundation
Intrusion Detection Systems
Python
MVC
Node.js
Open Web Application Security
Performance Tuning
Secure Coding
Web Application Security
Security Information and Event Management
Software Engineering
SQL Databases
Wireshark
TypeScript
Software Vulnerability Management
Web Applications
Scripting (Bash/Python/Go/Ruby)
GitHub Copilot
React
Software Security
Web Content
Kubernetes
Information Technology
Cybercrime
Web Technologies
Api Design
REST
Devsecops
Docker

Job description

Web Developer Security Engineer who meets the following specific requirements

Requirements

Extensive hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation. Proficiency in logs analysis, file integrity monitoring (FIM), and managing web application firewalls (WAF) to defend against emerging threats. Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec) or secure software development life cycle (SSDLC) Proven developing with modern web technologies and frameworks not limited to .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL Ability to leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript) to automate security monitoring and compliance audits Strong understanding of Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, and proactive mitigation of common web vulnerabilities. Experience deploying, tuning, and maintaining Web Application Firewalls (WAFs) solutions tailored to custom-developed applications and traffic patterns. Strong track record in configuring and managing File Integrity Monitoring (FIM) solutions for web content directories, to detect and alert on unauthorized change. Familiar with security testing tools such as Wireshark, SIEM, IDS/IPS, NDR, or EDR Evaluates, recommends, and implements security controls for mobile device solutions and mobile-web interface. Ability to perform complex risk assessments, analyze cyber threats, and provide remediation guidance for core systems and their dependencies Proven ability to implement DevSecOps principles, seamlessly integrating security controls throughout the CI/CD pipeline Experience developing security metrics, managing compliance reporting, and auditing systems against established security baselines Collaborate effectively across multidisciplinary teams, and work independently as well as in a team Experience providing Tier II support for security operations and recommending continue security enhancements for existing infrastructure. Preferred In-depth experience at Federal cybersecurity frameworks (NIST SP 800-53, FISMA, FedRAMP) authorization process Proven background in threat modeling, risk assessment, and designing resilient security architecture Advanced experience implementing secure DevOps/DevSecOps practices, specifically focus on CI/CD pipeline and automating security gates Knowledge of cloud security AWS and container security (Docker, Kubernetes) Required Education & Credentials: Bachelor's degree (or higher) in computer science, Cybersecurity, Information Systems, Engineering, or a related field. The Consultant must have the following current credentials: Specialized AppSec: o Certified Secure Software Lifecyle Professional (CSSLP) o GIAC Certified Web Application Defender (GWEB) o EC-Council Certified Application Security Engineer (CASE)

These (or their equivalent prior certifications) should have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered

Apply for this position