Washington, DC (Remote)
3 months ago

Job Overview

Job Type
Proposal Position
Pay
Not disclosed

Job description

Location:
Washington, DC (Remote), United States
Work arrangement:
Remote

Web Developer Security Engineer at Sprymethods in Washington, DC (Remote), United States.

Responsibilities

What Your Day-To-Day Looks Like (Position Responsibilities)

  • Identify , analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.
  • Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions.
  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services.
  • Review and analyze web server and application logs to detect anomalies and indicators of compromise.
  • Implement automation scripts for threat intelligence integration and application security monitoring.
  • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks.

Requirements

Who We’re Looking For (Position Overview)

The Web Developer Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.

What You Need to Succeed (Minimum Requirements)

  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work.
  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation.
  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL).
  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts.
  • Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools.
  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies.
  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field.
  • Ability to meet federal screening and suitability requirements prior to start.
  • Current security certifications maintained for a minimum of five years:
  • Specialized AppSec:
  • Certified Secure Software Lifecyle Professional (CSSLP)
  • GIAC Certified Web Application Defender (GWEB)
  • EC-Council Certified Application Security Engineer (CASE)
  • Offensive Security:
  • OffSec Web Expert (OSWE)
  • Offensive Security Certified Professional (OSCP)
  • Foundational Security:
  • Security+
  • GSEC

Ideally, You Also Have (Preferred Qualifications)

  • In-depth experience with federal cybersecurity frameworks and authorization processes.
  • Experience with threat modeling, resilient security architecture, cloud security, and container security.

Benefits

Perks of Working for Us (Benefits)

Medical Coverage – Cigna - 4 Options

  • Traditional - PPO Open Access Plus Network
  • (2) HDHP - PPO Open Access Plus Network
  • HDHP - EPO Open Access Plus Network
  • Dental Coverage – Cigna - PPO Base & Buy-Up Plans
  • Vision Coverage – Principal - VSP Choice Network
  • Paid Holidays: Full-time employees receive 11 paid federal holidays
  • Paid Time Off (PTO) – PTO accrual starts at 15 days per year
  • Training Benefit – Annual training allowance available toward any job-related training or education
  • 401(k) – Multiple Fund Choices through Fidelity with a company match
  • For our full list of benefits, please visit http://www.sprymethods.com/careers/benefits/

Additional Information

At Spry, we believe talented and dedicated employees are our most valued assets and the foundation of our success. We are committed to crafting a diverse and inclusive workplace that endorses engagement, creativity, quality and innovation.

We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.

Role:
Web Developer Security Engineer
Job Type:
Proposal Position

Company profile

Sprymethods

sprymethods.com

Spry Methods provides cyber security, platform services, national security and IT strategy and modernization services to the federal government and commercial entities. Its customers include federal civilian agencies, the Department of Defense, law enforcement and the Intelligence Community, which it supports across intelligence disciplines such as OSINT, HUMINT, SIGINT and GEOINT. It also offers DevSecOps, enterprise architecture and cloud solutions. Founded in 2001, Spry is ISO 9001:2015, ISO/IEC 20000-1:2018 and ISO/IEC 27001:2013 registered and CMMI-SVC ML3 rated.

Founded
2001

More jobs at Sprymethods

Similar Security Engineer jobs at other companies