Web Application Security Engineer (AppSec / DevSecOps)
Core
Integrating security throughout the software development lifecycle (SDLC) to protect enterprise web applications and APIs from cyber threats for federal government clients.
Role type
Web Application Security Engineer (AppSec / DevSecOps)
Builds
Secure web applications and APIs within federal environments
Domain
Federal Government Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Secure SDLC implementation, web application vulnerability assessment, threat modeling, OWASP Top 10 remediation, Web Application Firewall (WAF) configuration, CI/CD pipeline security integration, federal cybersecurity framework compliance (NIST, FISMA, FedRAMP)
Preferred skills
SAST/DAST/SCA tool usage, secure code review, cloud-native application support (AWS/Azure), federal environment experience
Technologies
WAF, CI/CD pipelines, AWS, Microsoft Azure, NIST, FISMA, FedRAMP
Responsibilities
Embed security in SDLC, perform vulnerability assessments and threat modeling, identify and remediate vulnerabilities, configure WAFs, integrate security tools into CI/CD, monitor logs and investigate events, support compliance with federal standards, develop security documentation
Seniority
Mid-to-Senior, hands-on IC