CareerPlanGet AI match score →

Web Application Security Engineer (AppSec / DevSecOps)

Washington, District of Columbia, United States💼 Full-time🗓 2026-06-23 → 2026-07-31

Core

Integrating security throughout the software development lifecycle (SDLC) to protect enterprise web applications and APIs from cyber threats for federal government clients.

Role type

Web Application Security Engineer (AppSec / DevSecOps)

Builds

Secure web applications and APIs within federal environments

Domain

Federal Government Cybersecurity

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Secure SDLC implementation, web application vulnerability assessment, threat modeling, OWASP Top 10 remediation, Web Application Firewall (WAF) configuration, CI/CD pipeline security integration, federal cybersecurity framework compliance (NIST, FISMA, FedRAMP)

Preferred skills

SAST/DAST/SCA tool usage, secure code review, cloud-native application support (AWS/Azure), federal environment experience

Technologies

WAF, CI/CD pipelines, AWS, Microsoft Azure, NIST, FISMA, FedRAMP

Responsibilities

Embed security in SDLC, perform vulnerability assessments and threat modeling, identify and remediate vulnerabilities, configure WAFs, integrate security tools into CI/CD, monitor logs and investigate events, support compliance with federal standards, develop security documentation

Seniority

Mid-to-Senior, hands-on IC

Sourced via workable · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on Workable ↗