Web Developer Security Engineer

Posted 4 Days Ago
Hiring Remotely in Washington, DC, USA
In-Office or Remote
135K-155K Annually
Mid level
Other
The Role
Embed application security across the SDLC: identify and remediate web/API vulnerabilities, perform threat modeling and risk assessments, automate monitoring and remediation, analyze logs for anomalies, support compliance and federal security authorization activities.
Summary Generated by Built In
Company Overview
Spry Methods is a proven provider of mission-focused technology, cybersecurity, and program management solutions supporting critical Federal and DoD missions. We specialize in delivering integrated, high-impact solutions across cyber operations, enterprise resource management, and mission support services. Our culture emphasizes collaboration, accountability, and innovation - empowering our teams to deliver meaningful outcomes in complex, high-security environments. 


Who We’re Looking For (Position Overview):
The Web Developer Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.   

What Your Day-To-Day Looks Like (Position Responsibilities):

    • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs. 

    • Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions. 

    • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services. 

    • Review and analyze web server and application logs to detect anomalies and indicators of compromise. 

    • Implement automation scripts for threat intelligence integration and application security monitoring. 

    • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks. 

What You Need to Succeed (Minimum Requirements):

    • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work. 

    • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation. 

    • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL). 

    • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts. 

    • Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools. 

    • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies. 

    • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field. 

    • Ability to meet federal screening and suitability requirements prior to start. 

    • Current security certifications maintained for a minimum of five years: 

      • Specialized AppSec:
        • Certified Secure Software Lifecyle Professional (CSSLP)
        • GIAC Certified Web Application Defender (GWEB)
        • EC-Council Certified Application Security Engineer (CASE)
        • Offensive Security:
          • OffSec Web Expert (OSWE)
          • Offensive Security Certified Professional (OSCP)
          • Foundational Security:
            • Security+
            • GSEC

Ideally, You Also Have (Preferred Qualifications):

    • In-depth experience with federal cybersecurity frameworks and authorization processes. 

    • Experience with threat modeling, resilient security architecture, cloud security, and container security. 

Perks of Working for Us (Benefits):

Medical Coverage – Cigna - 4 Options

- Traditional - PPO Open Access Plus Network

- (2) HDHP - PPO Open Access Plus Network

- HDHP - EPO Open Access Plus Network

Dental Coverage – Cigna - PPO Base & Buy-Up Plans

Vision Coverage – Principal - VSP Choice Network

Paid Holidays: Full-time employees receive 11 paid federal holidays

Paid Time Off (PTO) – PTO accrual starts at 15 days per year

Training Benefit – Annual training allowance available toward any job-related training or education

401(k) – Multiple Fund Choices through Fidelity with a company match

For our full list of benefits, please visit http://www.sprymethods.com/careers/benefits/

 
EEO Statement
At Spry, we believe talented and dedicated employees are our most valued assets and the foundation of our success. We are committed to crafting a diverse and inclusive workplace that endorses engagement, creativity, quality and innovation.
 
We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.

Skills Required

  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work
  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation
  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, REST APIs, and SQL
  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts
  • Strong understanding of OWASP Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools
  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies
  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field
  • Ability to meet federal screening and suitability requirements prior to start
  • Certified Secure Software Lifecycle Professional (CSSLP) maintained for a minimum of five years
  • GIAC Certified Web Application Defender (GWEB) maintained for a minimum of five years
  • EC-Council Certified Application Security Engineer (CASE) maintained for a minimum of five years
  • OffSec Web Expert (OSWE) maintained for a minimum of five years
  • Offensive Security Certified Professional (OSCP) maintained for a minimum of five years
  • Security+ maintained for a minimum of five years
  • GSEC maintained for a minimum of five years
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: McLean, VA
89 Employees
Year Founded: 2000

What We Do

Spry is a certified Small Business headquartered in McLean, VA. Spry provides Enterprise, C4IT, Management, and Cyber Solutions to the federal government and commercial entities. Founded in 2001, Spry Methods was built on the foundation of combining industry knowledge with unmatched responsiveness to produce results for our customers. Our goal is to build a business dedicated to the maximization of value for all stakeholders starting with our employees, our customers, and our community. We recognize that talented and dedicated employees are our most valued assets and the foundation of our success. Guided by these principles, we have established an impressive track record of proven past performance serving our customers within the Commercial, Federal Civilian, DoD, and Intelligence Communities. A CMMI Level 3 certified and ISO 9001:2008 registered company, Spry is committed to quality and continuous improvement.

Similar Jobs

Wipfli Logo Wipfli

Senior Consultant

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
80K-108K Annually

Wipfli Logo Wipfli

Architect

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
129K-174K Annually

Wipfli Logo Wipfli

Senior Consultant

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
88K-118K Annually
Remote
United States
40 Employees
75K-125K Annually

Similar Companies Hiring

Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account