Web Application Security Engineer (AppSec / DevSecOps)

Essnova Solutions, Inc.

Washington (Washington County)

Hybrid

USD 110,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Essnova Solutions, Inc. is seeking an experienced Web Application Security Engineer to support a federal customer by embedding security across the SDLC and protecting enterprise web apps and APIs from evolving cyber threats.

The candidate should have hands-on experience with secure SDLC, vulnerability assessments, threat modeling, and CI/CD integration in DevSecOps environments. Federal framework familiarity is required.

Qualifications

  • Experience in Application Security (AppSec), Web Application Security, or Product Security.
  • Strong knowledge of secure software development practices and Secure SDLC.
  • Experience performing vulnerability assessments, threat modeling, and application security testing.
  • Knowledge of OWASP Top 10, common web application vulnerabilities, and remediation techniques.
  • Experience implementing or supporting Web Application Firewalls (WAF).
  • Experience integrating security into CI/CD pipelines and DevSecOps environments.
  • Familiarity with federal cybersecurity frameworks including NIST and FedRAMP.
  • Excellent analytical, troubleshooting, and communication skills.

Responsibilities

  • Embed security throughout the Software Development Lifecycle (SDLC).
  • Perform web application vulnerability assessments, penetration support, and threat modeling activities.
  • Identify, prioritize, and remediate application security vulnerabilities.
  • Implement secure coding standards aligned with OWASP Top 10 and industry best practices.
  • Configure and maintain Web Application Firewalls (WAF) and application security controls.
  • Integrate application security tools into CI/CD pipelines and DevSecOps workflows.
  • Monitor application logs and investigate security events affecting web applications and APIs.
  • Collaborate with software developers, DevOps engineers, and cybersecurity teams to improve application security posture.
  • Support compliance with NIST, FISMA, FedRAMP, and other federal cybersecurity standards.

Skills

Web Application Security
AppSec
Secure SDLC
Vulnerability assessment
Threat modeling
OWASP Top 10
CI/CD integration
DevSecOps
Analytical skills

Education

CSSLP
OSCP
OSWE
GWEB
CASE
Security+
GSEC

Tools

Web Application Firewall (WAF)
SAST
DAST
SCA
CI/CD tooling

Job description

Location: Washington, DC Metropolitan Area (Hybrid)

Employment Type: Full-Time

Clearance: Public Trust (Tier 2) or ability to obtain*

About Essnova Solutions

Essnova Solutions is a growing technology consulting firm delivering innovative IT, cloud, cybersecurity, engineering, and digital transformation solutions to Federal Government clients. We are committed to technical excellence, collaboration, and providing our employees with opportunities to solve complex mission challenges.

Position Summary

Essnova Solutions is seeking an experienced Web Application Security Engineer to support a federal customer by integrating security throughout the software development lifecycle (SDLC) and protecting enterprise web applications and APIs from evolving cyber threats. The ideal candidate has experience with application security, secure software development, vulnerability management, DevSecOps, and federal cybersecurity frameworks.

Key Responsibilities
  • Embed security throughout the Software Development Lifecycle (SDLC).
  • Perform web application vulnerability assessments, penetration support, and threat modeling activities.
  • Identify, prioritize, and remediate application security vulnerabilities.
  • Implement secure coding standards aligned with OWASP Top 10 and industry best practices.
  • Configure and maintain Web Application Firewalls (WAF) and application security controls.
  • Integrate application security tools into CI/CD pipelines and DevSecOps workflows.
  • Monitor application logs and investigate security events affecting web applications and APIs.
  • Collaborate with software developers, DevOps engineers, and cybersecurity teams to improve application security posture.
  • Support compliance with NIST, FISMA, FedRAMP, and other federal cybersecurity standards.
Required Qualifications
  • Experience in Application Security (AppSec), Web Application Security, or Product Security.
  • Strong knowledge of secure software development practices and Secure SDLC.
  • Experience performing vulnerability assessments, threat modeling, and application security testing.
  • Knowledge of OWASP Top 10, common web application vulnerabilities, and remediation techniques.
  • Experience implementing or supporting Web Application Firewalls (WAF).
  • Experience integrating security into CI/CD pipelines and DevSecOps environments.
  • Familiarity with federal cybersecurity frameworks including NIST and FedRAMP.
  • Excellent analytical, troubleshooting, and communication skills.
Preferred Qualifications
  • Experience with SAST, DAST, Software Composition Analysis (SCA), or similar application security tools.
  • Experience with secure code reviews and developer security training.
  • Experience supporting cloud-native applications within AWS and/or Microsoft Azure.
  • Experience supporting federal government or highly regulated environments.
  • Relevant security certifications such as:
    • CSSLP
    • OSCP
    • OSWE
    • GWEB
    • CASE
    • Security+
    • GSEC
Clearance
  • Public Trust (Tier 2) clearance or the ability to obtain and maintain one.*
Why Join Essnova?

At Essnova Solutions, you’ll join a collaborative team supporting high-impact federal technology initiatives. We invest in our employees by providing opportunities to work with modern cloud technologies, cybersecurity best practices, and mission-critical systems that make a real difference.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Web Developer Security Engineer
Web Developer Security Engineer

Nationwide IT Services • Washington

Hybrid
USD 100,000 - 120,000
Senior Microsoft Cloud Engineer
Senior Microsoft Cloud Engineer

Essnova Solutions, Inc. • Washington

Hybrid
USD 120,000 - 150,000
Web App Security Engineer • DevSecOps (Hybrid)
Web App Security Engineer • DevSecOps (Hybrid)

Essnova Solutions, Inc. • Washington

Hybrid
USD 110,000 - 160,000
Application Security Engineer
Application Security Engineer

Eliassen Group • Washington

On-site
USD 90,000 - 120,000
Application Security Engineer
Application Security Engineer

Method, Inc. • Washington

On-site
USD 135,000 - 155,000
Medical Coverage
Dental Coverage
Vision Coverage
+4
Lead Security Engineer
Lead Security Engineer

Dev Technology • Suitland (MD)

On-site
USD 120,000 - 190,000
Generous time-off policy
Flexible work schedules
401K matching
+1
Application Security Engineer
Application Security Engineer

Spry Methods, Inc. • Washington

On-site
USD 120,000 - 160,000
Medical coverage
Dental coverage
Vision coverage
+4
Web Developer Security Engineer (SMA 4)
Web Developer Security Engineer (SMA 4)

E Logic • Washington

On-site
USD 120,000 - 160,000
Information Technology Security Specialist
Information Technology Security Specialist

Seneca Resources • Virginia (MN)

Remote
USD 120,000 - 160,000
Competitive pay
Health, dental, and vision coverage
401(k) retirement plans
+1
Application Security Engineer
Application Security Engineer

IPolarity • Hanover Township (NJ)

On-site
USD 68,000 - 97,000