Application Security Engineer

Spry Methods, Inc.

Washington (District of Columbia)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical coverage
Dental coverage
Vision coverage
Paid holidays
PTO
Training benefit
401(k)

Job summary

Spry Methods, Inc. seeks an Application Security Engineer to protect mission-critical web applications, APIs, and data across the software development lifecycle in federal environments.

You will lead vulnerability remediation, threat modeling, security monitoring, and compliance activities, leveraging .NET, HTML5, CSS3, JavaScript, REST APIs, and SQL. Expect OWASP Top 10 guidance, secure coding practices, and DevSecOps integration within a high-security program.

Qualifications

  • Minimum 3 years of web application security experience.
  • Hands-on secure software development and DevSecOps automation.
  • Proven experience with .NET, HTML5, CSS3, JavaScript, REST APIs, and SQL.
  • Ability to use AI-assisted development tools to automate monitoring and compliance.
  • Strong knowledge of OWASP Top 10, secure coding, WAFs, FIM, and security testing tools.
  • Ability to perform risk assessments and provide remediation guidance.
  • Bachelor's degree or higher in CS, cybersecurity, information systems, engineering, or related field.
  • Ability to meet federal screening and suitability requirements.

Responsibilities

  • Identify, analyze, and remediate vulnerabilities in web apps and APIs.
  • Drive vulnerability lifecycle through threat modeling and security assessments.
  • Support secure design, data protection, and secure communication across apps.
  • Review logs to detect anomalies and indicators of compromise.
  • Implement automation scripts for threat intel and app security monitoring.
  • Participate in audits, risk assessments, and security authorization activities under federal frameworks.

Skills

Web application security
DevSecOps automation
Secure coding practices
OWASP Top 10
Risk assessments

Education

Bachelor's degree in Computer Science or related field

Tools

.NET
HTML5
CSS3
JavaScript
SQL
REST APIs

Job description

Company Overview

Spry Methods is a proven provider of mission-focused technology, cybersecurity, and program management solutions supporting critical Federal and DoD missions. We specialize in delivering integrated, high-impact solutions across cyber operations, enterprise resource management, and mission support services. Our culture emphasizes collaboration, accountability, and innovation - empowering our teams to deliver meaningful outcomes in complex, high-security environments.

Who We’re Looking For (Position Overview)

The Application Security Security Engineer protects mission‑critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.

What Your Day-To-Day Looks Like (Position Responsibilities)
  • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.
  • Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions.
  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services.
  • Review and analyze web server and application logs to detect anomalies and indicators of compromise.
  • Implement automation scripts for threat intelligence integration and application security monitoring.
  • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks.
What You Need to Succeed (Minimum Requirements)
  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work.
  • Hands‑on experience in secure software development, DevSecOps automation, and vulnerability remediation.
  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL).
  • Ability to leverage AI‑assisted development tools and scripting languages to automate monitoring and compliance efforts.
  • Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools.
  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies.
  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field.
  • Ability to meet federal screening and suitability requirements prior to start.

Current security certifications maintained for a minimum of five years:

  • Specialized AppSec:
    • Certified Secure Software Lifecyle Professional (CSSLP)
    • GIAC Certified Web Application Defender (GWEB)
    • EC-Council Certified Application Security Engineer (CASE)
  • Offensive Security:
    • OffSec Web Expert (OSWE)
    • Offensive Security Certified Professional (OSCP)
  • Foundational Security:
    • Security+
    • GSEC
Ideally, You Also Have (Preferred Qualifications)
  • In‑depth experience with federal cybersecurity frameworks and authorization processes.
  • Experience with threat modeling, resilient security architecture, cloud security, and container security.
Perks of Working for Us (Benefits)
  • Medical Coverage - Cigna - 4 Options
    • Traditional - PPO Open Access Plus Network
    • (2) HDHP - PPO Open Access Plus Network
    • HDHP - EPO Open Access Plus Network
  • Dental Coverage - Cigna - PPO Base & Buy-Up Plans
  • Vision Coverage - Principal - VSP Choice Network
  • Paid Holidays: Full‑time employees receive 11 paid federal holidays
  • Paid Time Off (PTO) - PTO accrual starts at 15 days per year
  • Training Benefit - Annual training allowance available toward any job‑related training or education
  • 401(k) - Multiple Fund Choices through Fidelity with a company match
  • For our full list of benefits, please visit http://www.sprymethods.com/careers/benefits/
EEO Statement

At Spry, we believe talented and dedicated employees are our most valued assets and the foundation of our success. We are committed to crafting a diverse and inclusive workplace that endorses engagement, creativity, quality and innovation.

We are proud to be an affirmative action and equal opportunity employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Final compensation will be based on experience, qualifications, certifications, clearance level, and contract requirements. This position is contingent upon contract award.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Method, Inc. • Washington

On-site
USD 135,000 - 155,000
Medical Coverage
Dental Coverage
Vision Coverage
+4
Web Developer Security Engineer
Web Developer Security Engineer

Sprymethods • Washington

On-site
USD 110,000 - 170,000
Medical Coverage - Cigna - 4 Options
Traditional - PPO Open Access Plus Net
(2) HDHP - PPO Open Access Plus Net
+8
Web Developer Security Engineer
Web Developer Security Engineer

Method, Inc. • Washington

Hybrid
USD 120,000 - 160,000
Medical Coverage
Dental Coverage
Vision Coverage
+4
Staff Application Security Architect
Staff Application Security Architect

Rocket Homes Real Estate LLC • Seattle (WA)

On-site
USD 149,000 - 318,000
Application Security Engineer — Web & API Safeguards
Application Security Engineer — Web & API Safeguards

Method, Inc. • Washington

On-site
USD 135,000 - 155,000
Medical Coverage
Dental Coverage
Vision Coverage
+4
Systems Engineer
Systems Engineer

Method, Inc. • Virginia (MN)

On-site
USD 100,000 - 110,000
Medical Coverage
Dental Coverage
Vision Coverage
+4
Staff Application Security Engineer
Staff Application Security Engineer

Triwill Group • United States

On-site
USD 120,000 - 145,000
Fully remote work arrangement
Application Security Engineer
Application Security Engineer

SciTec Incorporated • Boulder (CO)

On-site
USD 96,000 - 146,000
401(k) match
100% paid Medical insurance
Annual Profit-Sharing Plan
App Security Engineer: Secure Web & DevSecOps
App Security Engineer: Secure Web & DevSecOps

Spry Methods, Inc. • Washington

On-site
USD 120,000 - 160,000
Medical coverage
Dental coverage
Vision coverage
+4
Senior Application Security Architect
Senior Application Security Architect

Payactiv • Milpitas (CA)

On-site
USD 130,000 - 160,000
Health, Dental, and Vision insurance
401(k) with company match
Unlimited Paid Time Off
+2