Web Developer Security Engineer (SMA 4)

E Logic

Washington (District of Columbia)

On-site

USD 120,000 - 160,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

E-Logic, Inc. is seeking a Web Developer Security Engineer to protect mission-critical web applications, APIs, and sensitive data as part of the CBO program.

You’ll embed security into the SDLC, identify and remediate vulnerabilities, and drive the vulnerability lifecycle across the stack. Responsibilities include secure design, monitoring and incident response, automation with AI-assisted tools, and ensuring compliance with federal frameworks.

Qualifications

  • Must hold certifications in CSSLP/GWEB/CASE, OSWE/OSCP, and Security+ or GSEC with at least 5 years maintained.
  • Must be eligible for Public Trust Tier 2 clearance (background check through U.S. Capitol Police).
  • Minimum of 3 years in Web App Security/SSDLC.
  • Hands-on with .NET (C# MVC, WCF), HTML5/CSS3/JS, REST APIs, SQL.

Responsibilities

  • Identify and neutralize web vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.
  • Drive end-to-end vulnerability lifecycle including threat modeling and security assessments.
  • Advise on secure design patterns and data protection mechanisms for applications and APIs.
  • Monitor web servers and applications to detect anomalies and support incident response.
  • Implement automation for threat intelligence integration and security governance using Python/JS.
  • Ensure compliance with NIST SP 800-53, FISMA, and FedRAMP where applicable.

Skills

OWASP Top 10
Secure coding standards
Threat modeling
CI/CD security
Python
JavaScript/Node.js
TypeScript
AWS security
WAFs/FIM
Security testing tools

Education

Bachelor's degree in CS/Cybersecurity/Engineering

Tools

GitHub Copilot
OpenAI Codex
Wireshark
SIEM
IDS/IPS
NDR/EDR

Job description

Job Description

We are looking for a highly skilled and proactive Web Developer Security Engineer to join our team supporting the Congressional Budget Office (CBO) under the SENTRY Blanket Purchase Agreement (BPA). As a Web Developer Security Engineer, you will play a pivotal role in protecting mission-critical web applications, APIs, and sensitive data. You will embed robust security principles throughout the software development lifecycle (SDLC) to build security as a proactive, foundational pillar. You will identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations, and drive the end-to-end vulnerability lifecycle.

Key Responsibilities
  • Web Application Security:Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.
  • Vulnerability Lifecycle:Drive the end-to-end vulnerability lifecycle--integrating proactive threat modeling and advanced security assessments, ensuring remediation integrity through rigorous technical validation.
  • Secure Design:Support integration of security controls into application architectures, APIs, and supporting services; advise on secure design patterns, data protection mechanisms, and secure communication protocols.
  • Monitoring & Incident Response:Obtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise; support the end-to-end response to web application security events.
  • Automation:Implement automation scripts for threat intelligence integration to optimize alert accuracy; leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting languages (Python, JavaScript/Node.js) to automate security monitoring and compliance audits.
  • Compliance:Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks, including NIST SP 800-53, FISMA, and FedRAMP (as applicable); participate in audits, risk assessments, and security authorization processes.
Required Qualifications
  • Certifications:Must hold at least one certification from each of the following three categories:
  • Specialized AppSec: CSSLP, GWEB, or CASE
  • Offensive Security: OSWE or OSCP
  • Foundational Security: Security+ or GSEC
  • Certifications must have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.
  • Clearance:Must be eligible to obtain and maintain a Public Trust Tier 2 clearance (background check conducted through U.S. Capitol Police).
  • Experience:Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC).
  • Technical Proficiency:Demonstrated hands-on experience with:
  • Modern web technologies: .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL
  • AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex)
  • Scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript)
  • Web Application Firewalls (WAFs) and File Integrity Monitoring (FIM) solutions
  • Security testing tools (Wireshark, SIEM, IDS/IPS, NDR, EDR)
  • Security Knowledge:Strong understanding of OWASP Top 10, secure coding standards, and proactive mitigation of common web vulnerabilities.
Desired Experience
  • Bachelor's degree (or higher) in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.
  • In-depth experience with federal cybersecurity frameworks (NIST SP 800-53, FISMA, FedRAMP) authorization processes.
  • Proven background in threat modeling, risk assessment, and designing resilient security architecture.
  • Experience implementing secure DevOps/DevSecOps practices, specifically CI/CD pipeline and automating security gates.
  • Knowledge of cloud security (AWS) and container security (Docker, Kubernetes).
Clearance Requirement
Citizenship

U.S. Citizenship or Permanent Residence Status is required

Job Type

Full-time

Equal Opportunity Employer Statement

E-Logic, Inc. is an equal opportunity employer and is committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Web Developer Security Engineer
Web Developer Security Engineer

CMT Services, Inc. • Washington

Hybrid
USD 120,000 - 160,000
Cybersecurity Engineer (SMA 5)
Cybersecurity Engineer (SMA 5)

E-Logic, Inc. • Washington

On-site
USD 140,000 - 190,000
Cybersecurity Engineer (SMA 5)
Cybersecurity Engineer (SMA 5)

E Logic • Washington

On-site
USD 150,000 - 190,000
DevSecOps Engineer (SMA 3)
DevSecOps Engineer (SMA 3)

E Logic • Washington

On-site
USD 140,000 - 200,000
Full Stack Software Developer (SMA 2)
Full Stack Software Developer (SMA 2)

E Logic • Washington

On-site
USD 120,000 - 180,000
Web Developer Security Engineer
Web Developer Security Engineer

Nationwide IT Services • Washington

Hybrid
USD 100,000 - 120,000
DevSecOps Engineer (SMA 3)
DevSecOps Engineer (SMA 3)

E-Logic, Inc. • Washington

On-site
USD 140,000 - 190,000
Web Developer Security Engineer
Web Developer Security Engineer

Sprymethods • Washington

On-site
USD 110,000 - 170,000
Medical Coverage - Cigna - 4 Options
Traditional - PPO Open Access Plus Net
(2) HDHP - PPO Open Access Plus Net
+8
Full Stack Software Developer (SMA 2)
Full Stack Software Developer (SMA 2)

E-Logic, Inc. • Washington

On-site
USD 120,000 - 160,000
Application Security Engineer
Application Security Engineer

Method, Inc. • Washington

On-site
USD 135,000 - 155,000
Medical Coverage
Dental Coverage
Vision Coverage
+4