Web Developer Security Engineer
Sprymethods·3 months ago
What Your Day-To-Day Looks Like (Position Responsibilities):
-
Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.
-
Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions.
-
Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services.
-
Review and analyze web server and application logs to detect anomalies and indicators of compromise.
-
Implement automation scripts for threat intelligence integration and application security monitoring.
-
Participate in audits, risk assessments, and security authorization activities tied to federal frameworks.
What You Need to Succeed (Minimum Requirements):
-
Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work.
-
Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation.
-
Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL).
-
Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts.
-
Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools.
-
Ability to perform risk assessments and provide remediation guidance for core systems and dependencies.
-
Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field.
-
Ability to meet federal screening and suitability requirements prior to start.
-
Current security certifications maintained for a minimum of five years:
- Specialized AppSec:
- Certified Secure Software Lifecyle Professional (CSSLP)
- GIAC Certified Web Application Defender (GWEB)
- EC-Council Certified Application Security Engineer (CASE)
- Offensive Security:
- OffSec Web Expert (OSWE)
- Offensive Security Certified Professional (OSCP)
- Foundational Security:
- Security+
- GSEC
-
-
-
-
Ideally, You Also Have (Preferred Qualifications):
-
In-depth experience with federal cybersecurity frameworks and authorization processes.
-
Experience with threat modeling, resilient security architecture, cloud security, and container security.
Perks of Working for Us (Benefits):
Medical Coverage – Cigna - 4 Options
- Traditional - PPO Open Access Plus Network
- (2) HDHP - PPO Open Access Plus Network
- HDHP - EPO Open Access Plus Network
Dental Coverage – Cigna - PPO Base & Buy-Up Plans
Vision Coverage – Principal - VSP Choice Network
Paid Holidays: Full-time employees receive 11 paid federal holidays
Paid Time Off (PTO) – PTO accrual starts at 15 days per year
Training Benefit – Annual training allowance available toward any job-related training or education
401(k) – Multiple Fund Choices through Fidelity with a company match
For our full list of benefits, please visit http://www.sprymethods.com/careers/benefits/
Market context
Measured from remote postings we have tracked ourselves — not self-reported survey data.
What Mid Level Engineering roles in Americas pay
- 25th
- $108k
- Median
- $144k
- 75th
- $175k
Based on 6,014 comparable postings with disclosed salaries, last 12 months.
How Sprymethods is hiring
- Last 90 days
- 5 roles
- Total tracked
- 24
- Hiring across
- 8 job families
Tracked since September 2022.