PLEASE READ IN IT'S ENTIRITY
Location: Remote (U.S.) may be expected to visit site for meeting and stakeholder engagement when requested. Employment: Contractor - Full-Time Salary: Starting at $143,000 - $150,000 annually (commensurate with experience and certifications) Clearance: U.S. Citizenship required. Ability to obtain or maintain a Federal security clearance preferred. No Visa sponsorship
Key Responsibilities
Web Application Security
- Identify, analyze, and remediate application vulnerabilities and security weaknesses.
- Perform threat modeling, secure code reviews, and security assessments.
- Integrate security controls into application architectures, APIs, and cloud environments.
- Implement secure-by-design principles and OWASP best practices.
Monitoring, Incident Response & Automation
- Analyze web server and application logs for threats and indicators of compromise.
- Develop automation using Python, JavaScript, or AI-assisted tools to improve security monitoring and response.
- Maintain documentation, remediation records, and security baselines.
Compliance & Governance
- Support compliance with NIST SP 800-53, FISMA, and FedRAMP requirements.
- Participate in risk assessments, audits, and security authorization activities.
- Develop security metrics and compliance reporting.
Minimum Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Engineering, or related field.
- 3+ years of experience in Web Application Security, Application Security Engineering, or Secure Software Development.
- Experience with secure software development, DevSecOps, CI/CD security, and vulnerability remediation.
- .NET (C#), HTML5, CSS3, JavaScript, REST APIs, SQL
- Python, JavaScript/Node.js, Java, React, or TypeScript
- GitHub Copilot, OpenAI, or similar AI-assisted development tools
- OWASP Top 10
- Secure coding practices
- Web Application Firewalls (WAF)
- File Integrity Monitoring (FIM)
- Security testing tools (Wireshark, SIEM, IDS/IPS, NDR, EDR)
- Experience performing risk assessments and implementing security controls throughout the software development lifecycle.
- Ability to work independently and collaboratively within multidisciplinary teams.
Preferred Qualifications
- Experience supporting Federal cybersecurity programs.
- Knowledge of NIST SP 800-53, FISMA, and FedRAMP authorization processes.
- Experience with AWS, Docker, Kubernetes, and container security.
- Experience designing resilient application security architectures and threat models.
Preferred Certifications
Candidates should possess one or more of the following (or equivalent):
- CSSLP
- GWEB
- CASE
- OSWE
- OSCP
- Security+