OVERVIEW
Clearance: Public Trust Tier 2 or higher preferred
Applied Intellect is seeking a Web Developer Security Engineer to support federal contracts, by playing a pivotal role in protecting mission-critical web applications, APIs and sensitive data. The objectives are to embed robust security principles throughout the software development lifecycle (SDLC) to build security as a proactive, foundational pillar.
Key Responsibilities
The Key Responsibilities include, but is not limited to, the following activities:
Web Application Security
- Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations
- Drive the end-to-end vulnerability lifecycle - integrating proactive threat modeling and advanced security assessments, ensuring remediation integrity through rigorous technical validation
- Support integration of security controls into application architectures, APIs, and supporting services, advising on secure design patterns; data protection mechanisms; and secure communication protocols to ensure applications are secure by design and resilient to evolving threats
Monitoring, Logging, Incident Response and Automation
- Obtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise
- Implement automation scripts for threat intelligence integration to optimize alert accuracy and actively support the end-to-end response to web application security events.
- Maintain documentation of findings, remediation steps, and security controls
Compliance & Governance
- Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks, including NIST SP 800‑53, FISMA, and FedRAMP (as applicable)
- Participate in audits, risk assessments, and security authorization processes
Required Skills/Knowledge/Expertise
- Extensive hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation.
- Proficiency in logs analysis, file integrity monitoring (FIM), and managing web application firewalls (WAF) to defend against emerging threats.
- Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec) or secure software development life cycle (SSDLC)
- Proven developing with modern web technologies and frameworks not limited to .NET (C# MVC, WCF), HTML5, CSS3, JavaScript, REST APIs, and SQL
- Ability to leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting languages (Python, JavaScript/Node.js, Java, React.js, TypeScript) to automate security monitoring and compliance audits
- Strong understanding of Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, and proactive mitigation of common web vulnerabilities.