Job Description:
We are looking for a highly skilled and proactive Web Developer Security Engineer to join our team supporting the Congressional Budget Office (CBO) under the SENTRY Blanket Purchase Agreement (BPA). As a Web Developer Security Engineer, you will play a pivotal role in protecting mission-critical web applications, APIs, and sensitive data. You will embed robust security principles throughout the software development lifecycle (SDLC) to build security as a proactive, foundational pillar. You will identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations, and drive the end-to-end vulnerability lifecycle.
Key Responsibilities:
- Web Application Security: Identify, analyze, and neutralize critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations.
- Vulnerability Lifecycle: Drive the end-to-end vulnerability lifecycle-integrating proactive threat modeling and advanced security assessments, ensuring remediation integrity through rigorous technical validation.
- Secure Design: Support integration of security controls into application architectures, APIs, and supporting services; advise on secure design patterns, data protection mechanisms, and secure communication protocols.
- Monitoring & Incident Response: Obtain, review, and analyze web server and application logs to detect anomalies and indicators of compromise; support the end-to-end response to web application security events.
- Automation: Implement automation scripts for threat intelligence integration to optimize alert accuracy; leverage AI-assisted development tools (e.g., GitHub Copilot, OpenAI API/Codex) and scripting languages (Python, JavaScript/Node.js) to automate security monitoring and compliance audits.
- Compliance: Ensure all web applications and cloud infrastructures comply with Federal cybersecurity frameworks, including NIST SP 800-53, FISMA, and FedRAMP (as applicable); participate in audits, risk assessments, and security authorization processes.
Required Qualifications:
- Certifications: Must hold at least one certification from each of the following three categories:
- Specialized AppSec: CSSLP, GWEB, or CASE
- Offensive Security: OSWE or OSCP
- Foundational Security: Security+ or GSEC
- Certifications must have been maintained for a minimum of 5 years. Expired certifications or certifications never used professionally will not be considered.
- Clearance: Must be eligible to obtain and maintain a Public Trust Tier 2 clearance (background check conducted through U.S. Capitol Police).
- Experience: Minimum of 3 years of experience in Web Application Security, Application Security Engineering (AppSec), or secure software development life cycle (SSDLC).
- Technical Proficiency: Demonstrated hands-on experience with: