Prepin
Log in
Spry Methods, Inc.

engineering opportunity

Web Developer Security Engineer

The role involves protecting mission-critical web applications and APIs by embedding security throughout the software development lifecycle. Responsibilities include identifying and remediating vulnerabilities, performing threat modeling, and automating security monitoring.

Washington, District of Columbia, United StatesremoteCONTRACTOR

Posted

About the role

What will you do at Spry Methods, Inc.?

Who We’re Looking For (Position Overview):

The Web Developer Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.

\n

What Your Day-To-Day Looks Like (Position Responsibilities):

Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.

Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions.

Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services.

Review and analyze web server and application logs to detect anomalies and indicators of compromise.

Implement automation scripts for threat intelligence integration and application security monitoring.

Participate in audits, risk assessments, and security authorization activities tied to federal frameworks.

What You Need to Succeed (Minimum Requirements):

Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work.

Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation.

Proven experience with . NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL).

Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts.

Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools.

Ability to perform risk assessments and provide remediation guidance for core systems and dependencies.

Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field.

Ability to meet federal screening and suitability requirements prior to start.

Current security certifications maintained for a minimum of five years:

Specialized AppSec:

Certified Secure Software Lifecyle Professional (CSSLP)

GIAC Certified Web Application Defender (GWEB)

EC-Council Certified Application Security Engineer (CASE)

Offensive Security:

OffSec Web Expert (OSWE)

Offensive Security Certified Professional (OSCP)

Foundational Security:

Security+

GSEC

Ideally, You Also Have (Preferred Qualifications):

In-depth experience with federal cybersecurity frameworks and authorization processes.

Experience with threat modeling, resilient security architecture, cloud security, and container security.

\n

$135,000 - $155,000 a year

Final compensation will be based on experience, qualifications, certifications, clearance level, and contract requirements. This position is contingent upon contract award.

\n

Which skills does this role require?

Application SecurityDevSecOpsVulnerability Remediation.NETHTML5CSS3JavaScriptREST APIsSQLOWASP Top 10Web Application FirewallsSecurity TestingRisk AssessmentAutomationComplianceWeb DeveloperSecurity EngineerWAFCSSLPGWEBCASEOSWEOSCPSecurity+GSECFederal FrameworksSoftware Development LifecycleC#

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.