
Web Developer, Security Engineer
Posted Jul 30

Posted Jul 30
This is a fully remote position, open to applicants in Washington.
• Identify, evaluate, and address critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.
• Lead the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation efforts.
• Advocate for secure design patterns, data protection methods, and secure communication protocols across applications and supporting services.
• Examine and analyze web server and application logs to identify anomalies and signs of compromise.
• Develop automation scripts for the integration of threat intelligence and the monitoring of application security.
• Engage in audits, risk assessments, and security authorization activities related to federal frameworks.
• At least three years of experience in web application security, application security engineering, or secure software development lifecycle practices.
• Practical experience in secure software development, DevSecOps automation, and vulnerability remediation.
• Demonstrated proficiency with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL).
• Capability to utilize AI-assisted development tools and scripting languages to streamline monitoring and compliance initiatives.
• Strong knowledge of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools.
• Proficient in conducting risk assessments and offering remediation guidance for core systems and dependencies.
• Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related discipline.
• Ability to satisfy federal screening and suitability requirements prior to employment.
• Current security certifications maintained for a minimum of five years:
• Specialized AppSec:
• Certified Secure Software Lifecycle Professional (CSSLP)
• GIAC Certified Web Application Defender (GWEB)
• EC-Council Certified Application Security Engineer (CASE)
• Offensive Security:
• OffSec Web Expert (OSWE)
• Offensive Security Certified Professional (OSCP)
• Foundational Security:
• Security+
• GSEC
• Comprehensive health, dental, and vision insurance coverage.
• Retirement savings plan with company matching.
• Flexible working hours and remote work opportunities.
• Professional development and training programs.
• Competitive salary and performance-based bonuses.
Magic, Inc
Magic, Inc
24-MAG
Koniag Government Services
Get handpicked remote jobs straight to your inbox weekly.