Logo for Nationwide IT Services, Inc.

Web Developer Security Engineer

Role overview

Qualifications

  • Minimum 3 years of experience in Application Security and Secure Software Development Lifecycle (SSDLC)
  • Strong knowledge of web application security principles and OWASP Top 10 vulnerabilities
  • Experience with secure application design, architecture reviews, data protection, and secure communications
  • Bachelor’s degree or higher in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field

Responsibilities

  • Perform application security reviews and threat modeling
  • Conduct vulnerability assessments and oversee remediation efforts
  • Implement and maintain security controls within CI/CD pipelines
  • Configure and tune WAF and File Integrity Monitoring solutions

About the company

Nationwide IT Services, Inc. logo

Nationwide IT Services, Inc.

IT Services & IT Consulting

Nationwide IT Services, Inc. (NIS) is designated 8(a) by the SBA, and a CVE verified Service Disabled Veteran Owned Small Business (SDVOSB) Information Technology (IT) and Management consulting company. NIS has been providing Information Technology Solutions, program management support services and subject matter expertise within the federal government since 2006. NIS works with each client to deploy a mission-specific solution that: Complies with the Regulatory Environment Captures the Client’s Mission, Vision & Values Aligns Objectives with Deliverables Applies Industry Best Practices Creates Measurable, Sustainable Change.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Web Developer Security Engineer
Clearance Requirement: Public Trust (Tier 2)
Location: Remote/Hybrid (as approved by customer)

Position Overview: Nationwide IT Services (NIS) is seeking a Web Developer Security Engineer to support application security initiatives across web applications, APIs, and the software development lifecycle (SDLC). The selected candidate will be responsible for secure application design, vulnerability management, DevSecOps integration, security monitoring, WAF administration, File Integrity Monitoring (FIM), and Tier II security operations support.

Required Experience:
  • Minimum 3 years of experience in Application Security and Secure Software Development Lifecycle (SSDLC).
  • Strong knowledge of web application security principles and OWASP Top 10 vulnerabilities.
  • Experience managing the full vulnerability lifecycle, including threat modeling, security assessments, remediation, and validation.
  • Experience with secure application design, architecture reviews, data protection, and secure communications.
  • Hands-on experience with Web Application Firewall (WAF) deployment, configuration, and tuning.
  • Experience with File Integrity Monitoring (FIM), log analysis, Indicators of Compromise (IOC) detection, and threat intelligence automation.
  • Experience supporting Tier II Security Operations.
  • Experience implementing DevSecOps practices and automated security controls within CI/CD pipelines.
Technical Skills:
  • .NET Technologies: C#, ASP.NET MVC, WCF
  • Front-End: HTML5, CSS3, JavaScript, React, TypeScript
  • APIs & Databases: REST APIs, SQL
  • Programming/Scripting: Python, Node.js, Java
  • AI-Assisted Development Tools (e.g., GitHub Copilot)
  • Security Tools: SIEM, IDS/IPS, NDR, EDR
  • Cloud & Container Security: AWS, Docker, Kubernetes
Compliance & Governance:
  • Experience supporting environments governed by NIST SP 800-53, FISMA, and FedRAMP.
  • Experience participating in audits, security assessments, and authorization activities.
Education:
  • Bachelor’s degree or higher in Computer Science, Cybersecurity, Information Systems, Engineering, or a related field.
Required Certifications:
Application Security (One Required):
  • CSSLP, OR
  • GIAC Web Application Penetration Tester (GWEB), OR
  • CASE
Offensive Security (One Required):
  • OSWE, OR
  • OSCP
Foundational Security (One Required):
  • Security+, OR
  • GSEC
Preferred Qualifications:
  • Experience securing federal government applications and systems.
  • Experience integrating security controls into modern CI/CD pipelines.
  • Strong understanding of cloud-native and containerized application security.
Key Responsibilities:
  • Perform application security reviews and threat modeling.
  • Conduct vulnerability assessments and oversee remediation efforts.
  • Implement and maintain security controls within CI/CD pipelines.
  • Configure and tune WAF and File Integrity Monitoring solutions.
  • Analyze logs, investigate security events, and support incident response activities.
  • Collaborate with development teams to ensure secure coding practices.
  • Support compliance, audit, and security authorization requirements.

Working at NIS means being part of a company grounded in purpose, resilience,
and a genuine commitment to people. Since its founding in 2006, NIS has focused not only
on delivering exceptional services to our government customers, but also supporting our
nation, taxpayers, and citizens—while consistently prioritizing the well-being and growth of
its employees. Today, NIS continues to evolve by embracing remote work, enhancing
wellness initiatives, and investing in modern technology, all while staying true to its
mission.

 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Nationwide IT Services, Inc.

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.