Logo for Spry Methods, Inc

Web Developer Security Engineer

Role overview

Qualifications

  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work.
  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL).
  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field.
  • Current security certifications maintained for a minimum of five years.

Responsibilities

  • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.
  • Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions.
  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services.
  • Review and analyze web server and application logs to detect anomalies and indicators of compromise.

About the company

Spry Methods, Inc logo

Spry Methods, Inc

IT Services & IT Consulting

Spry is a certified Small Business headquartered in McLean, VA. Spry provides Enterprise, C4IT, Management, and Cyber Solutions to the federal government and commercial entities. Founded in 2001, Spry Methods was built on the foundation of combining industry knowledge with unmatched responsiveness to produce results for our customers. Our goal is to build a business dedicated to the maximization of value for all stakeholders starting with our employees, our customers, and our community. We recognize that talented and dedicated employees are our most valued assets and the foundation of our success. Guided by these principles, we have established an impressive track record of proven past performance serving our customers within the Commercial, Federal Civilian, DoD, and Intelligence Communities. A CMMI Level 3 certified and ISO 9001:2008 registered company, Spry is committed to quality and continuous improvement.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Who We’re Looking For (Position Overview):
The Web Developer Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.   

What Your Day-To-Day Looks Like (Position Responsibilities):
  • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs. 

  • Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions. 

  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services. 

  • Review and analyze web server and application logs to detect anomalies and indicators of compromise. 

  • Implement automation scripts for threat intelligence integration and application security monitoring. 

  • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks. 


What You Need to Succeed (Minimum Requirements):
  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work. 

  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation. 

  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL). 

  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts. 

  • Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools. 

  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies. 

  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field. 

  • Ability to meet federal screening and suitability requirements prior to start. 

  • Current security certifications maintained for a minimum of five years: 

    • Specialized AppSec:
      • Certified Secure Software Lifecyle Professional (CSSLP)
      • GIAC Certified Web Application Defender (GWEB)
      • EC-Council Certified Application Security Engineer (CASE)
      • Offensive Security:
        • OffSec Web Expert (OSWE)
        • Offensive Security Certified Professional (OSCP)
        • Foundational Security:
          • Security+
          • GSEC

Ideally, You Also Have (Preferred Qualifications):
  • In-depth experience with federal cybersecurity frameworks and authorization processes. 

  • Experience with threat modeling, resilient security architecture, cloud security, and container security. 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Spry Methods, Inc

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.