Demo

Web Application Security Engineer (Senior)

Iron Vine Security, LLC Career Center
Suitland, MD Full Time
POSTED ON 1/22/2025
AVAILABLE BEFORE 3/21/2025

Job Requirements:

·        Strong written and verbal communication skills.

·        Must have an ability to communicate effectively, verbally and in writing, to interact effectively with internal and external vendors, project team members, management and agency departments, to build relationships and use facilitation skills with both technical and non-technical personnel.  

·        Security Engineer Maintained CompTIA Security Professional (Security ), CISSP and/or CEH certification for 5 consecutive years

·        5 consecutive years of systems assessment and authentication experience.

·        Proficient in Federal Information Security Management Act Metrics and Compliance Federal Information Processing Standards (FIPS)3 years hands on compliance testing experience Oracle Certified Professional or equivalent CIS Benchmarks.  

·        Splunk Certification or obtaining certification; knowledgeable in the use of Splunk Dashboards and audit data generation to support cyberattack investigations.

·        Detailed technical knowledge of database and operating system security.

·        Hands on experience in security systems and controls, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, etc.

·        Experience developing web applications in PHP, Java, .NET or JavaScript. Experience with OW ASP a plus. Experience with application security assessment tools such as: Web Inspect, Fortify, Burp Suite, etc.

·        Experience in engineering or assessing the security of cloud, SaaS, and multi-tenanted applications including designing authentication and authorization requirements.

 

Certifications/Licenses:

·        Bachelor’s degree or higher

·        10 years’ experience in security engineering in mid to large environments.

·        Certifications addressing security and risk management, asset security, security engineering, communications and network security, identity and access management, security assessment and testing, security operations, software development security, system security, network infrastructure, access control, cryptography, assessments and audits, and organizational security

·        Active Public Trust clearance or eligible to obtain a Public Trust clearance

 

Additional Experience Preferred:

·        In-depth knowledge of Information Theory (e.g., source coding, channel coding, algorithm complexity theory, and data compression).

·        Ability to apply system design tools, methods, and techniques, including automated systems analysis and design tools.

·        Knowledge of network protocols such as TCP/IP, Dynamic Host Configuration, Domain Name System (DNS), and directory services.

·        Knowledge of network design processes, to include understanding of security objectives, operational objectives, and trade-offs.

·        Ability to apply network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).

·        Experience designing the integration of hardware and software solutions.

·        Experience in developing and applying security system access controls.

·        Skill in discerning the protection needs (i.e., security controls) of information systems and networks.

·        Skill in evaluating the adequacy of security designs and conducting reviews of technical systems.

·        Skill in the use of design modeling (e.g., unified modeling language).

·        Ability to apply secure system design tools, methods and techniques and ensure security practices are followed throughout the acquisition process.

 

Position Responsibilities:

·        Evaluation of common security controls for internal and external web applications, client server systems and assist in the development of standardized technical implementation recommendations.

·        Track and update Acceptable Baseline Configuration deviations and false positives monthly to ensure accuracy

·        Automate technical security checks/audits throughout all components of applications (database, middleware, application code, servers, CI/CD pipeline )

·        Review/Preliminary Investigation for False Positives (FP).  Coordinates completion of False Positive form with ISSO signature and OIS signature approval.

·        Reports identified technical vulnerabilities. As a further way of sharing information about vulnerabilities, maintains contact with ISSO and stakeholders with the same types of systems to determine standardized remediation going forward.

·        Source Code Reviews / Deep Dives

·        Security assessment support of new ECON Security Architecture and Topologies

·        Technical writing for developing security standards and policies

·        Adjudications of Technical Findings,

·        Direct HP Fortify and/or HP Web Inspect hands on experience for system related vulnerability scanning Burp Suite

·        Visualization Reports

·        Automation of Audits

·        Automation of Config Benchmarks

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Web Application Security Engineer (Senior)?

Sign up to receive alerts about other jobs on the Web Application Security Engineer (Senior) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$109,826 - $143,482
Income Estimation: 
$129,898 - $168,102
Income Estimation: 
$79,717 - $106,492
Income Estimation: 
$100,513 - $130,942
Income Estimation: 
$116,473 - $152,973
Income Estimation: 
$118,843 - $170,999
Income Estimation: 
$100,513 - $130,942
Income Estimation: 
$116,473 - $152,973

Sign up to receive alerts about other jobs with skills like those required for the Web Application Security Engineer (Senior).

Click the checkbox next to the jobs that you are interested in.

  • Access Control Skill

    • Income Estimation: $60,745 - $74,630
    • Income Estimation: $83,579 - $128,541
  • Data Analysis Skill

    • Income Estimation: $58,079 - $86,663
    • Income Estimation: $59,813 - $83,853
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Iron Vine Security, LLC Career Center

Iron Vine Security, LLC Career Center
Hired Organization Address Baltimore, MD Full Time
Position Title: Deputy Incident Response Analyst Location: Baltimore, MD Hours: 8 am – 4pm (On-Call as Needed) Position ...
Iron Vine Security, LLC Career Center
Hired Organization Address Suitland, MD Full Time
Job Requirements: · Prior experience in cybersecurity and/or significant work within the Intelligence community · Strong...
Iron Vine Security, LLC Career Center
Hired Organization Address Washington, DC Full Time
Job Requirements: · Strong written and verbal communication skills. · Experience designing, implementing, and maintainin...
Iron Vine Security, LLC Career Center
Hired Organization Address Washington, DC Full Time
Program Analyst is responsible for managing communications with overseas countries and leading the development and publi...

Not the job you're looking for? Here are some other Web Application Security Engineer (Senior) jobs in the Suitland, MD area that may be a better fit.

Amazon Security Engineer, Networking

Amazon Web Services (AWS), Herndon, VA

Senior Security Engineer, RSCI Vector Security

Amazon Web Services (AWS), Herndon, VA

AI Assistant is available now!

Feel free to start your new journey!