远程工作雷达

网络安全开发工程师

Web Developer Security Engineer

开发工程市场运营全球可投
公司sprymethods
薪资未公开
工作地点Washington, DC (Remote)
地域资格全球可投
时区要求无特别要求
用工类型Proposal Position
发布时间未知
数据来源Lever
前往企业招聘页投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

公司简介

Spry Methods 是一家在任务导向型技术、网络安全和项目管理解决方案方面具有丰富经验的供应商,支持关键的联邦和国防部任务。我们专注于在网络运营、企业资源管理和任务支持服务领域提供集成的高影响力解决方案。我们的文化强调协作、问责制和创新,使我们的团队能够在复杂且高安全性的环境中实现有意义的成果。

我们寻找的人选(职位概述):

Web 开发者安全工程师通过在整个软件开发生命周期中嵌入安全性,保护关键任务的网络应用程序、应用程序编程接口(API)和敏感数据。该职位结合了应用安全工程、安全软件开发、漏洞修复、监控和合规支持。

与我们共事的福利(福利):

医疗保障 – Cigna - 4 种选择

- 传统计划 - PPO 开放访问加号网络

- (2)HDHP - PPO 开放访问加号网络

- HDHP - EPO 开放访问加号网络

牙科保障 – Cigna - PPO 基础及附加计划

视力保障 – Principal - VSP 选择网络

带薪节假日:全职员工享受 11 个带薪联邦节假日

带薪休假(PTO)– PTO 积累每年从 15 天开始

培训福利 – 年度培训津贴可用于任何与工作相关的培训或教育

401(k) – 通过 Fidelity 提供多种基金选择,公司有匹配

有关我们完整的福利列表,请访问 http://www.sprymethods.com/careers/benefits/

平等就业机会声明

在 Spry,我们认为才华横溢且敬业的员工是我们最宝贵的资产,也是我们成功的基础。我们致力于打造一个多元化和包容性的工作环境,鼓励参与、创造力、质量和创新。

我们自豪地成为平权行动和机会均等的雇主,因此,我们对合格候选人进行全面评估,不考虑种族、肤色、宗教、性别、性取向、性别认同、婚姻状况、国籍、年龄、残疾状况、受保护退伍军人状况或其他受保护的状态。

您日常工作的内容(职位职责):

  • 识别、分析并修复网络应用程序和 API 中的关键漏洞、逻辑缺陷、不安全依赖项和配置错误。
  • 通过威胁建模、安全评估和技术审查推动漏洞生命周期。
查看英文原文

Company Overview

Spry Methods is a proven provider of mission-focused technology, cybersecurity, and program management solutions supporting critical Federal and DoD missions. We specialize in delivering integrated, high-impact solutions across cyber operations, enterprise resource management, and mission support services. Our culture emphasizes collaboration, accountability, and innovation - empowering our teams to deliver meaningful outcomes in complex, high-security environments.

Who We’re Looking For (Position Overview):

The Web Developer Security Engineer protects mission-critical web applications, application programming interfaces (APIs), and sensitive data by embedding security across the software development lifecycle. This role combines application security engineering, secure software development, vulnerability remediation, monitoring, and compliance support.

Perks of Working for Us (Benefits):

Medical Coverage – Cigna - 4 Options

- Traditional - PPO Open Access Plus Network

- (2) HDHP - PPO Open Access Plus Network

- HDHP - EPO Open Access Plus Network

Dental Coverage – Cigna - PPO Base & Buy-Up Plans

Vision Coverage – Principal - VSP Choice Network

Paid Holidays: Full-time employees receive 11 paid federal holidays

Paid Time Off (PTO) – PTO accrual starts at 15 days per year

Training Benefit – Annual training allowance available toward any job-related training or education

401(k) – Multiple Fund Choices through Fidelity with a company match

For our full list of benefits, please visit http://www.sprymethods.com/careers/benefits/

EEO Statement

At Spry, we believe talented and dedicated employees are our most valued assets and the foundation of our success. We are committed to crafting a diverse and inclusive workplace that endorses engagement, creativity, quality and innovation.

We are proud to be an Affirmative Action and Equal Opportunity Employer and as such, we evaluate qualified candidates in full consideration without regard to race, color, religion, sex, sexual orientation, gender identity, marital status, national origin, age, disability status, protected veteran status, and any other protected status.

What Your Day-To-Day Looks Like (Position Responsibilities):

  • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs.
  • Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions.
  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services.
  • Review and analyze web server and application logs to detect anomalies and indicators of compromise.
  • Implement automation scripts for threat intelligence integration and application security monitoring.
  • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks.

What You Need to Succeed (Minimum Requirements):

  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work.
  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation.
  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL).
  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts.
  • Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools.
  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies.
  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field.
  • Ability to meet federal screening and suitability requirements prior to start.
  • Current security certifications maintained for a minimum of five years:
  • Specialized AppSec:
  • Certified Secure Software Lifecyle Professional (CSSLP)
  • GIAC Certified Web Application Defender (GWEB)
  • EC-Council Certified Application Security Engineer (CASE)
  • Offensive Security:
  • OffSec Web Expert (OSWE)
  • Offensive Security Certified Professional (OSCP)
  • Foundational Security:
  • Security+
  • GSEC

Ideally, You Also Have (Preferred Qualifications):

  • In-depth experience with federal cybersecurity frameworks and authorization processes.
  • Experience with threat modeling, resilient security architecture, cloud security, and container security.
本页面信息整理自 Lever,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位