Spry Methods, Inc. logo
Spry Methods, Inc.
Posted 66 days agoVerified live 1d ago

Web Developer Security Engineer

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
1 H-1B approvalsDept. of Labor
Clearance requiredU.S. government
Web application securityApplication security engineeringSecure software development lifecycleDevSecOps automationVulnerability remediationMicrosoft .NETHTML5CSS3JavaScriptREST APIsSQLAI-assisted development toolsScripting languagesOWASP Top 10Secure coding standardsWeb application firewallsFile integrity monitoring

About the company

Spry Methods, Inc. logo
Spry Methods, Inc.sprymethods.com

Spry is a certified Small Business headquartered in McLean, VA.

Visa sponsorship history

1 year sponsoring, last filed FY2025

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
1H-1B approved
100%approval rate
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20251

Job description

Summary

Spry Methods, Inc. is seeking a Web Developer Security Engineer to protect mission-critical web applications and sensitive data by embedding security across the software development lifecycle. The role involves application security engineering, vulnerability remediation, and compliance support.

Responsibilities

  • Identify, analyze, and remediate critical vulnerabilities, logic flaws, insecure dependencies, and misconfigurations in web applications and APIs
  • Drive the vulnerability lifecycle through threat modeling, security assessments, and technical validation of remediation actions
  • Support secure design patterns, data protection mechanisms, and secure communication protocols across applications and supporting services
  • Review and analyze web server and application logs to detect anomalies and indicators of compromise
  • Implement automation scripts for threat intelligence integration and application security monitoring
  • Participate in audits, risk assessments, and security authorization activities tied to federal frameworks

Skills

  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work
  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation
  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL)
  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts
  • Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools
  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies
  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field
  • Ability to meet federal screening and suitability requirements prior to start
  • Current security certifications maintained for a minimum of five years: Specialized AppSec: Certified Secure Software Lifecyle Professional (CSSLP), GIAC Certified Web Application Defender (GWEB), EC-Council Certified Application Security Engineer (CASE), Offensive Security: OffSec Web Expert (OSWE), Offensive Security Certified Professional (OSCP), Foundational Security: Security+, GSEC
  • In-depth experience with federal cybersecurity frameworks and authorization processes
  • Experience with threat modeling, resilient security architecture, cloud security, and container security

Qualifications

Must Haves

  • Minimum of three years of experience in web application security, application security engineering, or secure software development lifecycle work
  • Hands-on experience in secure software development, DevSecOps automation, and vulnerability remediation
  • Proven experience with .NET technologies, HTML5, CSS3, JavaScript, representational state transfer (REST) APIs, and structured query language (SQL)
  • Ability to leverage AI-assisted development tools and scripting languages to automate monitoring and compliance efforts
  • Strong understanding of the Open Worldwide Application Security Project (OWASP) Top 10, secure coding standards, web application firewalls (WAFs), file integrity monitoring, and security testing tools
  • Ability to perform risk assessments and provide remediation guidance for core systems and dependencies
  • Bachelor's degree or higher in computer science, cybersecurity, information systems, engineering, or a related field
  • Ability to meet federal screening and suitability requirements prior to start
  • Current security certifications maintained for a minimum of five years: Specialized AppSec: Certified Secure Software Lifecyle Professional (CSSLP), GIAC Certified Web Application Defender (GWEB), EC-Council Certified Application Security Engineer (CASE), Offensive Security: OffSec Web Expert (OSWE), Offensive Security Certified Professional (OSCP), Foundational Security: Security+, GSEC

Nice to Haves

  • In-depth experience with federal cybersecurity frameworks and authorization processes
  • Experience with threat modeling, resilient security architecture, cloud security, and container security

More jobs like this