Talent.com
Web Application Security Subject Matter Expert / Technical Lead
Web Application Security Subject Matter Expert / Technical LeadCybervance • Bethesda, MD, United States
Web Application Security Subject Matter Expert / Technical Lead

Web Application Security Subject Matter Expert / Technical Lead

Cybervance • Bethesda, MD, United States
1 day ago
Job type
  • Full-time
Job description

Position Title : Web Application Security Subject Matter Expert / Technical Lead

Location : Bethesda, MD | Hybrid- Not Remote

Cybervance is a rapidly growing information security and information technology company based in Washington, D.C., and we are an equal opportunity employer. We design, develop, and manage the successful execution of training programs for government and private sector organizations. Cybervance believes in creating innovative solutions to deliver measured results.

We are seeking an experienced Web Application Security Subject-Matter Expert (SME) / Technical Lead to provide expert-level guidance and technical oversight for enterprise web application security operations. The SME will lead vulnerability assessments, secure coding reviews, and remediation strategies to protect mission-critical applications from cyber threats and ensure compliance with organizational and federal security standards.

This role requires deep hands-on experience with web application vulnerability assessment tools, application security frameworks, and remediation practices. The ideal candidate will possess both the technical depth to identify vulnerabilities and the leadership skills to drive enterprise-level mitigation and continuous improvement.

Responsibilities

  • Lead web application security operations across enterprise environments, including vulnerability assessment, threat modeling, and secure application architecture reviews.
  • Operate and maintain automated and manual web vulnerability assessment tools to identify misconfigurations, missing patches, insecure code, and other weaknesses that could expose applications to cyberattacks.
  • Analyze and interpret vulnerability assessment results, translating findings into actionable remediation plans and risk-reduction strategies.
  • Develop and implement processes for prioritizing vulnerabilities, ensuring critical weaknesses are addressed first, and remediation efforts align with organizational risk management priorities.
  • Collaborate with developers, DevOps teams, and system owners to remediate findings in application code and configurations.
  • Secure web application platforms built on Python, PHP, Java / JavaScript, C#, and SQL by ensuring adherence to secure coding and configuration best practices.
  • Develop and maintain content and reporting mechanisms, including dashboards and metrics for vulnerability remediation progress, compliance tracking, and management reporting.
  • Provide technical leadership and mentoring to cybersecurity engineers and developers on secure application development and vulnerability mitigation techniques.
  • Recommend and implement enhancements to web application security tools, processes, and automation for continuous improvement.
  • Stay current on emerging web vulnerabilities, exploitation techniques, and best practices for defense-in-depth and web security hardening.

Experience

  • Demonstrated experience operating web vulnerability assessment tools (e.g., Burp Suite, Acunetix, Qualys Web Application Scanner, OWASP ZAP, or equivalent).
  • Proven ability to analyze and interpret vulnerability scan results and communicate findings to technical and non-technical stakeholders.
  • Hands-on experience securing web application platforms, including Python, PHP, Java / JavaScript, C#, and SQL-based applications.
  • Experience prioritizing vulnerabilities and remediation activities to address high-risk issues efficiently.
  • Demonstrated ability to develop content, dashboards, and reports to monitor vulnerability status, remediation progress, and compliance posture.
  • Strong understanding of OWASP Top 10, secure software development lifecycle (SDLC), and web application penetration testing techniques.
  • Familiarity with web servers and API security, including common misconfigurations and patch management practices.
  • Ability to collaborate effectively across cross-functional teams and communicate complex technical issues clearly.
  • Required Skills & Qualifications

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field (preferred).
  • Current government security clearance : Public Trust.
  • Preferred Qualifications

  • Professional certifications such as GWAPT, CEH, CISSP, CSSLP, or OSWE.
  • Experience integrating web application vulnerability scanning into DevSecOps pipelines.
  • Familiarity with cloud-based web application security, including AWS WAF, Azure App Service Security, and containerized environments.
  • Experience supporting federal cybersecurity compliance frameworks such as FedRAMP, FISMA, and NIST RMF.
  • #J-18808-Ljbffr

    Create a job alert for this search

    Subject Matter Expert • Bethesda, MD, United States

    Related jobs
    Product Security Engineer

    Product Security Engineer

    VirtualVocations • Washington, District of Columbia, United States
    Full-time
    A company is looking for a Product Security Engineer to maintain and enhance its Product Security Program.Key Responsibilities Lead Product Security Vulnerability Management efforts and ensure ti...Show more
    Last updated: 30+ days ago • Promoted
    Cybersecurity Subject Matter Expert

    Cybersecurity Subject Matter Expert

    VirtualVocations • Alexandria, Virginia, United States
    Full-time
    A company is looking for a Cybersecurity Technology Management Analyst.Key Responsibilities Serve as the Cybersecurity Subject Matter Expert (SME) for cybersecurity architecture policies, standar...Show more
    Last updated: 30+ days ago • Promoted
    Information Security Specialist II

    Information Security Specialist II

    Oceaneering International, Inc. • Hanover, MD, United States
    Full-time
    Oceaneering Technologies (OTECH) develops, manufactures, and operates customized marine systems, shipboard equipment, subsea vehicles, and engineered solutions for commercial and U.Oceaneering Aero...Show more
    Last updated: 9 days ago • Promoted
    Advanced Security Engineer - Cyber Security

    Advanced Security Engineer - Cyber Security

    Relativity • Washington, DC, United States
    Full-time
    As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...Show more
    Last updated: 30+ days ago • Promoted
    Information Security Engineer

    Information Security Engineer

    VirtualVocations • Baltimore, Maryland, United States
    Full-time
    A company is looking for an Information Security Engineer III.Key Responsibilities Monitor cybersecurity devices and investigate events and incidents Escalate or mitigate incidents and conduct c...Show more
    Last updated: 30+ days ago • Promoted
    Application Security Engineer

    Application Security Engineer

    VirtualVocations • Rockville, Maryland, United States
    Full-time
    A company is looking for an Application Security Engineer - 100% Remote.Key Responsibilities Develop and implement a complete security stack for endpoint management, vulnerability management, and...Show more
    Last updated: 30+ days ago • Promoted
    Lead Security Engineer - Cyber Security

    Lead Security Engineer - Cyber Security

    Relativity • Baltimore, MD, United States
    Full-time
    As a Lead Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging threat...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    VirtualVocations • Baltimore, Maryland, United States
    Full-time
    Application Security Engineer / Sr.Product Security Engineer (Remote).Key Responsibilities Collaborate with product and engineering teams to integrate security throughout the software development l...Show more
    Last updated: 30+ days ago • Promoted
    Application Security Advisor

    Application Security Advisor

    US Tech Solutions, Inc. • Reston, VA, US
    Temporary
    Duration : 6+ Months Contract (Hybrid) Description : The role that we are looking for is on the advisor team and what we do is we are integrated into the development squads to help them fix vulnerabi...Show more
    Last updated: 30+ days ago • Promoted
    Web Application Developer

    Web Application Developer

    VirtualVocations • Baltimore, Maryland, United States
    Full-time
    A company is looking for a Web Application Developer (Remote).Key Responsibilities Configure and maintain a variety of AWS services and provide technical support for cloud networking and security...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Analyst

    Senior Security Analyst

    VirtualVocations • Baltimore, Maryland, United States
    Full-time
    Security Analyst, Falcon Complete (Hybrid).Key Responsibilities Exercise incident handling processes across Windows, Mac, and Linux platforms Perform malware analysis and develop processes for i...Show more
    Last updated: 30+ days ago • Promoted
    Web Application Security SME / Technical Lead - NIH

    Web Application Security SME / Technical Lead - NIH

    cFocus Software Incorporated • Rockville, MD, US
    Full-time
    Quick Apply
    Web Application Security Subject-Matter Expert / Technical Lead Overview cFocus Software is seeking a Web Application Security Subject-Matter Expert (SME) / Technical Lead to provide advanced techn...Show more
    Last updated: 7 days ago
    Information Security Analyst

    Information Security Analyst

    VirtualVocations • Washington, District of Columbia, United States
    Full-time
    A company is looking for an Information Security Tech Analyst Jr.Key Responsibilities Administer and maintain security tools, monitoring alerts for cybersecurity threats Investigate and respond ...Show more
    Last updated: 30+ days ago • Promoted
    Information Security Architect

    Information Security Architect

    VirtualVocations • Alexandria, Virginia, United States
    Full-time
    A company is looking for an Information Security Lead Architect.Key Responsibilities Develop and implement information security architecture strategy and roadmap Provide guidance and oversight t...Show more
    Last updated: 30+ days ago • Promoted
    Web Application Security Subject-Matter Expert / Technical Lead

    Web Application Security Subject-Matter Expert / Technical Lead

    General Dynamics Information Technology • Bethesda, MD, United States
    Full-time
    General Dynamics Information Technology (GDIT) is seeking a knowledgeable and experienced Web Application Security Subject-Matter Expert / Technical Lead to support one of our federal customers on an...Show more
    Last updated: 2 days ago • Promoted
    Cyber Security Engineer Lead

    Cyber Security Engineer Lead

    ManTech • Springfield, VA, US
    Full-time
    The Cyber Security Engineer Lead is responsible for the detection, identification, analysis, and reporting of cyber threats, intrusions, anomalous activities, and potential misuse of systems.This r...Show more
    Last updated: 2 days ago • Promoted
    NAVAIR - Software Development and Acquisitions Analyst

    NAVAIR - Software Development and Acquisitions Analyst

    SimVentions, Inc • Barstow, MD, US
    Full-time
    SimVentions is a 100% employee-owned business and has consistently been voted one of Virginia's Best Places to Work.We are seeking a detail-oriented candidate with extensive knowledge of computer o...Show more
    Last updated: 2 days ago • Promoted
    Operational Technology Security Analyst

    Operational Technology Security Analyst

    VirtualVocations • Rockville, Maryland, United States
    Full-time
    A company is looking for an Operational Technology Security Analyst to support the delivery of Operational Technology security services. Key Responsibilities Assist with delivering OT services inc...Show more
    Last updated: 3 days ago • Promoted