Essnova Solutions, Inc.

Web Application Security Engineer (AppSec / DevSecOps)

Essnova Solutions, Inc.  •  Washington, DC (Hybrid)  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Location: Washington, DC Metropolitan Area (Hybrid)

Employment Type: Full-Time

Clearance: Public Trust (Tier 2) or ability to obtain*

About Essnova Solutions

Essnova Solutions is a growing technology consulting firm delivering innovative IT, cloud, cybersecurity, engineering, and digital transformation solutions to Federal Government clients. We are committed to technical excellence, collaboration, and providing our employees with opportunities to solve complex mission challenges.

Essnova Solutions is seeking an experienced Web Application Security Engineer to support a federal customer by integrating security throughout the software development lifecycle (SDLC) and protecting enterprise web applications and APIs from evolving cyber threats. The ideal candidate has experience with application security, secure software development, vulnerability management, DevSecOps, and federal cybersecurity frameworks.

Key Responsibilities

  • Embed security throughout the Software Development Lifecycle (SDLC).
  • Perform web application vulnerability assessments, penetration support, and threat modeling activities.
  • Identify, prioritize, and remediate application security vulnerabilities.
  • Implement secure coding standards aligned with OWASP Top 10 and industry best practices.
  • Configure and maintain Web Application Firewalls (WAF) and application security controls.
  • Integrate application security tools into CI/CD pipelines and DevSecOps workflows.
  • Monitor application logs and investigate security events affecting web applications and APIs.
  • Collaborate with software developers, DevOps engineers, and cybersecurity teams to improve application security posture.
  • Support compliance with NIST, FISMA, FedRAMP, and other federal cybersecurity standards.
  • Develop security documentation, technical recommendations, and remediation guidance.

Required Qualifications

  • Experience in Application Security (AppSec), Web Application Security, or Product Security.
  • Strong knowledge of secure software development practices and Secure SDLC.
  • Experience performing vulnerability assessments, threat modeling, and application security testing.
  • Knowledge of OWASP Top 10, common web application vulnerabilities, and remediation techniques.
  • Experience implementing or supporting Web Application Firewalls (WAF).
  • Experience integrating security into CI/CD pipelines and DevSecOps environments.
  • Familiarity with federal cybersecurity frameworks including NIST and FedRAMP.
  • Excellent analytical, troubleshooting, and communication skills.

Preferred Qualifications

  • Experience with SAST, DAST, Software Composition Analysis (SCA), or similar application security tools.
  • Experience with secure code reviews and developer security training.
  • Experience supporting cloud-native applications within AWS and/or Microsoft Azure.
  • Experience supporting federal government or highly regulated environments.
  • Relevant security certifications such as:
    • CSSLP
    • OSCP
    • OSWE
    • GWEB
    • CASE
    • Security+
    • GSEC

Clearance

  • Public Trust (Tier 2) clearance or the ability to obtain and maintain one.*

Why Join Essnova?

At Essnova Solutions, you'll join a collaborative team supporting high-impact federal technology initiatives. We invest in our employees by providing opportunities to work with modern cloud technologies, cybersecurity best practices, and mission-critical systems that make a real difference.

Essnova Solutions, Inc.

About Essnova Solutions, Inc.

Ranked at 163 in the INC. magazine’s prestigious list of 500 fastest growing companies in the U.S, Essnova is an award winning, and mature small business offering broad range of technology and programmatic support services to the governmental and commercial customers. Essnova’s CEO is proud to be awarded with the Alabama’s SBA 2020 Small Business Person of the Year recognition.

We offer specialization in SETA Services, Geospatial, Environmental and Medical Services. Our Technology Integration/VAR reseller unit augments our services with SME Support, products and licensing from hundreds of manufacturers.

Essnova offers a highly capable management team, delivering mature management services as demonstrated by our Federal and commercial exceptional past performance. We utilize ISO-registered commercial best practices to deliver highly efficient and responsive solutions. Our team works diligently to ensure that we continue to be the world-class small business in our customers’ vendor portfolio.

Comprised of solution architects, engineers, subject matter experts – Team Essnova stands ready to assist our customers with deploying enterprise, agency wide solutions from assessment, concept, design, technology solutions procurement, implementation, training and ongoing maintenance and management.

We are the American Dream- a company comprised of normal everyday people who have a shared vision of being a contributing part of how this country and its people communicate, work together, and share together through technology and connection. This vision is what gives us the continued drive and excitement of working with the Federal agencies and Commercial organizations that are our clients, who all share our desire and goal to facilitate the implementation of systems and services that help communication and collaboration expand and be available to all who can benefit.

Industry
IT & Software
Company Size
11-50 employees
Headquarters
Birmingham, Alabama
Year Founded
2005
Social Media