Web Developer Security Engineer at DMI
$77,800–$85,341from the description
Jul 5, 2026
—
Jul 21, 2026
What this job asks for AI summary
A hybrid developer-security role supporting a federal agency client, focused on finding and fixing vulnerabilities in web applications and APIs, embedding security controls across the software development lifecycle, and maintaining compliance with federal frameworks such as NIST SP 800-53 and FedRAMP. The work spans WAF and FIM deployment, CI/CD security gate automation, log analysis, and threat modeling, suiting someone with a background in both application development and AppSec engineering.
Mid level · 3+ years · Remote · Bachelor's required · Secret clearance
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
This role sits squarely at the intersection of application security and software development. 15-1212 (Information Security Analysts) was chosen as primary because the core mandate — vulnerability identification/remediation, WAF/FIM deployment, compliance with NIST/FISMA/FedRAMP, and security operations support — is security-analyst work; 15-1252 (Software Developers) is the close runner-up given the hands-on coding requirements (.NET/C#, JavaScript, DevSecOps pipeline automation).
The posted salary range ($77,800–$85,341/year) is labeled 'Minimum' and 'Median' rather than a standard min/max band; the true maximum is not stated. Both figures are captured as-is.
Wireshark, SIEM, IDS/IPS, NDR, and EDR appear under 'Familiarity with security testing tools' — framed as familiarity rather than a hard gate; listed as preferred. NDR and EDR were omitted as they name categories rather than specific tools.
AI-assisted development tools (GitHub Copilot, OpenAI API) are framed with 'Ability to leverage' — aspirational rather than a hard gate; listed as preferred with alternatives.
Active security certifications (AppSec, offensive security, foundational security) are required per the qualifications section but name no specific certification product, so no skill entry was created.
The clearance requirement states 'must possess or be eligible to obtain' a Secret clearance — this is treated as a hard gate at the Secret level.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.
Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.