Web Developer Security Engineer at MicroTech
Washington, DC
—
Jul 6, 2026
Washington, DC
Jul 21, 2026
What this job asks for AI summary
A security engineering role focused on protecting web applications, APIs, and cloud services across the full development lifecycle. Day-to-day work spans vulnerability assessment and remediation, embedding security controls into CI/CD pipelines, configuring WAFs and monitoring tools, and supporting federal compliance frameworks such as NIST SP 800-53 and FedRAMP. The role also involves advising development teams on secure architecture and contributing to incident response and audit activities.
Mid level · 3+ years · National · Bachelor's required · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $106,594 (middle half $82,076–$136,109).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
SOC classification is a genuine toss-up: the role blends application security engineering (15-1212) with hands-on web/software development (.NET, React, Python scripting). 15-1212 was chosen because the primary framing is security — vulnerability management, DevSecOps integration, WAF/FIM configuration, compliance, and incident response — but a strong case exists for 15-1252 given the depth of development-stack requirements.
Location is not stated anywhere in the posting. MicroTech is headquartered in the Washington, DC area and primarily serves federal clients, but no work location or remote policy is specified; remote is marked false as a conservative default.
The clearance requirement is ambiguous: the posting states 'ability to meet all government personnel security and access requirements associated with the program' but does not name a specific clearance level or gate on holding an active clearance. This is treated as a general suitability requirement rather than a hard clearance gate.
Python is listed as the primary scripting language with Node.js, TypeScript, and Java as named alternatives in the same requirement ('Python, JavaScript/Node.js, TypeScript, Java, React.js, or similar'). React.js was separated because it is a distinct front-end framework rather than a scripting-language substitute.
The six preferred certifications (CSSLP, GWEB, CASE, OSWE, OSCP, Security+, GSEC) appear under a 'Preferred Certifications' heading and are listed as preferred, despite the heading saying 'Candidate must have all of the following' — this is internally contradictory. Because the section is explicitly labeled 'Preferred Certifications' (a secondary heading), they are treated as preferred rather than hard gates.
NIST SP 800-53, FISMA, and FedRAMP appear in both the responsibilities narrative and the Preferred Qualifications section. They are marked preferred because the Preferred Qualifications section is the authoritative placement for these as explicit requirements.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.