Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Web Application Security Subject Matter Expert / Technical Lead image - Rise Careers
Job details

Web Application Security Subject Matter Expert / Technical Lead

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Fast Facts

Cybervance is seeking an experienced Web Application Security Subject Matter Expert/Technical Lead to oversee enterprise web application security operations, including vulnerability assessments and secure coding practices.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Responsibilities: Key responsibilities include leading web application security operations, conducting vulnerability assessments, collaborating with development teams for remediation, and providing technical leadership in secure application development.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Skills: Required skills include hands-on experience with web vulnerability assessment tools, secure coding practices, and the ability to analyze and communicate vulnerability findings effectively.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Qualifications: Preferred qualifications include a degree in a relevant field, current government security clearance, and certifications like GWAPT or CISSP.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Location: The job is based in Bethesda, MD, with a hybrid work model.

liETtVLaARqgmMEbYzHNNLIzUPcdfPrwhYtVK7Qa.png Compensation: Not provided by employer. Typical compensation ranges for this position are between $120,000 - $180,000.




image.png

Position Title: Web Application Security Subject Matter Expert / Technical Lead

Location: Bethesda, MD | Hybrid- Not Remote

Cybervance is a rapidly growing information security and information technology company based in Washington, D.C., and we are an equal opportunity employer. We design, develop, and manage the successful execution of training programs for government and private sector organizations. Cybervance believes in creating innovative solutions to deliver measured results.

We are seeking an experienced Web Application Security Subject-Matter Expert (SME) / Technical Lead to provide expert-level guidance and technical oversight for enterprise web application security operations. The SME will lead vulnerability assessments, secure coding reviews, and remediation strategies to protect mission-critical applications from cyber threats and ensure compliance with organizational and federal security standards.

This role requires deep hands-on experience with web application vulnerability assessment tools, application security frameworks, and remediation practices. The ideal candidate will possess both the technical depth to identify vulnerabilities and the leadership skills to drive enterprise-level mitigation and continuous improvement.

Responsibilities

  • Lead web application security operations across enterprise environments, including vulnerability assessment, threat modeling, and secure application architecture reviews.
  • Operate and maintain automated and manual web vulnerability assessment tools to identify misconfigurations, missing patches, insecure code, and other weaknesses that could expose applications to cyberattacks.
  • Analyze and interpret vulnerability assessment results, translating findings into actionable remediation plans and risk-reduction strategies.
  • Develop and implement processes for prioritizing vulnerabilities, ensuring critical weaknesses are addressed first, and remediation efforts align with organizational risk management priorities.
  • Collaborate with developers, DevOps teams, and system owners to remediate findings in application code and configurations.
  • Secure web application platforms built on Python, PHP, Java/JavaScript, C#, and SQL by ensuring adherence to secure coding and configuration best practices.
  • Develop and maintain content and reporting mechanisms, including dashboards and metrics for vulnerability remediation progress, compliance tracking, and management reporting.
  • Provide technical leadership and mentoring to cybersecurity engineers and developers on secure application development and vulnerability mitigation techniques.
  • Recommend and implement enhancements to web application security tools, processes, and automation for continuous improvement.
  • Stay current on emerging web vulnerabilities, exploitation techniques, and best practices for defense-in-depth and web security hardening.

Experience

  • Demonstrated experience operating web vulnerability assessment tools (e.g., Burp Suite, Acunetix, Qualys Web Application Scanner, OWASP ZAP, or equivalent).
  • Proven ability to analyze and interpret vulnerability scan results and communicate findings to technical and non-technical stakeholders.
  • Hands-on experience securing web application platforms, including Python, PHP, Java/JavaScript, C#, and SQL-based applications.
  • Experience prioritizing vulnerabilities and remediation activities to address high-risk issues efficiently.
  • Demonstrated ability to develop content, dashboards, and reports to monitor vulnerability status, remediation progress, and compliance posture.
  • Strong understanding of OWASP Top 10, secure software development lifecycle (SDLC), and web application penetration testing techniques.
  • Familiarity with web servers and API security, including common misconfigurations and patch management practices.
  • Ability to collaborate effectively across cross-functional teams and communicate complex technical issues clearly.

Required Skills & Qualifications

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field (preferred).
  • Current government security clearance: Public Trust.

Preferred Qualifications

  • Professional certifications such as GWAPT, CEH, CISSP, CSSLP, or OSWE.
  • Experience integrating web application vulnerability scanning into DevSecOps pipelines.
  • Familiarity with cloud-based web application security, including AWS WAF, Azure App Service Security, and containerized environments.
  • Experience supporting federal cybersecurity compliance frameworks such as FedRAMP, FISMA, and NIST RMF.

Average salary estimate

$150000 / YEARLY (est.)
min
max
$120000K
$180000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs

Cybervance is hiring a Chief Cybersecurity Engineer to lead enterprise cybersecurity architecture and FedRAMP-aligned security for hybrid on-premises and cloud environments.

Experienced endpoint vulnerability management SME and technical lead needed to oversee scanning, analysis, SIEM integration, and remediation coordination across cloud, on-prem, and OT environments for Cybervance in Bethesda, MD.

Photo of the Rise User

Experienced Senior Firewall Administrator needed to lead Palo Alto firewall operations, policy management, and network security engineering for a regulated IT environment.

Photo of the Rise User

True Zero Technologies seeks a Cribl Engineer to architect, deploy, and support Cribl LogStream-based log management solutions for clients while expanding platform use and delivering technical enablement.

Photo of the Rise User
Jobgether Hybrid No location specified
Posted 21 hours ago

Senior IT leader wanted to own enterprise Salesforce strategy and multi-cloud implementations, driving scalable, compliant solutions and leading a high-performing delivery organization in a remote US role.

Photo of the Rise User

Senior technology leader needed to architect and execute a comprehensive IT strategy, lead digital transformation, and manage ITS operations at North Carolina A&T State University.

Photo of the Rise User
Allegiant Hybrid Las Vegas, NV
Posted 3 hours ago

Allegiant Air seeks a Trax Analyst to manage Trax configuration, troubleshooting, testing, and user documentation to improve MRO and supply-chain processes.

Posted 9 hours ago

Amentum is hiring an Associate System Administrator in McLean, VA to support and maintain secure Windows/network infrastructure with an active Top Secret/SCI clearance required.

Photo of the Rise User

Lead and scale Americas network architecture and operations for a global technology services firm, driving security, reliability, and strategic network initiatives across on-prem and cloud environments.

Photo of the Rise User

Florida State University is hiring a Systems Administrator/Program to architect and administer cloud collaboration platforms (Google Workspace, Azure, Office 365, Zoom) and lead automation and integration efforts.

Experienced Senior Network Administrator & Systems Engineer needed at a long-standing MSP to lead escalations, design secure multi-site environments, and mentor support teams from the Delray Beach office.

Photo of the Rise User

Lead Learning Ally’s Enterprise Systems team to modernize SaaS, CRM, and ERP platforms and drive scalable technology solutions that support educators and learners.

Photo of the Rise User
Inclusive & Diverse
Collaboration over Competition
Growth & Learning
Transparent & Candid

Affirm is hiring a Staff Endpoint Engineer to lead and scale macOS endpoint management, automation, and security for its remote-first employee platform.

Senior Security Engineer needed to lead SIEM optimization, cloud and on-prem security hardening, and compliance efforts for a federal-focused cybersecurity firm in Bethesda, MD.

Photo of the Rise User
Posted 15 hours ago

Experienced PAM operations leader needed to manage CyberArk platforms and service delivery for a global data and technology company, ensuring stability, compliance, and strong operational performance.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
HQ LOCATION
No info
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
October 25, 2025
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!