Talent.com
Web Application Security Subject Matter Expert / Technical Lead
Web Application Security Subject Matter Expert / Technical LeadCybervance • Bethesda, MD, United States
Web Application Security Subject Matter Expert / Technical Lead

Web Application Security Subject Matter Expert / Technical Lead

Cybervance • Bethesda, MD, United States
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Position Title : Web Application Security Subject Matter Expert / Technical Lead

Location : Bethesda, MD | Hybrid- Not Remote

Cybervance is a rapidly growing information security and information technology company based in Washington, D.C., and we are an equal opportunity employer. We design, develop, and manage the successful execution of training programs for government and private sector organizations. Cybervance believes in creating innovative solutions to deliver measured results.

We are seeking an experienced Web Application Security Subject-Matter Expert (SME) / Technical Lead to provide expert-level guidance and technical oversight for enterprise web application security operations. The SME will lead vulnerability assessments, secure coding reviews, and remediation strategies to protect mission-critical applications from cyber threats and ensure compliance with organizational and federal security standards.

This role requires deep hands-on experience with web application vulnerability assessment tools, application security frameworks, and remediation practices. The ideal candidate will possess both the technical depth to identify vulnerabilities and the leadership skills to drive enterprise-level mitigation and continuous improvement.

Responsibilities

  • Lead web application security operations across enterprise environments, including vulnerability assessment, threat modeling, and secure application architecture reviews.
  • Operate and maintain automated and manual web vulnerability assessment tools to identify misconfigurations, missing patches, insecure code, and other weaknesses that could expose applications to cyberattacks.
  • Analyze and interpret vulnerability assessment results, translating findings into actionable remediation plans and risk-reduction strategies.
  • Develop and implement processes for prioritizing vulnerabilities, ensuring critical weaknesses are addressed first, and remediation efforts align with organizational risk management priorities.
  • Collaborate with developers, DevOps teams, and system owners to remediate findings in application code and configurations.
  • Secure web application platforms built on Python, PHP, Java / JavaScript, C#, and SQL by ensuring adherence to secure coding and configuration best practices.
  • Develop and maintain content and reporting mechanisms, including dashboards and metrics for vulnerability remediation progress, compliance tracking, and management reporting.
  • Provide technical leadership and mentoring to cybersecurity engineers and developers on secure application development and vulnerability mitigation techniques.
  • Recommend and implement enhancements to web application security tools, processes, and automation for continuous improvement.
  • Stay current on emerging web vulnerabilities, exploitation techniques, and best practices for defense-in-depth and web security hardening.

Experience

  • Demonstrated experience operating web vulnerability assessment tools (e.g., Burp Suite, Acunetix, Qualys Web Application Scanner, OWASP ZAP, or equivalent).
  • Proven ability to analyze and interpret vulnerability scan results and communicate findings to technical and non-technical stakeholders.
  • Hands-on experience securing web application platforms, including Python, PHP, Java / JavaScript, C#, and SQL-based applications.
  • Experience prioritizing vulnerabilities and remediation activities to address high-risk issues efficiently.
  • Demonstrated ability to develop content, dashboards, and reports to monitor vulnerability status, remediation progress, and compliance posture.
  • Strong understanding of OWASP Top 10, secure software development lifecycle (SDLC), and web application penetration testing techniques.
  • Familiarity with web servers and API security, including common misconfigurations and patch management practices.
  • Ability to collaborate effectively across cross-functional teams and communicate complex technical issues clearly.
  • Required Skills & Qualifications

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field (preferred).
  • Current government security clearance : Public Trust.
  • Preferred Qualifications

  • Professional certifications such as GWAPT, CEH, CISSP, CSSLP, or OSWE.
  • Experience integrating web application vulnerability scanning into DevSecOps pipelines.
  • Familiarity with cloud-based web application security, including AWS WAF, Azure App Service Security, and containerized environments.
  • Experience supporting federal cybersecurity compliance frameworks such as FedRAMP, FISMA, and NIST RMF.
  • #J-18808-Ljbffr

    serp_jobs.job_alerts.create_a_job

    Subject Matter Expert • Bethesda, MD, United States

    Job_description.internal_linking.related_jobs
    Adjunct, Information Technology

    Adjunct, Information Technology

    InsideHigherEd • Frederick, Maryland, United States
    serp_jobs.job_card.part_time
    Adjunct, Information Technology.Frederick Community College (FCC) is seeking dynamic and knowledgeable adjunct instructors to teach hybrid courses in the information technology and cybersecurity.Ca...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Application Security Analyst - US Cit, GC, GC / EAD- no H1B candidates

    Application Security Analyst - US Cit, GC, GC / EAD- no H1B candidates

    USM • Vienna, VA, US
    serp_jobs.job_card.full_time
    System Integrator, Software and Product Development, IT Outsourcing and Technology assistance supplier headquartered in Chantilly, VA with off-shore delivery centers in India.We offer world-class a...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Security Information Systems Analyst Staff

    Security Information Systems Analyst Staff

    Lockheed Martin • Herndon, VA, US
    serp_jobs.job_card.full_time
    The Security Information Systems Analyst Staff performs a variety of activities in information systems design, development, and analysis encompassing one or more of the following areas of technical...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    NAVAIR - Software Developer Analyst

    NAVAIR - Software Developer Analyst

    SimVentions, Inc - Glassdoor 4.6 • Hughesville, MD, US
    serp_jobs.job_card.temporary
    SimVentions is a 100% employee-owned business and has consistently been voted one of Virginia's Best Places to Work.We are seeking a detail-oriented candidate with extensive knowledge of computer o...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    SharePoint Developer (REMOTE / NO C2C) (Germantown)

    SharePoint Developer (REMOTE / NO C2C) (Germantown)

    Amerit Consulting • Germantown, MD, US
    serp_jobs.filters.remote
    serp_jobs.job_card.part_time +1
    Our client, a US Fortune 50 organization and a leading provider of Health care and Health Insurance services, seeks an accomplished. NOTE : THIS IS REMOTE ROLE & ONLY W2 CANDIDATES (NO C2C / 1099).Cand...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Senior Manager - Global Payment Network Information Security Office (ISO) Consultant

    Senior Manager - Global Payment Network Information Security Office (ISO) Consultant

    Capital One • Baltimore, MD, US
    serp_jobs.job_card.full_time +1
    Senior Manager - Global Payment Network Information Security Office (ISO) Consultant.At Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    SharePoint Developer (REMOTE / NO C2C) (Frederick)

    SharePoint Developer (REMOTE / NO C2C) (Frederick)

    Amerit Consulting • Frederick, MD, US
    serp_jobs.filters.remote
    serp_jobs.job_card.part_time +1
    Our client, a US Fortune 50 organization and a leading provider of Health care and Health Insurance services, seeks an accomplished. NOTE : THIS IS REMOTE ROLE & ONLY W2 CANDIDATES (NO C2C / 1099).Cand...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Web Application Security SME / Technical Lead - NIH

    Web Application Security SME / Technical Lead - NIH

    cFocus Software Incorporated • Rockville, MD, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Web Application Security Subject-Matter Expert / Technical Lead Overview cFocus Software is seeking a Web Application Security Subject-Matter Expert (SME) / Technical Lead to provide advanced techn...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days
    Subject Matter Expert - Level IV

    Subject Matter Expert - Level IV

    EmergencyMD • Bethesda, MD, United States
    serp_jobs.job_card.full_time
    Nalu Federal is a subsidiary company of the Kanaka Foundation - An NHO who's mission is to support Native Hawaiians.You will receive a comprehensive benefits package that includes : .Annual membershi...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Web Application Security Subject-Matter Expert / Technical Lead

    Web Application Security Subject-Matter Expert / Technical Lead

    General Dynamics Information Technology • Bethesda, MD, United States
    serp_jobs.job_card.full_time
    General Dynamics Information Technology (GDIT) is seeking a knowledgeable and experienced Web Application Security Subject-Matter Expert / Technical Lead to support one of our federal customers on an...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Enterprise Functional Applications and Security Analyst

    Enterprise Functional Applications and Security Analyst

    InsideHigherEd • Bowie, Maryland, United States
    serp_jobs.job_card.permanent
    JR101151 Enterprise Functional Applications and Security Analyst (Open).This is a lead functional and security role within Information Technology (IT). The IT Enterprise Functional Applications & Se...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Faculty Member, Cybersecurity / Information Technology

    Faculty Member, Cybersecurity / Information Technology

    InsideHigherEd • Frederick, Maryland, United States
    serp_jobs.job_card.full_time +1
    Faculty Member, Cybersecurity / Information Technology.The ­­­­­Cybersecurity / Information Technology faculty position supports the Cybersecurity and Information Technology programs and strategic oper...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Information Technology_USA - USA_Project Manager

    Information Technology_USA - USA_Project Manager

    Artech • Frederick, MD, US
    serp_jobs.job_card.full_time
    Required Skills & Qualifications : .Applicants must be able to work directly for Artech on W2.Bachelor's degree in Engineering, Computer Science, or related field. Minimum of 10 years of experience in...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Tech Lead, Web Core Product & Chrome Extension - Baltimore, USA

    Tech Lead, Web Core Product & Chrome Extension - Baltimore, USA

    Speechify • Baltimore, MD, US
    serp_jobs.job_card.full_time
    Tech Lead, Web Core Product & Chrome Extension - Baltimore, USA.Speechify's mission is to eliminate reading barriers.Over 50 million people use Speechify's text-to-speech products—PDFs, books, ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Cyber Security Engineer Lead

    Cyber Security Engineer Lead

    ManTech • Springfield, VA, US
    serp_jobs.job_card.full_time
    The Cyber Security Engineer Lead is responsible for the detection, identification, analysis, and reporting of cyber threats, intrusions, anomalous activities, and potential misuse of systems.This r...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    NAVAIR - Software Development and Acquisitions Analyst

    NAVAIR - Software Development and Acquisitions Analyst

    SimVentions, Inc • Barstow, MD, US
    serp_jobs.job_card.full_time
    SimVentions is a 100% employee-owned business and has consistently been voted one of Virginia's Best Places to Work.We are seeking a detail-oriented candidate with extensive knowledge of computer o...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Cyber Security Protect Analyst Lead

    Cyber Security Protect Analyst Lead

    TekSynap • Fort Belvoir, VA, US
    serp_jobs.job_card.full_time
    The Protect team serves as the Subscriber Cybersecurity Liaison and provides dedicated cybersecurity support.The following are required responsibilities for this position : .Vulnerability Analysis an...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Cyber Security Legislative Analyst

    Cyber Security Legislative Analyst

    Cape Fox Shared Services • Arlington, VA, US
    serp_jobs.job_card.full_time
    Cyber Security Legislative Analyst.Kwaan Tech is seeking a highly qualified Cyber Security Legislative Analyst to provide Cyber Security Legislative Support Services in support of the Bureau of Dip...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted