Talent.com
Web Application Security SME / Technical Lead - NIH

Web Application Security SME / Technical Lead - NIH

cFocus Software IncorporatedRockville, MD, US
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
  • serp_jobs.filters_job_card.quick_apply
job_description.job_card.job_description

Web Application Security Subject-Matter Expert / Technical Lead Overview cFocus Software is seeking a Web Application Security Subject-Matter Expert (SME) / Technical Lead to provide advanced technical guidance and leadership in securing federal web applications and platforms.

The SME / Technical Lead will operate vulnerability assessment tools, analyze application security weaknesses, and develop dashboards and reports to track remediation efforts.

This role requires a deep understanding of application security principles, secure coding practices, and vulnerability management across various development environments.

This is a full-time position that may require on-site support at federal agency locations in the Washington, D.C. metro area.

Some telework flexibility may be available depending on mission requirements.   Must be able to obtain and maintain a Public Trust or higher-level security clearance as required by the agency.

Responsibilities The Web Application Security SME / Technical Lead shall perform duties that include, but are not limited to :

  • Lead the execution of web application vulnerability assessments using both automated and manual tools to identify security flaws, misconfigurations, and missing patches.
  • Analyze and interpret scan results to identify exploitable vulnerabilities, prioritize findings, and recommend appropriate remediation strategies.
  • Ensure web applications and associated platforms are configured and maintained in compliance with federal cybersecurity standards and secure coding practices.
  • Operate and maintain web vulnerability assessment tools and integrate results into enterprise dashboards and reporting systems.
  • Develop reporting and dashboards for vulnerability remediation analysis, status tracking, and compliance documentation.
  • Collaborate with software developers, system administrators, and cybersecurity engineers to remediate vulnerabilities and enhance application security posture.
  • Conduct security reviews of web application architectures and provide recommendations for risk mitigation and design improvements.
  • Develop and implement security baselines, policies, and standard operating procedures (SOPs) for web application security.
  • Support security testing and validation during all phases of the software development lifecycle (SDLC).
  • Provide subject-matter expertise for penetration testing, vulnerability management, and continuous monitoring initiatives related to web applications.
  • Required Qualifications Demonstrable knowledge, skills, and experience in operating and maintaining automated or manual tools to identify web application weaknesses such as misconfigurations, missing patches, and other security flaws.
  • Experience operating web vulnerability assessment tools and analyzing and interpreting results.
  • Experience securing web application platforms such as Python, PHP, Java / JavaScript, C#, and SQL.
  • Ability to prioritize findings or configuration settings to address the most critical vulnerabilities first.
  • Experience developing reporting and dashboards for vulnerability remediation analysis, status, and tracking.
  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (preferred).
  • Preferred Qualifications Experience securing federal or DHS web application environments.
  • Knowledge of OWASP Top 10, NIST SP 800-53, and related web application security frameworks.
  • Proficiency with web vulnerability scanning tools such as Burp Suite, Acunetix, Nessus, Qualys, or similar technologies.
  • Experience integrating vulnerability assessment data with SIEM and compliance reporting tools.
  • Strong understanding of secure coding practices, DevSecOps principles, and web application development lifecycles.
  • Ability to communicate complex security findings to developers and executives effectively.
  • About cFocus Software cFocus Software Incorporated provides cybersecurity, cloud, and enterprise IT services to the federal government.
  • Our team of experts delivers innovative solutions that protect critical assets and enable mission success.
  • Equal Employment Opportunity Statement cFocus Software Incorporated is an Equal Opportunity Employer.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.

  • Powered by JazzHR
  • serp_jobs.job_alerts.create_a_job

    Application Security Lead • Rockville, MD, US

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.new
    Vulnerability Management Team Lead - NIH

    Vulnerability Management Team Lead - NIH

    cFocus Software IncorporatedRockville, MD, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Vulnerability Management Team Lead Overview cFocus Software is seeking an experienced Vulnerability Management Team Lead to oversee the development, execution, and continuous improvement of a compr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    Cybersecurity Lead-(Program Manager – Advanced) OR Security Control Assessor – Advanced

    Cybersecurity Lead-(Program Manager – Advanced) OR Security Control Assessor – Advanced

    BTIQuantico, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Business Technology Integrators (BTI), A Service -Disable Veteran Owned Small Business with over 25 years of experience delivering innovative IT Solutions to the Federal Government, is seeking a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Network Security SME, Lead

    Network Security SME, Lead

    Booz Allen HamiltonWashington, DC, United States
    serp_jobs.job_card.full_time +1
    Network Security SME, Lead page is loaded.Apply locations Washington, DC time type Full time posted on Posted 5 Days Ago time left to apply End Date : November 17, 2025 (30+ days left to apply) job ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Information Assurance Sr SME

    Information Assurance Sr SME

    Leidos IncBethesda, MD, United States
    serp_jobs.job_card.temporary
    National Security Sector's (NSS) Cyber & Analytics Business Area (CABA).Our talented team is at the forefront in Security Engineering, Computer Network Operations (CNO), Mission Software, Analytica...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Lead

    Security Lead

    VirtualVocationsRockville, Maryland, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Lead to build and manage its security function across governance, engineering, and operations. Key Responsibilities Own the company's security posture from code...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.new
    Security Infrastructure Support Team Lead - NIH

    Security Infrastructure Support Team Lead - NIH

    cFocus Software IncorporatedRockville, MD, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Security Infrastructure Support Team Lead Overview cFocus Software is seeking a highly experienced Security Infrastructure Support Team Lead to oversee and manage the operation, maintenance, and se...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    Cybersecurity SME (TS / SCI w / FS Poly Req.)

    Cybersecurity SME (TS / SCI w / FS Poly Req.)

    August SchellHerndon, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    A TS / SCI with FULL SCOPE POLYGRAPH IS REQUIRED FOR THIS ROLE Who we are.August Schell offers 30 years of experience in providing our customers innovative solutions and engineering services to...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    SAP Security Specialist III (TS / SCI #25-171)

    SAP Security Specialist III (TS / SCI #25-171)

    Clearance JobsWashington, DC, US
    serp_jobs.job_card.full_time
    Senior Sap Security Specialist.Strategic Analysis, Inc is in search of a Senior Sap Security Specialist who provides expert-level guidance and oversight for all security aspects of Special Access P...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Product Manager, NodeZero Federal

    Senior Product Manager, NodeZero Federal

    Horizon3 AI, Inc.Washington, DC, United States
    serp_jobs.job_card.full_time
    We’re looking for individuals who : .Thrive in high-performing teams.Are passionate about disruption.If you’re eager to grow, driven to contribute, and ready to shape the future of cybersecurity, we ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Information System Security Manager (ISSM)

    Information System Security Manager (ISSM)

    The Johns Hopkins University Applied Physics LaboratoryLaurel, MD, United States
    serp_jobs.job_card.full_time
    Do you love solving problems while enabling impactful research to operate securely?.Are you passionate about making meaningful contributions to national security cyber missions?.Do you like collabo...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Project Manager- Cyber Security

    Senior Project Manager- Cyber Security

    SamprasoftWashington, DC, US
    serp_jobs.job_card.full_time
    The Project Manager - Senior is a member of the Information Security department specific PMO, managing technology projects within the Cyber Security Department.serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Sr. Information Assurance (IA) Team Lead

    Sr. Information Assurance (IA) Team Lead

    Potawatomi Federal SolutionsWashington, District of Columbia, United States
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Information Assurance (IA) Team Lead.The Senior Information Assurance (IA) Team Lead provides enterprise-level leadership and oversight of cybersecurity compliance operations across classified and ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cross Domain Approval Expert

    Cross Domain Approval Expert

    Leidos IncOdenton, MD, United States
    serp_jobs.job_card.full_time
    Leidos has an opportunity for a.DISA Cross Domain Enterprise Services (CDES) effort.This is a technical position that supports both engineering and cross domain areas across multiple doctrines and ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Advanced Security Engineer - Cyber Security

    Advanced Security Engineer - Cyber Security

    RelativityBaltimore, MD, United States
    serp_jobs.job_card.full_time
    As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.new
    Endpoint Vulnerability Management SME / Technical Lead - NIH

    Endpoint Vulnerability Management SME / Technical Lead - NIH

    cFocus Software IncorporatedRockville, MD, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Endpoint Vulnerability Management Subject-Matter Expert / Technical Lead Overview cFocus Software is seeking an Endpoint Vulnerability Management Subject-Matter Expert (SME) / Technical Lead to pro...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    Cybersecurity Assessment & Authorization (A&A) SME

    Cybersecurity Assessment & Authorization (A&A) SME

    Nationwide IT ServicesFort Belvoir, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Cybersecurity Assessment & Authorization (A&A) SME Security Clearance : IT-II Non-Critical Sensitive or Tier 3 (T3) Secret Location : Remote or DLA HQ, Fort Belvoir, VA Certifications : Certif...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    Information Systems Security Engineer (ISSE) - Active TS / SCI with FSP

    Information Systems Security Engineer (ISSE) - Active TS / SCI with FSP

    TOMORROW HIREHerndon, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Herndon / Chantilly and Tysons, VA.TS / SCI with Full Scope Polygraph (FSP).Our Client is seeking an experienced.Information Systems Security Engineer (ISSE). Phoenix program in a fully funded, mission-...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.new
    Continuous Diagnostics and Mitigation (CDM) Team Lead - NIH

    Continuous Diagnostics and Mitigation (CDM) Team Lead - NIH

    cFocus Software IncorporatedRockville, MD, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Continuous Diagnostics and Mitigation (CDM) Team Lead Overview cFocus Software is seeking a Continuous Diagnostics and Mitigation (CDM) Team Lead to manage and oversee the implementation, operation...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Product Manager - AI SecurityHybrid - New York, Hybrid - San Francisco, Remote

    Product Manager - AI SecurityHybrid - New York, Hybrid - San Francisco, Remote

    VercelWashington, DC, US
    serp_jobs.filters.remote
    serp_jobs.job_card.full_time
    Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web.AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour bu...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Technical Lead

    Technical Lead

    Lucayan Technology Solutions LLCChantilly, VA, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Chantilly, VA | 🕒 Full-Time | 🔒 TS / SCI with Polygraph | Onsite Overview Lucayan Technology LLC is hiring a Technical Lead to support mission-critical government cybersec...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days