Web Application Security SME/Technical Lead
MBL Technologies Inc.About the role
Description
MBL Technologies, Inc. offers a diverse set of management and technology consulting services to Federal government and commercial markets. Our solutions are tailored to support each client’s mission, accounting for their unique needs and operating environments to ensure success. We bring the right people, capabilities, and expertise together to assist our clients with enabling their mission. Together our individual differences drive successful business results.
If you are transitioning from military to civilian life, have prior service, are a retired veteran, or a member of the National Guard or Reserves, or spouse of an active military service member, we encourage you to apply. Please visit our webpage for information on our policies and benefits for the military and veteran community.
Why Work with Us?
- We trust, empower, and believe in our employees to soar to their fullest potential!
- We offer a robust benefits package (medical, dental, vision, STD, Accident, Life, Hospital Insurance, FSA, HSA, 401K match, professional development stipend, etc.).
- We love to have fun and give back to the community. Community Service and Employee Engagement events are atop our calendar events!
- We genuinely like each other and champion everyone to achieve their own greatness!
MBL Technologies is seeking a Web Application Security Subject-Matter Expert (SME) / Technical Lead to provide expert technical support and leadership for a federal cybersecurity program. The SME will lead efforts to identify, assess, and mitigate vulnerabilities across web-based systems and applications, ensuring the protection of mission-critical platforms and data from cyber threats. This role requires deep technical proficiency with web application architectures, security assessment tools, and vulnerability remediation practices, as well as the ability to mentor team members and collaborate with stakeholders across the federal enterprise.
This role is mostly remote; however, it will require occasional onsite meetings in the Bethesda, MD area. With no travel reimbursements allocated. This role is contingent based on contract award.
Key Responsibilities:
- Lead the design, implementation, and management of the agency’s web application security program, ensuring alignment with federal cybersecurity policies and frameworks.
- Operate and maintain automated and manual web application vulnerability assessment tools to detect weaknesses such as misconfigurations, missing patches, insecure coding practices, and other security flaws.
- Analyze, interpret, and validate scan results, providing actionable recommendations for remediation and risk reduction.
- Develop and maintain custom scripts, test cases, or configurations to enhance application vulnerability detection and validation.
- Coordinate vulnerability testing across production, staging, and development environments to ensure comprehensive security coverage.
- Serve as the primary technical lead and subject-matter expert for web application security assessments, remediation planning, and vulnerability management strategies.
- Collaborate with developers, system administrators, and cybersecurity operations teams to prioritize and remediate vulnerabilities efficiently.
- Provide guidance on secure coding practices and assist in the development of security standards for web applications and APIs.
- Prioritize findings based on exploitability, potential impact, and risk, ensuring that the most critical vulnerabilities are addressed first.
- Develop and maintain content such as reports, dashboards, and data visualizations to communicate remediation status, risk trends, and vulnerability metrics.
- Provide executive-level and technical reporting on web application security posture, remediation progress, and compliance status.
- Identify systemic weaknesses and propose long-term improvements to enhance application security controls and processes.
- Stay current with emerging web application threats, vulnerabilities, and mitigation technologies to continuously evolve program effectiveness.
Required Qualifications / Skills:
- Demonstrated experience operating and managing web application vulnerability assessment tools (e.g., Burp Suite, Acunetix, Netsparker, Qualys WAS, or OWASP ZAP).
- Strong technical understanding of web application platforms, languages, and frameworks, including Python, PHP, Java/JavaScript, C#, and SQL.
- Proven ability to analyze and interpret vulnerability scan data, develop risk-based remediation plans, and track
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s