1

Ciw Web Security Specialist Jobs (NOW HIRING)

$100 - $130/hr

Developing and enforcing security policies * Create and maintain web filtering, SSL inspection, DLP ... specialist expertise, technology solutions and partnership approach to client management. Across ...

$21.82/hr

Security Specialist First Coast Security Solutions provides security services nationwide. The ... At least 1 year of experience working with security-related web-based applications (JPAS, DISS, e ...

$75K - $80K/yr

Description We are looking for a Security Specialist in Washington D.C. to join our team. Top ... Web Fingerprint Transmission Plus Enrollment (SWFT+), and National Background Investigation ...

$75K - $80K/yr

We are looking for a Security Specialist in Washington D.C. to join our team. Top candidates will ... Web Fingerprint Transmission Plus Enrollment (SWFT+), and National Background Investigation ...

next page

Showing results 1-20

Ciw Web Security Specialist information

See salary details

$37.5K

$95K

How much do ciw web security specialist jobs pay per year?

As of Sep 3, 2026, the average yearly pay for ciw web security specialist in the United States is $91,584.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,000.00 and $94,500.00 per year, depending on experience, location, and employer.

What is a CIW Web Security Specialist?

A CIW Web Security Specialist is an IT professional certified by the Certified Internet Web Professional (CIW) program, specializing in securing web applications and websites. Their role includes implementing security measures, conducting risk assessments, and defending against threats such as hacking, malware, and data breaches. They are knowledgeable in areas like network security, encryption, authentication, and security policies. This certification demonstrates expertise in protecting web-based assets and ensuring safe online environments.

What are the key skills and qualifications needed to thrive as a CIW Web Security Specialist?

To thrive as a CIW Web Security Specialist, you need a solid understanding of web security principles, networking, and risk management, typically supported by a CIW Web Security Specialist certification or similar credentials. Familiarity with security tools such as firewalls, intrusion detection systems, and vulnerability scanners, as well as knowledge of web protocols and cryptography, is essential. Strong analytical thinking, attention to detail, and the ability to communicate complex security issues clearly are valuable soft skills in this role. These skills are crucial for effectively identifying, mitigating, and communicating web security threats to protect organizational assets.

What are some common challenges faced by CIW Web Security Specialists when implementing security protocols across different platforms?

CIW Web Security Specialists often encounter challenges in ensuring consistent security protocols across diverse platforms, such as legacy systems, cloud environments, and mobile interfaces. Adapting security measures to meet varying technical requirements and compliance standards can be complex, particularly when integrating with third-party applications or older infrastructure. Additionally, staying ahead of rapidly evolving cyber threats requires ongoing learning and quick adaptation. Effective collaboration with developers, IT personnel, and management is essential for identifying vulnerabilities and deploying comprehensive solutions.

What is the difference between Ciw Web Security Specialist vs Cybersecurity Analyst?

AspectCiw Web Security SpecialistCybersecurity Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, CEH (common)
Work EnvironmentFocus on web applications, security testing, and vulnerability assessmentsBroader security monitoring, incident response, and threat analysis
Industry UsagePrimarily in IT, cybersecurity firms, and organizations with web assetsAcross various industries including finance, healthcare, and government

The Ciw Web Security Specialist primarily concentrates on securing web applications and testing for vulnerabilities, while the Cybersecurity Analyst has a broader role in monitoring overall security threats and incident response. Both roles require similar certifications and often work within the same industry sectors, but their focus areas differ significantly.

More about Ciw Web Security Specialist jobs

What states have the most Ciw Web Security Specialist jobs?

States with the most job openings for Ciw Web Security Specialist jobs include:

Infographic showing various Ciw Web Security Specialist job openings in the United States as of August 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 91% Physical, 2% Hybrid, and 7% Remote job distribution, with an average salary of $91,584 per year, or $44 per hour.

Application & Web Security Specialist

Dillards

Little Rock, AR • On-site

Full-time

Re-posted yesterday


Dillard's rating

5.9

Company rating: 5.9 out of 10

Based on 288 frontline employees who took The Breakroom Quiz

11th of 21 rated department stores


Job description

APPLICATION AND WEB SECURITY SPECIALIST
THE OPPORTUNITY
The Application and Web Security Specialist will serve as a security consultant to Web and Application Developers. You will work with developers on identifying security risks within their applications and validating remediation. This role offers the opportunity to build solid relationships throughout the enterprise, with developers and vendors, while learning about the various technologies employed within our organization. There are other opportunities to serve included with this role that relate to other Security disciplines such as Threat Security, Vulnerability Management, and Event Correlation.
THE TEAM
The Information Security Team is responsible for the confidentiality of customer and employee information, ensuring the data stored and shared maintains integrity, all while making sure that all of this does not impact the availability of the entire Dillard's enterprise.
This team is expected to be high-performing. To meet this expectation, the team members are communicative and collaborative, always sharing knowledge and research. Members of this team should be able to understand what is expected of them and adjust on the fly, as priorities may change depending on the company's needs. If you are someone who sets a standard of excellence for yourself and you enjoy working alongside others who set the same standard and who genuinely want each of their peers to succeed, you may be the perfect addition to this team.
WHAT YOU WILL DO
  • Inspect and assess current solutions for Web and Application Security risks
  • Architect and implement security controls within the Software Development Lifecycle (SDLC)
  • Hold recurring cadences with development and security leadership to discuss findings and future paths for the company regarding application security posture
  • Participate in vulnerability verification and assist development teams in remediation based on reports from scanners, along with manual application security testing
  • Conduct application security testing on code and web environments after every significant modification
  • Ensure security controls comply with applicable laws, regulations, and policies to minimize risk and audit findings
  • Train others in IT on application security concepts and educate developers on risk-based coding, including the OWASP best practices
  • Participate in on-call rotation across the Information Security Team
  • Ensure applications maintain a Software Bill of Materials (SBOM) for each application
  • Secure and monitor web applications using the web application firewall
  • Secure and monitor all in-house APIs for exploitation
  • Implement security solution(s) for securing AI systems across the environment
  • Collaborate with AI/ML teams to ensure AI security
  • Secure and monitor all in-house AI applications for risk and exploitation

THE SKILLSET
  • Knowledge of web architectures (Apache, WebSphere, CDN, OCP/Docker, Next.JS, React) and ability to read, review, and analyze OOP languages when used in production-ready web applications
  • Understanding of security threats and solutions for applications
  • Experience analyzing risk following regulations, including PCI, HIPAA, Sarbanes-Oxley, and state privacy laws
  • Experience creating processes, procedures, and solutions that reduce technical risk and increase operational efficiency
  • Experience using DAST and SAST tools
  • Experience navigating and monitoring web application traffic through the web application firewall
  • Experience using AI tools for creating and implementing agentic solutions
  • Experience with LLMs, generative AI systems, or LLM-based applications
  • Experience implementing guardrail solutions
  • Hands-on experience with assessing risk and security testing AI systems for OWASP Top 10 for LLMs
  • Ability to work independently and with teams while meeting multiple deadlines
  • Strong interpersonal and communication skills with proven decision-making skills
  • Desire to troubleshoot and lead investigations
  • History of and commitment to ethical behavior and full ethical disclosure

Location & Hours: This is a full-time, on-site position located at our Little Rock, Arkansas headquarters. A high level of attendance is required as an essential function of this position.
No immigration sponsorship (ex. H-1B, TN, STEM OPT) is available for this position

What Dillard's employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom