2

Remote Web App Penetration Testing Jobs in Springfield, VA

Application Security Engineer

Washington, DC · On-site +1

$180K - $200K/yr

Experience with Nodejs, Go, etc. * Experience running bug-bounty, penetration testing ... Access to Headspace , a mental health app tailored to your specific needs. * A flat 3% contribution ...

Sr Cyber Security Engineer

Reston, VA · Remote

$83.33 - $87/hr

Remote (Needs to be in office 1 time/month) Hours: 40.0 Responsibilities * Develops and implements ... and manual penetration testing. * Experience with cloud native security platforms like Wiz ...

Sr Cyber Security Engineer

Reston, VA · Remote

$83.33 - $87/hr

Remote (Needs to be in office 1 time/month) Hours: 40.0 Responsibilities * Develops and implements ... and manual penetration testing. * Experience with cloud native security platforms like Wiz ...

Sr Cyber Security Engineer

Reston, VA · Remote

$83.33 - $87/hr

Remote (Needs to be in office 1 time/month) Hours: 40.0 Responsibilities * Develops and implements ... and manual penetration testing. * Experience with cloud native security platforms like Wiz ...

Remediate security vulnerabilities identified through automated scanning or penetration testing ... Responsive web design Backend Technologies * Python frameworks (FastAPI, Flask, or Django) * ...

Showing results 41-60

Remote Web App Penetration Testing information

See Springfield, VA salary details

$12

$61

$90

How much do remote web app penetration testing jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for remote web app penetration testing in Springfield, VA is $61.64, according to ZipRecruiter salary data. Most workers in this role earn between $53.46 and $69.81 per hour, depending on experience, location, and employer.

What is the difference between Remote Web App Penetration Testing vs Remote Network Security Analyst?

AspectRemote Web App Penetration TestingRemote Network Security Analyst
CertificationsOSCP, CEH, GPENCompTIA Security+, CISSP, GIAC
Work EnvironmentSecurity consulting firms, tech companies, freelanceCorporate IT teams, government agencies
Primary FocusIdentifying vulnerabilities in web applicationsMonitoring and securing network infrastructure
Tools & TechniquesBurp Suite, OWASP ZAP, SQLmapSIEM, IDS/IPS, network scanners

Remote Web App Penetration Testing focuses on assessing web application security by identifying vulnerabilities, while Remote Network Security Analysts monitor and protect entire network infrastructures. Both roles require cybersecurity certifications and involve security tools, but they target different aspects of an organization's security landscape.

What are the most commonly searched types of Web App Penetration Testing jobs in Springfield, VA?

The most popular types of Web App Penetration Testing jobs in Springfield, VA are:

What cities near Springfield, VA are hiring for Remote Web App Penetration Testing jobs?

Cities near Springfield, VA with the most Remote Web App Penetration Testing job openings:

Infographic showing various Remote Web App Penetration Testing job openings in Springfield, VA as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 11% Part Time, 1% Temporary, 5% Contract, and 1% Nights. Highlights an 86% Physical, 2% Hybrid, and 12% Remote job distribution, with an average salary of $128,201 per year, or $61.6 per hour.

Security Oversight Product Owner

ResolveSoft Inc

Washington, DC • Remote

$120K - $130K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 27 days ago


Job description

Security Oversight Product Owner

 

Position Overview

The Security Oversight Product Owner serves as a Key Personnel leader responsible for coordinating and executing the Security Oversight management program operations, maintenance, and continuous improvements for the Client’s Web and Emerging Technologies Group (WETG) digital ecosystem. This role ensures comprehensive security operations, continuous compliance management, proactive risk assessment, incident response, and security documentation support across high-profile, public-facing federal web assets.

The ideal candidate possesses deep expertise in Federal system security policies, NIST SP 800-series frameworks, and DevSecOps environments, serving as a trusted quality partner to protect beneficiary data and ensure continuous system authorization (ATO).


Core Responsibilities:

1. Program Coordination & Leadership

  • Coordinate the execution of the Security Oversight management program, managing operations, maintenance, and continuous engineering improvements.
  • Foster a collaborative, "badge-less" environment using Client-approved communication tools (e.g., Slack, Confluence) to align activities with federal Product Managers, ISSOs, the eCloud Service Provider (AWS), and third-party Application Development and Operations (ADO) contractors.
  • Manage a customized security service from an accredited FISMA-Moderate facility, ensuring all contractor workstations adhere to strict security configurations.

2. Vulnerability Management & Testing Coordination

  • Coordinate and support regular system security scanning activities, including Static/Dynamic Application Security Testing (SAST/DAST), penetration testing, and database vulnerability scans.
  • Collaborate closely with the Task 2 Independent Testing teams to align security testing with overall quality assurance workflows, ensuring non-duplicative effort and consistent prioritization of security fixes.
  • Analyze scan findings to generate actionable Vulnerability Result Reports with definitive remediation timelines matching Client’s metrics (Critical: 15 days; High: 30 days).

3. Risk Assessment & Requirements Analysis

  • Establish, maintain, and continuously update a comprehensive Security Risk Register mapping system vulnerability to formal Plans of Action and Milestones (POA&Ms).
  • Synthesize technical risk telemetry into a high-level monthly Security Risk Report tailored for executive decision-making.
  • Identify, track, and maintain security requirements baseline for all in-scope applications using global and local threat intelligence.

4. Compliance & Security Documentation (A&A / ATO)

  • Lead the preparation, quarterly review, and annual updates of a wide variety of NIST SP 800-Series security artifacts within the Client’s security documentation repository.
  • Develop and maintain critical authorization packages, including System Security and Privacy Plans (SSPPs), Information System Risk Assessments (ISRA), Security Impact Analyses (SIAs), Privacy Impact Assessments (PIAs), and Information System Contingency Plans (ISCP).
  • Proactively prepare for and actively support the auditing community during Inspector General (IG), FISMA, third-party, and internal agency audits.

5. Incident Handling Oversight

  • Manage 24x7x365 on-call staffing to respond to security alerts and Indicators of Compromise (IOCs) from the Client’s Virtual Data Center NOC and SOC within 24 hours.
  • Facilitate and triage responses to suspected or confirmed privacy breaches/incidents in accordance with Client Incident Handling Guidelines, reporting critical issues within the mandatory 1-hour window.
  • Coordinate reverse malware engineering to support forensic analysis and incident response workflows when required.

Key Deliverables Managed

  • Vulnerability Result Reports (As required)
  • Security Risk Register (Updated within 4 days of risk identification)
  • Monthly Security Risk Reports (Sourced from live data dashboards)
  • A&A Package Updates (SSP, SAR, POA&Ms, ISCP)
  • Security Impact Analyses (SIAs) (Aligned to product release cycles)


Qualifications & Experience Requirements

Minimum Technical Qualifications

  • Experience: Demonstrated expertise in cybersecurity oversight, risk management frameworks, and security auditing within a large-scale, multi-team Agile/DevSecOps digital environment.
  • Framework Mastery: Deep, demonstrable familiarity with the CMS Risk Management Framework, Cybersecurity and Risk Assessment Program (CSRAP), FIPS 199/200, FedRAMP guidelines, and NIST SP 800-53 security controls.
  • Tooling Familiarity: Experience working with automated configuration/vulnerability tools, (or similar Trusted Agent FISMA applications), and common Agile toolchains (Jira, Confluence, GitHub).

Certifications (Highly Preferred / Contract Required)

  • Certified Information Systems Security Professional (CISSP), CISM, or equivalent federal security governance certification.
  • Demonstrated experience maintaining organization-level ISO 20000 (IT Management) and ISO 2700X (Security) certifications.

Core Competencies

  • Ability to interpret complex cryptographic validation standards (FIPS 140) and supply chain risk requirements (C-SCRM).
  • Strong communication skills to present highly technical security concepts into non-technical, consumable formats for senior stakeholders.
  • Suitability: Must be able to obtain a federal background investigation clearance commensurate with a high-level Position Sensitivity Designation.

Company Description

Our mission is to empower our clients to achieve sustainable success through efficient, cost-effective, and scalable solutions that drive significant performance improvements. We believe in delivering value-driven results and fostering a culture that attracts and retains top talent to provide scalable, adaptable services.