Web Application Security Testing Team Lead Job at gTANGIBLE Corporation, Arlington, VA

UG9jSHpSVkVXTjk3RHQ5LzkrWGp3dXAx
  • gTANGIBLE Corporation
  • Arlington, VA

Job Description

Description

gTANGIBLE Corporation (gTC), www.gtangible.com, is a C corporation and a registered Government contractor that provides services and solutions in:

  • National Security Programs
  • Professional, Administrative, and Management Support
  • Mission and Warfighter Support

 

We are a Service Disabled Veteran Owned Small Business (SDVOSB) and the founder has years of successful experience in the Government contracting arena. Our leadership team is an exceptional group of Government contracting professionals. gTANGIBLE is in the processof identifying candidates for the following position.

Requisition Type:Full Time

Position Status:  Contingent

Position Title: Web Application Security Testing Team Lead

Location:National Capital Region

Security Clearance: Secret

 

Duties and Responsibilities

The Web Application Security Testing Team Leadsupports thisTransportation Security Administration Information Technology (TSA IT) Task Order (TO) by web application testing that require testing both via automated tools and with manual testing techniques.  Application testing will require authenticated and non-authenticated testing to ensure full evaluation of the cybersecurity controls for the applications.Off hours testing conducted on a as needed basis. Periodic travel required.

 

Team duties include the following:

  • Become, and remain, familiar with TSA and DHS security policies and Technical Standards relating to web applications and web application development to facilitate effective security assessments. Make recommendations for updates, additions, and modifications to TSA security policy as gaps or deficiencies in security policy are identified.
  • Engage with testing engagement stakeholders to gather all required information needed to create detailed test plans.
  • Conduct security testing of web applications and services (and other web-related assets) using both Information Assurance and Cybersecurity Division(IAD)-provided automated testing tools and manual testing techniques.
  • Troubleshoot any technical issues preventing successful completion of testing engagements within the scheduled time allotted for the engagement (i.e. insufficient credentials, proxy blocking, accounts blocked/expired, etc.).
  • Participate in findings meetings to review and provide input on the validity of application stakeholder responses to IAD findings.
  • Recommend adjustments of finding validity (valid or false positive) and severity (high, medium, low) to Governance, Risk, and Compliance(GRC) Portfolio Managers and Primary Assessors based on stakeholder responses.
  • Review application stakeholder mitigation or remediation actions to address valid findings to assist IAD with determining the applicability and effectiveness of those actions.
  • Provide Subject Matter Expertise for a variety of topics concerning web applications in a variety of formats (verbal or written). Includes common and emerging web and mobile technologies, languages, and frameworks to discuss the benefits and security detriments of those technologies.
  • Provide support for external security audits conducted of the TSA.  Such support would include items such as: providing technical insight into datacalls required by external Federal entities, offering technical information to facilitate external auditors work, or validating findings identified in external audit reports.

Knowledge and Qualifications

  • At least eight (8) years of technical IT security experience.  Such experience can come from system or network administration, security analysis, security testing and evaluation, security incident response, security monitoring, IT project implementation, or other similar technical activities.
  • At least five (5) years of experience performing security control assessments (i.e. security testing such as security auditing, primary assessor for Security Control Assessments, etc.).
  • At least three (3) years of experience performing web application security testing.
  • At least one (1) year of experience performing security testing of Federal IT systems.
  • Experience with NIST and FIPS security controls, DISA STIGs, and CIS standards.
  • Experience working in groups acting as the sole security practitioner, as well as experience working in team(s) of various sizes of security personnel reviewing the same system.
  • Experience with HP WebInspect, IBM/HCL AppScan, PortswiggerBurpSuite, SmartBear SoapUI, Nessus Professional, HP Fortify, Apple Developers Toolkit, Eclipse, and Wireshark. 
  • Excellent communication skills to be able to understand concepts being verbally presented, participate in group discussions, and to present recommendations.
  • Strong organizational, analytical, and technical writing skills to be able to document findings in reports.

gTANGIBLE Corporation is an equal opportunity employer and does not discriminate against any employee or applicant because of race, age, sex, color, physical or mental disability, religion, sexual orientation, marital status, national origin, or political affiliation.

Job Tags

Full time, For contractors

Similar Jobs

Connvertex Technologies Inc.

MDM Developer Job at Connvertex Technologies Inc.

 ...Job Title: MDM Developer Location: Quincy, MA Work Type: Hybrid Job Type: Contract (6+ Months) Rate: $55/hr on W2 Notes...  ...cloud-based analytics or reporting ecosystems (AWS, Snowflake, Tableau, or similar) Comfortable using approved AI-assisted development... 

Disney

Power Distribution Technician, Walt Disney World Job at Disney

 ...Job ID 1344777BR Location Orlando, Florida, United States / Lake Buena Vista, Florida, United States Business Walt Disney World Resort Date posted Apr. 12, 2026 Job Summary: At Disney, were storytellers. We make the impossible, possible. We do this through... 

BJC Healthcare

Intermediate Care Unit Registered Nurse (RN) - Night Shift Job at BJC Healthcare

 ...weekends, and holidays BSN differential Comprehensive benefits , including PTO accrual starting Day 1 and parental leave BJC RN Career Ladder supporting competencybased advancement and professional growth while remaining at the bedside A culture of... 

Confidential

High School Chemistry Teacher-NoOfficeHr Job at Confidential

 ...Class size:25-30 students/class -Type of school: international high school -Teaching...  ...-Vacancy:1 High School A Level Chemistry Teacher -Start date: August 2026Requirements:...  ...Allowance: Provided.Need to provide invoices. -Summer/winter holiday: provided.Fully Paid... 

Conch Technologies Inc

BI Developer III - Data / Business Intelligence Job at Conch Technologies Inc

 ...Job Title: BI Developer III Data / Business Intelligence Location: Remote (PST Hours Must be located in CA) Duration: 4 Months...  ...Power BI (Dashboards, Paginated Reports, Power Automate) Tableau Tabular Modeling (SSAS) Snowflake / Data Warehousing...