ICF logo
ICF

Founded in 1969, ICF is a global advisory and technology services company headquartered in Reston, Virginia. It delivers data-driven solutions across energy, environment, infrastru

Senior Security Engineer - Remote

Location

United States

Posted

38 days ago

Salary

$98.6K - $167K / year

Seniority

Senior

Job Description

Senior Security Engineer - Remote

ICF

Description The Work: ICF is looking for an enthusiastic Senior Security Engineer to join our team and help with ensuring our environments and applications meet Federal Security Standards. If you are Security Engineer interested in applying your expertise in Security Engineering in a consulting environment, then this may be the role for you. Job Location: This position requires that the job be performed in the United States.  If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses, and also prohibits personal VPN connections. - Our core work hours are 10am - 4pm Eastern Time with the option to start earlier or work later depending on your time zone. However, please note our client is on the east coast and may sometimes start a meeting earlier than 10:00 which may require your participation. - Travel for a conference or to another ICF location for collaboration may be required once a year. What You Will Do: The selected candidate will be required to work on multiple products and must be able to develop and present secure solutions and advice to technical teams as well as leadership. The candidate will further be required to assess risks and advise on security standards, best practices, and solutions. All this must be done by maintaining security quality and customer satisfaction. Various tools are used to detect vulnerabilities and the security engineer documents these vulnerabilities and works with developers to get them corrected. The security engineer will need to work on a path to production for new applications ensuring all the documentation and appropriate steps are taken and approved to have a highly secure production application and environment. Responsibilities: - Perform Static Application Security Testing (SAST) to identify potential vulnerabilities in the application code and infrastructure  - Perform Dynamic Application Security Testing (DAST)  - Create and update threat models for FISMA systems  - Assist and lead security incident response  - Assist with documentation of System Security plan and Contingency Plans for related projects  - Ensure security systems are up to date and create documentation and planning for all security-related information, including incident response and disaster recovery plans  - Review policies and procedures for compliance with applicable standards; and to identify areas of improvement for finding remediation  - Interact with senior level management, including the ISSO  - Use security assessment tools such as Nessus, Snyk, AWS GuardDuty and AWS Inspector  - Apply a demonstrated understanding of cryptography to secure web applications and data at rest  - Work with development teams to review and correct code written in higher level programming languages and scripts   - Work with DevOps teams to securely harden Linux based machines and cloud infrastructure   Basic Qualifications: - Bachelor’s Degree - 5+ years of professional security engineering experience - Candidate must be able to obtain and maintain a Public Trust - Candidate must reside in the U.S., be authorized to work in the U.S., and all work must be performed in the U.S. - Candidate must have lived in the U.S. for three (3) full years out of the last five (5) years What We Would Like You To Bring With You: . - Hands on experience that includes: - NIST 800‑53 security controls - System hardening and implementation of DoD STIGs - Leading incident response activities - Data management and applied cryptography - Cloud security and infrastructure (AWS, Azure, and/or GCP) - Awareness of OWASP Top Ten and CWE Top 25 - Linux command line usage (e.g., bash, sh, zsh) - Scripting in Python, Perl, or similar languages - Prior experience in consulting or healthcare is an advantage but not essential. - Strong engineering background   - Application architecture experience   - Federal Government contracting work experience  - One or more of the following certifications is preferred: - OSCP/OSCE/OWSE - CISSP - GPEN - GXPN  - Security + - CEH Professional Skills: - Good leadership and team-working skills. - Highly effective analytical, problem-solving, and decision-making capabilities. - Excellent communication and interpersonal skills to interface effectively at all levels of the business. - Organized, detailed oriented and able to prioritize and multi-task. - Ability to self-organize, prioritize and conduct work on multiple projects under tight deadlines in a fast-paced environment. - Prior experience working remotely full-time  #DMX-HES Working at ICF ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future. We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy. We will consider for employment qualified applicants with arrest and conviction records. Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email Candidateaccommodation@icf.com and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.  Read more about workplace discrimination rights or our benefit offerings which are included in the Transparency in (Benefits) Coverage Act. Candidate AI Usage Policy At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process.  However, we understand that some candidates may require accommodation that involves the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance at candidateaccommodation@icf.com. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed.   Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position. The pay range for this position based on full-time employment is: $98,614.00 - $167,644.00 Nationwide Remote Office (US99)

Related Categories

Related Job Pages

More Security Engineer Jobs

TalentRemedy logo

Biomedical Cybersecurity Team Engineer

TalentRemedy

TalentRemedy is revolutionizing the way recruiting is being done!

Full TimeRemoteTeam 11-50Since 2012H1B No Sponsor

This is a remote position. About Our Client Known for being a Best Place to Work and a People First company, our client is an award-winning Service-Disabled Veteran-Owned Small Business (SDVOSB) specializing in providing innovative solutions and world-class services to Federal Government clients. Their employees have voted them a 'Best Place to Work' 9 times, and they are an INC 5000 recipient for being one of the fastest growing businesses in the United States. Company Values: Deliver Outcomes with Speed | Own the Work and the Results | Respect People. Speak Directly. | Stay Curious. Enjoy the Journey. What You’ll Do As a Biomedical Cybersecurity Team Engineer, you will support the Client program by contributing to cross-functional coordination, operational readiness, and technical execution. You will collaborate with stakeholders to ensure issues are identified early, risks are mitigated, and project activities remain aligned with program goals. In this role, you will help streamline processes, maintain accurate documentation, and promote consistent communication across teams. Your work will enable reliable, secure, and efficient modernization activities across the enterprise. Key Responsibilities - Develop and maintain a cyber tracker to provide clear communication on system status - Provide leadership with live, automated cyber updates (e.g., JIRA dashboards) for ATCs, CRs, and connectivity timelines - Perform gap analyses for future sites and support mitigation planning (e.g., upgrades, licensing, configuration requirements) - Assist in PPSM development efforts - Support auditing and review of inventories, including creation of POA&M statements as needed - Assist with firewall ruleset development and creation of standardized templates across deployment sites - Provide onsite support for inventory analysis as required - Assist in developing enterprise standard configuration guides aligned with cybersecurity best practices (e.g., Welch Allyn, SkyVue, CCE Admin Tool) - Collaborate with client HTM and biomedical leadership to review and validate documentation for medical system designs, including devices, ensuring alignment with timelines and existing infrastructure - Support the review and validation of system design documentation to facilitate client timelines and integration with existing systems - Provide technical guidance and support for implementation of the Risk Management Framework (RMF), including activities related to Authority to Operate (ATO) and Authority to Connect (ATC) Requirements - Bachelor’s degree or equivalent experience - Understanding of federal cybersecurity guidance, particularly as it relates to healthcare technology - Knowledge of VLANs and logical network segmentation based on risk characterization - Familiarity with healthcare data standards (e.g., HL7 FHIR, CCDA) and interoperability concepts, including Health Information Exchange (HIE) - Strong problem-solving and communication skills - Ability to collaborate across diverse technical and functional teams - Familiarity with enterprise IT environments or system modernization initiatives - Experience with documentation, tracking, or reporting tools (e.g., JIRA) - Ability to manage multiple priorities in a fast-paced, dynamic environment Preferred Experience - Experience supporting Client, federal, or healthcare IT programs - Exposure to cybersecurity, testing, data, or operations domains - Knowledge of Electronic Health Record (EHR) systems or large-scale system integrations Benefits - Awarded Best Place to Work 9 times! - Competitive compensation and market-leading bonus opportunities - Medical, dental, and vision benefits where a significant portion of the premium is subsidized by our client. For qualifying high deductible health plans, our client also contributes towards a Health Reimbursement Account to cover eligible medical expenses - Company-provided healthcare concierge assistance to help explain your coverage in plain language; help you find, choose, and schedule quality care; and address billing, benefit, or claims concerns, potentially saving hours of your time - 401(k) retirement plan where the company contributes dollar for dollar up to 3 percent, and 50 cents on the dollar for the 4th and 5th percent, with immediate entry and immediate vesting - 20 days of PTO accumulated per calendar year - 11paid holidays - Bereavement, jury duty, parental (maternity/paternity/adoption), and military leaves - Sabbatical programs - Company-paid short- and long-term disability - Company-paid life insurance - Voluntary life, accidental, and indemnity income replacement benefits - Professional development reimbursement - Health club reimbursement - Matching donation program and annual philanthropic activities - Pet insurance - And more!

United States
Capco logo

Data Privacy & Security

Capco

Capco, a Wipro company, is a management & technology consultancy dedicated to the financial services & energy industries

Full TimeRemoteTeam 1,001-5,000Since 1998H1B Sponsor

Job Title: Sr. BA Data Governance About Us “Capco, a Wipro company, is a global technology and management consulting firm. Awarded with Consultancy of the year in the British Bank Award and has been ranked Top 100 Best Companies for Women in India 2022 by Avtar & Seramount. With our presence across 32 cities across globe, we support 100+ clients across banking, financial and Energy sectors. We are recognized for our deep transformation execution and delivery. WHY JOIN CAPCO? You will work on engaging projects with the largest international and local banks, insurance companies, payment service providers and other key players in the industry. The projects that will transform the financial services industry. MAKE AN IMPACT Innovative thinking, delivery excellence and thought leadership to help our clients transform their business. Together with our clients and industry partners, we deliver disruptive work that is changing energy and financial services. #BE YOURSELF AT WORK Capco has a tolerant, open culture that values diversity, inclusivity, and creativity. CAREER ADVANCEMENT With no forced hierarchy at Capco, everyone has the opportunity to grow as we grow, taking their career into their own hands. DIVERSITY & INCLUSION We believe that diversity of people and perspective gives us a competitive advantage. Role Description Location - Bangalore Experience – 7+ years We are seeking an experienced Senior Consultant with deep expertise in Data Governance and Data Management to support enterprise-wide data initiatives within the banking sector. The ideal candidate will help strengthen data quality, ensure regulatory compliance, and drive governance practices that align with banking industry standards. Key Responsibilities - Data Governance & Regulatory Alignment • Interpret and apply data governance policies, frameworks, and regulatory requirements (e.g., Basel, BCBS 239) across banking programs. • Review and challenge data element definitions to ensure compliance, accuracy, and consistency with risk and reporting needs. • Serve as a critical voice in governance discussions, ensuring alignment with organizational and regulatory objectives. Cross-functional Collaboration • Partner with risk, compliance, finance, operations, and IT teams to ensure clarity and alignment on data governance expectations. • Act as a liaison between business and technology teams to translate banking data requirements into actionable solutions. • Engage senior domain owners to manage global/regional stakeholder relationships. Documentation & Communication • Document and communicate data governance issues and recommendations clearly for stakeholders at all levels. • Translate complex data governance and regulatory concepts into clear, actionable insights. • Develop materials for senior leader communication, steering committees, and regulatory reviews. Data Cataloging & Data Quality Management • Catalog data elements and lineage using enterprise metadata tools. • Support classification of data aligned with risk and compliance taxonomies. • Manage data quality rules, controls, and remediation initiatives relevant to banking operations. • Monitor data quality issues impacting reporting, regulatory submissions, and customer information. Required Skills & Experience • 7+ years of experience in Data Governance or Data Management, preferably within the banking or financial services industry. • Strong ability to interpret and challenge governance policies and regulatory requirements. • Exceptional verbal and written communication skills with the ability to influence stakeholders. • Analytical thinker able to review and analyze complex data definitions and business rules. • Experience managing stakeholders in matrixed environments. • Proficiency in Microsoft Excel, Project, and PowerPoint. • Experience with Data Governance tools such as Collibra or Informatica is a plus. If you are keen to join us, you will be part of an organization that values your contributions, recognizes your potential, and provides ample opportunities for growth. For more information, visit www.capco.com. Follow us on Twitter, Facebook, LinkedIn, and YouTube.

India
Job Closed
Cardinal Technology Systems, Corp. logo

Cybersecurity SME

Cardinal Technology Systems, Corp.

Cardinal Technology Systems, Corp (“CTech-Sys”) is an SBA Certified 8(a) and HUBZone company located in the National Capital Region (NCR) and serves both government and commercial clients such as US CBP, US CIS, DLA, DFuse Technologies, and American Environmental Engineering Consultants. Cardinal Technology Systems, Corp is an Equal Employment Opportunity employer and it's our policy to consider applicants for employment without regard to sex, race, color, creed, religion, national origin, sexual orientation, marital status, age, disability, veteran status, alienage, ancestry, or any other factors prohibited by law. Employment selections are based on company and client requirements and the qualifications and skills of the candidate. CTech-Sys is committed to actively capitalizing on the diversity of skills, talents and perspectives of our employees.

Responsibilities Cardinal Technology Systems Corp. is a government IT solutions provider servicing commercial and government initiative in various parts of the United States. We are currently seeking a Cybersecurity SME to work for our company. Summary - Must possess IT-II security clearance or have a current National Agency Check with Local Agency Check and Credit Check (NACLC). (Basic Federal Clearance requirements are U.S. Citizenship, clear criminal history check, no recent or pending bankruptcies) - Provides expert support, research and analysis of exceptionally complex problems, and processes relating to them. - Serves as technical expert to the Cybersecurity Assessment Program providing technical direction, interpretation, and alternatives to complex problems. - Thinks independently and demonstrates exceptional written and oral communications skills. - Applies advanced technical principles, theories, and concepts. Contributes to the development of new principles, concepts, and methodologies. - Works on unusually complex technical problems and provides highly innovative and ingenious solutions. - Recommends cybersecurity software tools and assists in the development of software tool requirements and selection criteria to include the development of product specific STIGs from applicable DISA SRGs. - Works under consultative direction toward predetermined long-range goals and objectives. - Assignments are often self-initiated. Determines and pursues courses of action necessary to obtain desired results. - Develops advanced technological ideas and guides their development into a final product. Requirements - Must possess IT-II security clearance or have a current National Agency Check with Local Agency Check and Credit Check (NACLC). (Basic Federal Clearance requirements are U.S. Citizenship, clear criminal history check, no recent or pending bankruptcies) - Required Training /Certifications In: ICS300 or relevant Operational Technology “OT” or Industrial Control System “ICS” Cybersecurity Certifications, ACAS and Tanium Training Module /Course Completion. - Must possess an active DoD 8570 IAT Level III certification (e.g., CISSP, CASP+ CE, CISSP-ISSAP, or CISSP-ISSEP). - 10+ years of IT experience. - 10+ years of DOD Cybersecurity experience. - 10+ years of Risk Management Framework (RMF) and NIST A&A experience. - Demonstrated expertise in leading and mentoring teams, providing clear guidance, quality oversight, and technical direction to ensure all cybersecurity artifacts meet DoD standards, organizational expectations, and inspection-ready quality levels. - Proven real world hands-on experience preparing enterprise environments for DoD cybersecurity inspections (CCRI, CORA, Blue Team assessments). - SME level experience in assessing security controls and conducting authorization reviews for large, complex organizations. - SME level understanding of DoD cybersecurity requirements, including documenting and developing artifacts for STIGs, TCG configuration guides, IAVMs, and Task Orders. - Oversees end to end POA&M lifecycle management, ensuring accurate documentation, status tracking, and closure of all remediation actions. - Exceptional ability to develop, maintain, and validate RMF artifacts and cybersecurity documentation. - Expert ability to interpret new and evolving DoD cybersecurity documentation, templates, and compliance requirements to develop high-quality cyber security artifacts even when guidance is incomplete, ambiguous, or inconsistently applied. - Skilled in analyzing and interpreting cybersecurity guidance from the ISSM/ISSO to produce authoritative system documents such as the SSP, CONOPS, Incident Response Plan, and Contingency. - Plan, Configuration Management Plan, and other required artifacts. - Proven ability to work independently and collaboratively with minimal oversight. - Strong research, analytical, and problem-solving skills. - Proficiency with analytical tools such as Microsoft Excel, Access, Power BI, and Power Platforms. - Ability to generate clear, accurate, and audit-ready cybersecurity reports, including vulnerability summaries, compliance status updates, and risk findings for technical and leadership audiences. - Ability to generate detailed analytics and trend reports using data from vulnerability scanners, configuration tools, and security platforms to support decision-making and inspection readiness. - Excellent written and verbal communication skills, including the ability to brief leadership and produce clear documentation. Benefits • Medical, Dental, Vision Benefits • Paid Life • Paid Vacation, Holidays, Sick Leave, Floating Holidays, Bereavement Leave • Semi-monthly pay cycle Work With Us Cardinal Technology Systems, Corp (“CTech-Sys”), www.ctech-sys.com, is an SBA Certified 8(a) and HUBZone company located in the National Capital Region (NCR) and serves both government and commercial clients such clients as US CBP, US CIS, DLA, DFuse Technologies, and American Environmental Engineering Consultants. Cardinal Technology Systems, Corp is an Equal Employment Opportunity employer and it’s our policy to consider applicants for employment without regard to sex, race, color, creed, religion, national origin, sexual orientation, marital status, age, disability, veteran status, alienage, ancestry, or any other factors prohibited by law. Employment selections are based on company and client requirements and the qualifications and skills of the candidate. CTech-Sys is committed to actively capitalizing on the diversity of skills, talents and perspectives of our employees.

United States
Sentrabyte Digital Solusi logo

Offensive Security Engineer

Sentrabyte Digital Solusi

Join our team at Sentrabyte Digital Solusi and embark on a journey of growth and innovation.

Full TimeRemoteTeam 51-200

Role Description We are actively hiring an Offensive Security Engineer to work on real-world security testing and automation across modern systems. This role is ideal for candidates with a strong foundation in penetration testing who want to expand into automation, tooling, and advanced offensive security practices. You will work on practical security challenges — not just scanning tools — and contribute to improving security at scale. Responsibilities - Perform security testing across web applications, APIs, and infrastructure - Develop scripts and tools (Python, Bash, etc.) to automate testing workflows - Identify, validate, and analyze vulnerabilities - Support internal offensive security initiatives and tooling - Collaborate with engineering teams to improve system security - Contribute to improving detection and response capabilities Qualifications - 2–5 years of experience in penetration testing or security engineering - Basic to intermediate scripting skills (Python, Bash, or similar) - Strong understanding of web security (OWASP Top 10 and beyond) - Familiarity with Linux systems and networking concepts - Strong analytical and problem-solving mindset Requirements - Nice to Have - Experience building security tools or automation - Exposure to cloud security or DevSecOps environments - Experience with real-world testing or bug bounty programs Work Setup - Full-time - Remote (Worldwide) Company Description Join our team at Sentrabyte Digital Solusi and embark on a journey of growth and innovation.

Worldwide
$60K - $120K / year