Senior Software Security Engineer
Location
Virginia
Posted
84 days ago
Salary
0
Seniority
Senior
No structured requirement data.
Job Description
Senior Software Security Engineer
ICF
Open this listing to view full details.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Lead OT risk assessments and develop a multi-year OT security roadmap • Architect and implement security controls for various environments • Support deployment and maintenance of security tools • Build systems for automation and threat detection • Drive security initiatives and foster a security-first mindset • Collaborate with production teams to ensure secure designs
• Serve, prospect for, solicit, and develop business relationships with members and clients • Sell life and health insurance products and services through multiple distribution channels • Analyze member/client needs and recommend personalized solutions • Balance sales objectives, risk management, profitability, and member/client satisfaction • Advise and assist current and potential members and clients
• Conduct scans (agent/network), analyze results (CVEs, CVSS), identify systemic issues, and perform risk assessments for complex environments (cloud, mobile, DB, OS) • Define VM policies, improve posture, guide remediation, lead risk reduction initiatives, and serve as the subject matter expert for complex security vulnerability challenges • Develops reports, dashboards, and alerts to automate tasks (Python, PowerShell), and track metrics. • Monitor threat landscape, analyze new vulnerabilities (NVD, MITRE), and provide proactive guidance. • Develops, tests and operates firewalls, intrusion detection systems, enterprise anti-virus systems and software deployment tools. • Provides complex engineering analysis and support for firewalls, routers, networks and operating systems. • Performs and evaluates vulnerability scans within a multi-platform, large enterprise environment. • Reacts to and initiates corrective action regarding security violations, attempts to gain unauthorized access, virus infections that may affect the network or other event affecting security. • Oversees user access process to ensure operational integrity of the system.
• You'll be the technical voice of product security across Aalyria, reporting to the Director of Security & IT. • You'll own application security, CI/CD and supply-chain security, our Kubernetes-based product infrastructure, product-side authentication and PKI. • You'll partner closely with hardware engineering on Tightbeam. • Application & software security. SAST/DAST/SCA, secure SDLC, threat modeling, and software vulnerability management across our codebase. • CI/CD and supply-chain security. Hardening our GitLab pipelines, build provenance, dependency integrity, signing, and SLSA-aligned controls. • Product infrastructure security. GKE and Kubernetes hardening, container security, workload identity, network policy, and runtime protection. • Product PKI. Certificate lifecycle, issuance, rotation, and mTLS architecture across distributed services and remote assets. • Vulnerability management. Triage, prioritization, remediation tracking, and exception handling, for both disclosed upstream issues and internal findings. • Product incident response. Leading triage and response for product-side security incidents, coordinating with corporate IR, and driving post-mortems to action. • Product infra hardening. Baseline configurations, secure defaults, and compensating controls across product environments. • Hardware security partnership. Working with the Tightbeam team on firmware security, secure boot, key storage, and hardware supply-chain integrity.




