ICF logo
ICF

Founded in 1969, ICF is a global advisory and technology services company headquartered in Reston, Virginia. It delivers data-driven solutions across energy, en

Senior Software Security Engineer

Location

United States

Posted

25 days ago

Salary

$119.3K - $202.9K / year

Seniority

Senior

Job Description

Senior Software Security Engineer

ICF

Role Description Please note: This role is contingent upon a contract award. While it is not an immediate opening, we are actively conducting interviews and extending offers in anticipation of the award. ICF is seeking an experienced and driven Software Security Engineer to lead and oversee mission-critical initiatives in support of the Defense Counterintelligence and Security Agency (DCSA). In this role, you will help safeguard applications and cloud-based systems by integrating security best practices throughout the software development lifecycle. Job Location: This position is remote. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses and also prohibits personal VPN connections. You may be asked to travel once a quarter to an office or client site. Our core work hours are 8am - 5pm Eastern Time with the option to start earlier or work later depending on your time zone. What You Will Do: - Proactively monitor and assess application and system security to identify vulnerabilities and potential threats. - Perform secure code reviews and static/dynamic analysis to strengthen application security and ensure adherence to secure coding standards. - Test and evaluate security tools, applications, and system configurations to validate compliance with federal and DoD security requirements. - Investigate and remediate potential security vulnerabilities, recommending and implementing corrective actions to reduce risk. - Design and implement security controls, tools, and automation to enhance protection across cloud and on-premise environments. - Provide guidance and training to development teams on secure coding practices and DevSecOps principles. - Develop and maintain technical documentation related to security architecture, risk findings, and mitigation strategies. - Prepare and deliver executive-level briefings, status reports, and performance updates to government stakeholders and corporate leadership. - Maintain a positive, results-oriented work environment by building partnerships with internal and external partners. Qualifications - Active Top Secret clearance. - Proven experience (8+ years) in application security, secure software development, or cybersecurity engineering. Requirements - Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related technical field. - 2 years’ experience working with DCSA. - 5 years’ experience with working on/around cloud platforms in AWS. - Hands-on experience performing secure code reviews and vulnerability assessments using industry-standard tools (e.g., SAST, DAST, SCA). - Experience implementing security controls in cloud environments (e.g., AWS GovCloud or similar secure federal cloud environments). - Strong understanding of secure coding standards (e.g., OWASP, NIST, DoD STIGs). - Experience supporting systems within regulated or high-security environments. - Ability to self-organize, prioritize and conduct research on multiple projects under tight deadlines in a fast-paced environment. - An ability to communicate and write clearly in English. Professional Skills - Highly effective analytical, problem-solving, and decision-making capabilities. - Excellent communication and interpersonal skills to interface effectively at all levels of the business. Benefits - We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. - We are an equal opportunity employer. - Reasonable Accommodations are available for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs. Pay Range The pay range for this position based on full-time employment is: $119,323.00 - $202,850.00.

Related Categories

Related Job Pages

More Security Engineer Jobs

Accenture Federal Services logo

Cybersecurity Tools Administrator

Accenture Federal Services

We believe in the power of change, harnessed in ways that matter for our country and communities.

Full TimeRemoteTeam 10,001+Since 2017H1B No Sponsor

• Proposing, developing, installing, managing, operating, maintaining, integrating, and configuring a suite of cybersecurity tools to support project network cybersecurity operations • Ensuring proper configuration and operation of tools • Monitoring resource utilization • Contributing to the deployment of new tools • Developing security plans and maintaining network architecture diagrams

Virginia
$78.6K - $160.2K / year
Job Closed
Part TimeRemoteTeam 51-200Since 2003H1B Sponsor

• Review cloud and infrastructure security architectures • Assess AWS, firewall, virtualization, and endpoint security controls • Support vulnerability analysis and remediation recommendations • Validate security configurations and technical evidence • Provide guidance on network, server, and SaaS security best practices • Support security assessment and testing activities

United States
Job Closed
Full TimeRemoteTeam 51-200Since 2003H1B Sponsor

• Provide technical leadership for Certification & Accreditation (C&A) and Risk Management Framework (RMF) activities supporting system authorization decisions. • Lead RMF strategy and authorization roadmap. • Guide NIST SP 800-37 lifecycle activities. • Identify NIST SP 800-53 security controls. • Validate FIPS 199 and FIPS 200 categorization. • Oversee SSP, Risk Assessment, ST&E, and authorization package development. • Provide interpretation of NIST, FIPS, and federal requirements.

United States
Job Closed
SpyCloud logo

Security Researcher III – Phishing

SpyCloud

The leader in operationalizing Cybercrime Analytics to prevent ATO, ransomware, and online fraud.

Full TimeRemoteTeam 51-200H1B Sponsor

• Data Collection: Locate, target and recapture data from Phishing-as-a-Service (PhaaS) kits using a combination of human intelligence and platform sourcing. • Data Analysis: Apply data science techniques to understand the quality of sourced data, in order to refine and improve the PhaaS data sourcing pipeline. • Human Intelligence: Perform human intelligence techniques such as managing multiple alternate personas, actor engagements, and social engineering in support of data recapture efforts. • Security Analysis: Participate in the drafting of research blogs and analytical products to support customers and business objectives. • Security Research: Participate in security research including investigation of threat actors, PhaaS, and other critical research in support of SpyCloud’s priorities.

United Kingdom