Software Security Engineer- Cloud/GovCloud (Top Secret cleared)
Job Description
ICF seeks a Software Security Engineer to secure mission-critical applications and cloud systems for a government customer on a remote basis, contingent upon a contract award and an active Top Secret clearance.
Responsibilities
- Monitor and assess application and system security to identify vulnerabilities and potential threats.
- Conduct secure code reviews and perform static/dynamic analysis to improve application security and confirm alignment with secure coding standards.
- Test and evaluate security tools, applications, and system configurations to validate compliance with federal and DoD security requirements.
- Investigate and remediate security vulnerabilities, recommending and implementing corrective actions to reduce risk.
- Design and implement security controls, tools, and automation across cloud and on-premise environments.
- Provide guidance and training to development teams on secure coding practices and DevSecOps principles.
- Develop and maintain technical documentation covering security architecture, risk findings, and mitigation strategies.
- Prepare and deliver executive-level briefings, status reports, and performance updates to government stakeholders and corporate leadership.
- Maintain a positive, results-oriented work environment by building partnerships with internal and external partners.
Requirements
- Active Top Secret clearance.
- 2+ years experience in application security, secure software development, or cybersecurity engineering.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related technical field.
- 2 years experience working on or around AWS cloud platforms.
- Hands-on experience performing secure code reviews and vulnerability assessments using industry-standard tools such as SAST, DAST, and SCA.
- Experience implementing security controls in cloud environments (including AWS GovCloud or comparable secure federal cloud environments).
- Strong understanding of secure coding standards including OWASP, NIST, and DoD STIGs.
- Experience supporting systems in regulated or high-security environments.
- Ability to self-organize, prioritize, and conduct research on multiple projects under tight deadlines in a fast-paced environment.
- Ability to communicate and write clearly in English.
- Highly effective analytical, problem-solving, and decision-making capabilities.
- Excellent communication and interpersonal skills to interface at all business levels.
Technologies
- AWS
- AWS GovCloud
- SAST
- DAST
- SCA
- OWASP
- NIST
- DoD STIGs
Location and Work Details
- Remote (Reston, VA).
- ICF monitors employee work locations and blocks access from foreign locations/foreign IP addresses and prohibits personal VPN connections.
- Travel may be required once per quarter to an office or client site.
- Core work hours are 8am - 5pm Eastern Time, with flexibility to start earlier or work later based on time zone.
Additional Information
- This role is contingent upon a contract award.
- Interviews and offers may be extended in anticipation of the award (not an immediate opening).
- Application must be submitted directly by the applicant for consideration; failure to do so may result in exclusion.
- For disability or religious accommodations related to the application process, contact [email protected].
Candidate AI Usage Policy
- Use of AI tools to generate or assist with responses during interviews (in-person or virtual) is not permitted.
- Candidates may contact [email protected] in advance if an accommodation is needed involving AI.
Pay Range
- $81,499.00 - $138,549.00 per year (full-time employment).
- Nationwide Remote Office: US99.