1 hour ago
Reston, VA, USASenior
Base Salary
$99k - $168k/yr
Responsibilities
- Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify application and infrastructure vulnerabilities.
- Create and update threat models for FISMA systems.
- Assist with and lead security incident response activities.
- Document vulnerabilities and collaborate with developers on remediation.
- Support System Security Plan and Contingency Plan documentation.
- Maintain security systems and prepare security, incident response, and disaster recovery documentation.
- Review policies and procedures for compliance with applicable standards and identify remediation improvements.
- Advise technical teams and leadership on risks, security standards, best practices, and secure solutions.
- Use Nessus, Snyk, AWS GuardDuty, and AWS Inspector for security assessments.
- Apply cryptography to secure web applications and data at rest.
- Review and correct code written in higher-level programming languages and scripts.
- Work with DevOps teams to harden Linux machines and cloud infrastructure.
- Ensure new applications follow required security documentation, approval, and production-readiness steps.
Requirements
- Bachelor’s degree.
- At least 5 years of professional security engineering experience.
- Ability to obtain and maintain a Public Trust.
- Must reside in the United States, be authorized to work in the United States, and perform all work in the United States.
- Must have lived in the United States for 3 full years out of the last 5 years.
- Hands-on experience with NIST 800-53 security controls, system hardening, DoD STIGs, incident response, data management, applied cryptography, cloud security, and infrastructure.
- Knowledge of AWS, Azure, and/or GCP cloud security and infrastructure.
- Awareness of the OWASP Top Ten and CWE Top 25.
- Linux command-line experience, including bash, sh, or zsh.
- Scripting experience in Python, Perl, or similar languages.
- Strong engineering background and application architecture experience.
- Consulting, healthcare, or Federal Government contracting experience is advantageous.
- Preferred certifications include OSCP, OSCE, OWSE, CISSP, GPEN, GXPN, Security+ CE, or CEH.
- Strong leadership, teamwork, analytical, problem-solving, decision-making, communication, organizational, prioritization, and multitasking skills.
- Prior experience working remotely full-time.
Benefits
- Nationwide remote work within the United States, with core hours from 10:00 a.m. to 4:00 p.m. Eastern Time and flexibility to start earlier or work later depending on time zone.
- Travel to a conference or another ICF location for collaboration may be required approximately once a year.
- Position is contingent upon a contract award.
- Work must be performed in the United States; foreign locations, foreign IP addresses, and personal VPN connections are prohibited.
