ICF

Security Engineer - Remote

ICF
Apply
1 hour ago
Reston, VA, USASenior

Base Salary

$99k - $168k/yr

Responsibilities

  • Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify application and infrastructure vulnerabilities.
  • Create and update threat models for FISMA systems.
  • Assist with and lead security incident response activities.
  • Document vulnerabilities and collaborate with developers on remediation.
  • Support System Security Plan and Contingency Plan documentation.
  • Maintain security systems and prepare security, incident response, and disaster recovery documentation.
  • Review policies and procedures for compliance with applicable standards and identify remediation improvements.
  • Advise technical teams and leadership on risks, security standards, best practices, and secure solutions.
  • Use Nessus, Snyk, AWS GuardDuty, and AWS Inspector for security assessments.
  • Apply cryptography to secure web applications and data at rest.
  • Review and correct code written in higher-level programming languages and scripts.
  • Work with DevOps teams to harden Linux machines and cloud infrastructure.
  • Ensure new applications follow required security documentation, approval, and production-readiness steps.

Requirements

  • Bachelor’s degree.
  • At least 5 years of professional security engineering experience.
  • Ability to obtain and maintain a Public Trust.
  • Must reside in the United States, be authorized to work in the United States, and perform all work in the United States.
  • Must have lived in the United States for 3 full years out of the last 5 years.
  • Hands-on experience with NIST 800-53 security controls, system hardening, DoD STIGs, incident response, data management, applied cryptography, cloud security, and infrastructure.
  • Knowledge of AWS, Azure, and/or GCP cloud security and infrastructure.
  • Awareness of the OWASP Top Ten and CWE Top 25.
  • Linux command-line experience, including bash, sh, or zsh.
  • Scripting experience in Python, Perl, or similar languages.
  • Strong engineering background and application architecture experience.
  • Consulting, healthcare, or Federal Government contracting experience is advantageous.
  • Preferred certifications include OSCP, OSCE, OWSE, CISSP, GPEN, GXPN, Security+ CE, or CEH.
  • Strong leadership, teamwork, analytical, problem-solving, decision-making, communication, organizational, prioritization, and multitasking skills.
  • Prior experience working remotely full-time.

Benefits

  • Nationwide remote work within the United States, with core hours from 10:00 a.m. to 4:00 p.m. Eastern Time and flexibility to start earlier or work later depending on time zone.
  • Travel to a conference or another ICF location for collaboration may be required approximately once a year.
  • Position is contingent upon a contract award.
  • Work must be performed in the United States; foreign locations, foreign IP addresses, and personal VPN connections are prohibited.
ICF

About ICF

10,000+ employees
Contact me