ICF is seeking a Secure Software Assessment Subject Matter Expert (SME) to support a Defense Human Resources Activity (DHRA) cybersecurity this role you will oversee software assurance activities and lead efforts to ensure application security through secure coding practices code reviews and vulnerability analysis. The SME will advise developers and system owners on software security requirements manage static and dynamic code analysis and provide actionable recommendations to mitigate risk and strengthen DHRAs secure development posture.
This is for an expected future opportunity. The role can be based in either Alexandria VA or Seaside CA.
What Youll Do
Lead application security assessment and remediation activities across multiple DHRA software systems and environments.
Perform and oversee secure code reviews static (SAST) and dynamic (DAST) analysis and manual assessments to identify vulnerabilities.
Develop and maintain software security standards secure coding guidelines and review procedures consistent with DoD and NIST frameworks.
Advise development teams on remediation strategies secure design patterns and risk prioritization.
Coordinate integration of security tools into the software development lifecycle (CI/CD pipelines).
Support vulnerability tracking and closure through collaboration with developers system owners and RMF personnel.
Provide training and mentorship on secure coding principles and software assurance practices.
Generate detailed technical reports and executive summaries of findings trends and recommendations.
Evaluate and recommend application security technologies and techniques to improve software assurance capabilities.
Contribute to governance and continuous improvement of DHRAs software security processes.
Required Qualifications
Bachelors degree required
10 years of experience in software development vulnerability analysis or application security management.
Active DOD security clearance
Certifications:
CISSP-ISSEP
Desired Qualifications
Masters degree in computer science cybersecurity or software engineering.
Demonstrated expertise in software assurance secure coding and vulnerability remediation.
Hands-on experience with SAST/DAST tools such as Fortify Veracode Checkmarx or SonarQube.
Proficiency in one or more programming languages (e.g. Java C# Python JavaScript).
Experience developing or reviewing secure applications in DoD or Federal environments.
Experience integrating security into Agile and DevSecOps pipelines.
Familiarity with NIST SP 800-218 (Secure Software Development Framework) OWASP Top 10 and DoD DevSecOps guidance.
Knowledge of container security cloud-native application hardening and supply chain risk management.
Strong communication and collaboration skills with developers and system owners.
Ability to convey technical findings clearly to both technical and executive audiences.
#icfns
Working at ICF
ICF is a global advisory and technology services provider but were not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges navigate change and shape the future.We can only solve the worlds toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer.Together our employees are empowered to share theirexpertiseand collaborate with others to achieve personal and professional goals. For more information please read ourEEOpolicy.
We will consider for employment qualified applicants with arrest and conviction records.
Reasonable Accommodations are available including but not limited to for disabled veterans individuals with disabilities and individuals withsincerely heldreligious beliefs in all phases of the application and employment process. To requestan accommodationplease emailand we will be happy toassist. All information you provide will be kept confidential and will be used only to the extentto provide needed reasonable accommodations.
Read more aboutworkplacediscriminationrightsor our benefit offerings which are included in theTransparency in (Benefits) CoverageAct.
At ICF we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment the use of artificial intelligence (AI) tools to generate orassistwith responses during interviews (whether in-person or virtual) is notpermitted. This policy is in place tomaintainthe integrity and authenticity of the interview process.
However we understand that some candidates may require accommodationthat involves the use of AI. Ifsuch anaccommodation is needed candidates are instructed to contact us in advance at. Weare dedicated to providingthe necessary support to ensure that all candidates have an equal opportunity to succeed.
Pay Range - There are multiple factors that are considered in determining final pay for a position including but not limited to relevant work experience skills certifications and competencies that align to the specified role geographic location education and certifications as well as contract provisions regarding labor categories that are specific to the position.
The pay range for this position based on full-time employment is:
$107936.00 - $183491.00Virginia Client Office (VA88)
About ICF: The Integral Coach Factory is one of the earliest production units of independent India. It was inaugurated by the first Prime Minister of India Pt. Jawaharlal Nehru on 2nd October, 1955. Later the Furnishing Division was inaugurated on 2nd October, 1962 and the production ... View more