Senior Security Engineer
Reston, VA - USA
Job Summary
The Work:
ICFis looking for an enthusiasticSenior Security Engineerto join our team and helpwithensuring our environments and applications meet Federal Security you areSecurity Engineerinterested in applying yourexpertiseinSecurityEngineeringin a consulting environment then this may be the role for you.
Job Location:
This position requires that the job be performed in the United States. If you accept this position you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IPaddresses andalso prohibits personal VPN connections.
- Our core work hours are 10am - 4pm Eastern Time with theoptionto start earlier or work later depending on your time please note our client is on the east coast and may sometimes start a meeting earlier than 10:00which may require your participation.
- Travel for a conference or to another ICF location for collaborationmayberequiredonce a year.
What You Will Do:
The selected candidate willbe requiredto work on multiple products and must be able to develop and present secure solutions and advice to technical teams as well as leadership. The candidate will furtherbe requiredto assess risks and advise on security standards best practices and solutions. All this must be done bymaintainingsecurity quality and customer tools are used to detectvulnerabilitiesand the security engineer documents these vulnerabilities and works with developers to get them corrected. The security engineer will need to work on a path to production for new applications ensuring all the documentation andappropriate stepsare taken and approved to have a highly secure production application and environment.
Responsibilities:
- Perform Static Application Security Testing (SAST) toidentifypotential vulnerabilities in the application code and infrastructure
- Perform Dynamic Application Security Testing (DAST)
- Create and update threat models for FISMA systems
- Assistand lead security incident response
- Assistwith documentation of System Security plan and Contingency Plans for related projects
- Ensure security systems are up to date and create documentation and planning for all security-related information including incident response and disaster recovery plans
- Review policies and procedures for compliance with applicable standards; and toidentifyareas of improvement for finding remediation
- Interact with senior level management including the ISSO
- Usesecurity assessment tools such as NessusSnyk AWSGuardDutyand AWS Inspector
- Apply a demonstrated understanding of cryptography tosecureweb applications and data at rest
- Work with development teams to review and correctcode written in higher level programming languages and scripts
- Work with DevOps teams to securely harden Linux based machines and cloudinfrastructure
Basic Qualifications:
- Bachelors Degree
- 5 years of professional security engineering experience
- Candidate must be able to obtain andmaintaina Public Trust
- Candidate mustresidein the authorized towork in the U.S. and all work must be performed in the U.S.
- Candidate must have lived in the U.S. for three (3) full years out of the last five (5) years
What We Would Like YouToBringWithYou:.
- Hands on experience that includes:
- NIST 80053 security controls
- System hardening and implementation of DoD STIGs
- Leading incident response activities
- Data management and applied cryptography
- Cloud security and infrastructure (AWS Azure and/or GCP)
- Awareness of OWASP Top Ten and CWE Top 25
- Linux command line usage (e.g. bash sh zsh)
- Scripting in Python Perl or similar languages
- Prior experience in consulting or healthcare is an advantage but not essential.
- Strong engineering background
- Application architecture experience
- Federal Government contracting work experience
- One or more of the following certifications is preferred:
- OSCP/OSCE/OWSE
- CISSP
- GPEN
- GXPN
- Security
- CEH
Professional Skills:
- Goodleadershipandteam-workingskills.
- Highly effective analytical problem-solving and decision-making capabilities.
- Excellent communication and interpersonal skills to interface effectively at all levels of the business.
- Organizeddetailed orientedand able to prioritize and multi-task.
- Ability to self-organizeprioritizeand conduct work on multiple projects under tight deadlines in a fast-paced environment.
- Prior experience working remotely full-time
#DMX-HES
Working at ICF
ICF is a global advisory and technology services provider but were not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges navigate change and shape the future.We can only solve the worlds toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer.Together our employees are empowered to share theirexpertiseand collaborate with others to achieve personal and professional goals. For more information please read ourEEOpolicy.
We will consider for employment qualified applicants with arrest and conviction records.
Reasonable Accommodations are available including but not limited to for disabled veterans individuals with disabilities and individuals withsincerely heldreligious beliefs in all phases of the application and employment process. To requestan accommodationplease emailand we will be happy toassist. All information you provide will be kept confidential and will be used only to the extentto provide needed reasonable accommodations.
Read more aboutworkplacediscriminationrightsor our benefit offerings which are included in theTransparency in (Benefits) CoverageAct.
At ICF we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment the use of artificial intelligence (AI) tools to generate orassistwith responses during interviews (whether in-person or virtual) is notpermitted. This policy is in place tomaintainthe integrity and authenticity of the interview process.
However we understand that some candidates may require accommodationthat involves the use of AI. Ifsuch anaccommodation is needed candidates are instructed to contact us in advance at. Weare dedicated to providingthe necessary support to ensure that all candidates have an equal opportunity to succeed.
Pay Range - There are multiple factors that are considered in determining final pay for a position including but not limited to relevant work experience skills certifications and competencies that align to the specified role geographic location education and certifications as well as contract provisions regarding labor categories that are specific to the position.
The pay range for this position based on full-time employment is:
$98614.00 - $167644.00Nationwide Remote Office (US99)Required Experience:
Senior IC
About Company
About ICF: The Integral Coach Factory is one of the earliest production units of independent India. It was inaugurated by the first Prime Minister of India Pt. Jawaharlal Nehru on 2nd October, 1955. Later the Furnishing Division was inaugurated on 2nd October, 1962 and the production ... View more