Software Security Engineer (Public Trust)

ICFWashington, DC
15hOnsite

About The Position

Our Digital Modernization Division is an information technology and management consulting department that offers integrated, strategic solutions to its public and private-sector clients. ICF has the expertise, agility, and commitment to design, build, and operate high-performance IT engines to support all aspects of our client’s business. ICF is seeking an experienced and driven Software Security Engineer to lead and oversee mission-critical initiatives in support of the General Service Administration (GSA). In this role, you will help safeguard applications and cloud-based systems by integrating security best practices throughout the software development lifecycle. Job Location: Must be able to go on-site 5 days a week to the client's office in Washington, DC. Hybrid work flexibility may be available after the first 90 days .

Requirements

  • Bachelor’s degree in Computer Science, Engineering, Information Systems, or related technical field
  • Professional certifications: CISSP, CISM, CISA, Security+, or GIAC certifications
  • 5 years experience with working on/around cloud platforms in AWS.
  • Must be able to obtain and maintain a Public Trust clearance.
  • MUST RESIDE IN THE United States (U.S.) and the work MUST BE PERFORMED in the United States (U.S.) as this work is for a federal contract, and laws do apply.

Nice To Haves

  • Hands-on experience performing secure code reviews and vulnerability assessments using industry-standard tools (e.g., SAST, DAST, SCA).
  • Experience implementing security controls in cloud environments (e.g., AWS GovCloud or similar secure federal cloud environments).
  • Strong understanding of secure coding standards (e.g., OWASP, NIST, DoD STIGs).
  • Experience supporting systems within regulated or high-security environments.
  • Ability to self-organize, priorities and conduct research on multiple projects under tight deadlines in a fast-paced environment.
  • Experience supporting and maintaining CATO
  • Understanding of the GSA FedRamp process
  • Experience with NIST Cybersecurity Framework or similar security frameworks
  • Ability to lead and direct teams to remediate compliance issues

Responsibilities

  • Integrate security best practices throughout the software development lifecycle (SDLC) for applications and cloud environments
  • Perform secure code reviews and vulnerability assessments using industry‑standard tools, including SAST, DAST, and SCA solutions
  • Design, implement, and validate security controls within cloud environments such as AWS and AWS GovCloud
  • Identify security weaknesses, prioritize risks, and support remediation efforts to ensure compliance with federal security requirements
  • Support systems operating in regulated and high‑security environments
  • Conduct research and provide recommendations on emerging security threats, tools, and best practices
  • Collaborate with development, DevOps, and compliance teams to ensure secure system design and implementation
  • Lead or guide teams in resolving compliance gaps and security findings under tight deadlines
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service