Senior Cyber Security Specialist; Top Secret
Remote / Online - Candidates ideally in
Reston, Fairfax County, Virginia, 22090, USA
Listed on 2026-07-23
Reston, Fairfax County, Virginia, 22090, USA
Listing for:
ICF Consulting Group, Inc.
Remote/Work from Home
position Listed on 2026-07-23
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Please note:
This role is contingent upon a contract award. While it is not an immediate opening, we are actively conducting interviews and extending offers in anticipation of the award.
ICF is seeking a Senior Cyber Security Specialist to support a secure federal Service Now program with multiple mission work streams. This role is responsible for helping maintain the security posture of the platform and supporting the security activities that keep development, testing, release, and sustainment efforts aligned to federal cybersecurity requirements.
The ideal candidate is an experienced security professional who can work across infrastructure, application, data, and development teams to support vulnerability management, access control, system authorization, and continuous monitoring. You will help ensure security is built into the lifecycle of the solution, not added after the fact, while also supporting operational workflows, release readiness, and compliance tracking in a fast-paced Agile environment.
Job Location: Remote work is authorized. Must support US Eastern time zone working hours. Preference to candidates who live in the Washington DC metro area.
* If you accept this position, you should note that ICF does monitor employee work locations blocks access from foreign locations/foreign IP addresses and prohibits personal VPN connections.
What You Will Do
- Support the security posture of enterprise Service Now systems and related applications
- Assist with security governance, system authorization, and continuous monitoring activities
- Develop, maintain, and update security documentation and artifacts such as SSPs, POA&Ms, risk registers, and related compliance materials
- Support ATO efforts, security assessments, evidence gathering, and control validation
- Track and remediate vulnerabilities, scan findings, and security issues through closure
- Coordinate with developers, administrators, testers, and program stakeholders to ensure security findings are understood and addressed
- Support access control reviews, role-based permissions, least-privilege practices, and secure user administration
- Help evaluate security implications of workflow changes, data integrations, releases, and configuration updates
- Support audit preparation, findings response, and ongoing compliance reporting
- Monitor and document security process changes, configuration updates, and remediation actions
- Contribute to secure release practices, including validation of fixes and scan remediation before deployment
- Support incident and issue triage from a security perspective when needed
- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or a related field
- 6+ years of relevant experience in information security, cybersecurity, or system security roles
- 6+ years of experience supporting federal security frameworks such as FISMA, NIST RMF, or similar
- 4+ years of experience supporting ATO processes, security documentation, and continuous monitoring
- 4+ years of experience with vulnerability management, security scanning tools, or remediation workflows
- 3+ years of experience conducting risk assessments, security analysis, or compliance reviews
- 3+ years of experience supporting cloud or enterprise system security
- Experience supporting federal Service Now environments or other enterprise workflow platforms
- Familiarity with RMF artifacts, ATO packages, POA&M tracking, and continuous monitoring programs
- Experience with identity and access management, role governance, or least-privilege design
- Experience supporting secure release practices, scan remediation, or Dev Sec Ops workflows
- Familiarity with vulnerability tools, static/dynamic analysis, or cloud security controls
- Experience supporting audit response, corrective action tracking, or security governance meetings
- Relevant cybersecurity certification such as Security+, CISSP, or equivalent
- Demonstrated ability to communicate security issues clearly to technical and non-technical stakeholders
- Strong organizational skills and attention to detail for compliance tracking and evidence management
#Li-cc1
#Indeed
Working at ICF
ICF…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×