More jobs:
Security Engineer - Remote Security Clearance
Remote / Online - Candidates ideally in
Reston, Fairfax County, Virginia, 20190, USA
Listed on 2026-09-08
Reston, Fairfax County, Virginia, 20190, USA
Listing for:
ICF Consulting Group, Inc.
Remote/Work from Home
position Listed on 2026-09-08
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Description
* This role is contingent upon a contract award. The Work: ICFis looking for an enthusiastic
Security Engineer to join our team and helpwithensuring our environments and applications meet Federal Security Standards.
If you are Security Engineerinterested in applying yourexpertisein
Security
Engineering in a consulting environment, then this may be the role for you.
Job Location:
This position requires that the job be performed in the United States. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IPaddresses, andalso prohibits personal VPN connections.
* Our core work hours are 10am - 4pm Eastern Time with theoptionto start earlier or work later depending on your time zone.
However, please note our client is on the east coast and may sometimes start a meeting earlier than 10:00which may require your participation.
* Travel for a conference or to another ICF location for collaborationmayberequiredonce a year.
What You Will Do:
The selected candidate willbe required to work on multiple products and must be able to develop and present secure solutions and advice to technical teams as well as leadership. The candidate will furtherbe required to assess risks and advise on security standards, best practices, and solutions. All this must be done bymaintainingsecurity quality and customer satisfaction.
Various tools are used to detectvulnerabilitiesand the security engineer documents these vulnerabilities and works with developers to get them corrected. The security engineer will need to work on a path to production for new applications ensuring all the documentation and appropriate stepsare taken and approved to have a highly secure production application and environment. Responsibilities:
* Perform Static Application Security Testing (SAST) toidentifypotential vulnerabilities in the application code and infrastructure
* Perform Dynamic Application Security Testing (DAST)
* Create and update threat models for FISMA systems
* Assistand lead security incident response
* Assist with documentation of System Security plan and Contingency Plans for related projects
* Ensure security systems are up to date and create documentation and planning for all security-related information, including incident response and disaster recovery plans
* Review policies and procedures for compliance with applicable standards; and toidentifyareas of improvement for finding remediation
* Interact with senior level management, including the ISSO
* Use security assessment tools such as Nessus,Snyk, AWSGuard
Dutyand AWS Inspector
* Apply a demonstrated understanding of cryptography tosecureweb applications and data at rest
* Work with development teams to review and correctcode written in higher level programming languages and scripts
* Work with Dev Ops teams to securely harden Linux based machines and cloud infrastructure
Basic Qualifications:
* Bachelor's Degree
* 5+ years of professional security engineering experience
* Candidate must be able to obtain andmaintaina Public Trust
* Candidate mustresidein the U.S.,be authorized towork in the U.S., and all work must be performed in the U.S.
* Candidate must have lived in the U.S. for three (3) full years out of the last five (5) years What We Would Like You To Bring With You : .
* Hands on experience that includes:
* NIST 800-53 security controls
* System hardening and implementation of DoD STIGs
* Leading incident response activities
* Data management and applied cryptography
* Cloud security and infrastructure (AWS, Azure, and/or GCP)
* Awareness of OWASP Top Ten and CWE Top 25
* Linux command line usage (e.g., bash, sh, zsh)
* Scripting in Python, Perl, or similar languages
* Prior experience in consulting or healthcare is an advantage but not essential.
* Strong engineering background
* Application architecture experience
* Federal Government contracting work experience
* One or more of the following certifications is preferred:
* OSCP/OSCE/OWSE
* CISSP
* GPEN
* GXPN
* Security +
* CEH Professional
Skills:
* Goodleadershipandteam-working skills.
* Highly effective analytical,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×