Match score not available

Senior Security Engineer

extra holidays - extra parental leave - fully flexible
Remote: 
Full Remote
Contract: 
Salary: 
98 - 167K yearly
Experience: 
Senior (5-10 years)

Offer summary

Qualifications:

Bachelor's degree or equivalent experience, 7+ years IT engineering experience, 5+ years of Security Engineering experience, US citizenship required with Public Trust clearance..

Key responsabilities:

  • Perform Static and Dynamic Application Security Testing (SAST and DAST)
  • Develop secure solutions and provide guidance to technical teams and leadership.

ICF logo
ICF XLarge https://www.icf.com
5001 - 10000 Employees
See all jobs

Job description

The Company 

ICF is a leading company specializing in the design and development of digital health services, and the work we do is just as unique as the culture we’ve created. We develop cutting-edge solutions to complex problems for commercial, academic, and government organizations. The systems we develop are used in finding cures for deadly diseases, improving the quality of healthcare delivered to millions of people, and revolutionizing the healthcare industry on a nationwide scale. There is a meaningful connection between our work and the real people who benefit from it; and, as such, we create an environment in which new ideas and innovative strategies are encouraged. We are an established company with the mindset of a startup, and we feel confident that we offer an employment experience unlike any other and that we set our employees up for professional success every day.  
 

The Team 

ICF is looking for a Security Engineer to keep our business, users, and data safe by assuring the security of our applications and platforms. This will be a highly collaborative position, in which the right candidate works to secure existing applications and platforms, makes platform and security enhancements, and helps to scale our security program through automation, process improvement, and tool creation.  
 

The Work 

The selected candidate will be required to work on multiple products and must be able to develop and present secure solutions and advice to technical teams as well as leadership. The candidate will further be required to assess risks and advise on security standards, best practices, and solutions. All this must be done by maintaining security quality and customer satisfaction.  
 

Responsibilities:  

  • Bachelor's degree or strong equivalent experience. 

  • 10 years of experience in IT or technical engineering. 

  • Perform Static Application Security Testing (SAST) to identify potential vulnerabilities in the application code and infrastructure  

  • Perform Dynamic Application Security Testing (DAST)  

  • Create and update threat models for FISMA systems  

  • Assist and lead security incident response  

  • Assist with documentation of System Security plan and Contingency Plans for related projects  

  • Ensure security systems are up to date and create documentation and planning for all security-related information, including incident response and disaster recovery plans  

  • Review policies and procedures for compliance with applicable standards; and to identify areas of improvement for finding remediation  

  • Interact with senior level management, including the ISSO  

  • Use security assessment tools such as Nessus, Snyk, AWS GuardDuty and AWS Inspector  

  • Apply a demonstrated understanding of cryptography to secure web applications and data at rest  

  • Work with development teams to review and correct code written in higher level programming languages and scripts   

  • Work with DevOps teams to securely harden Linux based machines and cloud infrastructure  
     

Required Qualifications: 

  • Bachelor's degree or strong equivalent experience 

  • 7+ years of experience in IT or technical engineering 

  • 5+ years of Security Engineering experience 

  • Candidate must be able to obtain and maintain a Public Trust clearance 

  • Candidate must reside in the U.S., be authorized to work in the U.S., and all work must be performed in the U.S. Candidate must have lived in the U.S. for three (3) full years out of the last five (5) years 

  • Must be able to travel approximately 5% 

 

Professional Skills: 

  • Strong communication skills (both verbal and written) 

  • Strong analytical skills  

 

Preferred Qualifications: 

  • Bachelors degree or higher in Computer Science, Electrical Engineering, Information Assurance, Network Security Computer Engineering or a related field, or equivalent experience strongly preferred 

  • Experience with NIST 800-53 security controls 

  • Experience in System Hardening (blue team) Implementing 

  • Experience with DoD STIGs Leading Incident Response 

  • Experience with Data management Applied cryptography 

  • Experience with Cloud Security and Infrastructure (AWS, Azure, GCP) 

  • Understand the OWASP Top Ten and CWE Top 25 Linux command line (sh, bash, or zsh) 

  • Experience working with Python, Perl or other scripting languages 

  • Application architecture experience   

  • Experience working in the healthcare industry  

  • Federal Government contracting work experience  

  • Prior experience working remotely full-time  

  • One or more of the following certifications is preferred.OSCP/OSCE/OWSE - CISSP - GPEN- GXPN - Security + - CEH 

 

Job Location: This position requires that the job be performed in the United States. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses, and also prohibits personal VPN connections.

Working at ICF

ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future.

We can only solve the world's toughest challenges by building an inclusive workplace that allows everyone to thrive. We are an equal opportunity employer, committed to hiring regardless of any protected characteristic, such as race, ethnicity, national origin, color, sex, gender identity/expression, sexual orientation, religion, age, disability status, or military/veteran status. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO & AA policy.

Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation please email Candidateaccommodation@icf.com and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. Read more here: Requesting an Accommodation for the ICF interview process.

Read more about workplace discrimination rights, the Pay Transparency Statement, or our benefit offerings which are included in the Transparency in (Benefits) Coverage Act.

 

Candidate AI Usage Policy

At ICF, we are committed to ensuring a fair and equitable interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process. 

However, we understand that some candidates may require accommodations that involve the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance at candidateaccommodation@icf.com. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed. 


 

Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position.

The pay range for this position based on full-time employment is:

$98,124.00 - $166,810.00

Nationwide Remote Office (US99)

Required profile

Experience

Level of experience: Senior (5-10 years)
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Communication
  • Analytical Skills

Security Engineer Related jobs