Security Engineer - Remote
Salary: $98,614 - 167,644 per year
Requirements:
We require a bachelors degree. We require at least 5 years of professional security engineering experience. You must be able to obtain and maintain a Public Trust clearance. You must reside in the U.S., be authorized to work in the U.S., and complete all work within the U.S. You must have lived in the U.S. for three full years out of the last five. Hands-on experience with NIST 800-53 security controls is preferred. Experience with system hardening and implementation of DoD STIGs is preferred. Experience leading incident response activities is preferred. Background in data management and applied cryptography is preferred. Cloud security and infrastructure experience with AWS, Azure, or Google Cloud Platform is preferred. Awareness of OWASP Top Ten and CWE Top 25 is preferred. Proficiency with Linux command-line tools such as bash, sh, or zsh is preferred. Scripting experience in Python, Perl, or similar languages is preferred. Strong engineering background is preferred. Application architecture experience is preferred. Federal government contracting experience is preferred. One or more certifications is preferred: OSCP, OSCE, OWSE, CISSP, GPEN, GXPN, Security+, or CEH. Good leadership and teamwork skills are preferred. Strong analytical, problem-solving, and decision-making abilities are preferred. Excellent communication and interpersonal skills are preferred. Strong organizational skills, attention to detail, and the ability to prioritize and manage multiple tasks are preferred. Ability to self-organize and deliver work across multiple projects under tight deadlines in a fast-paced environment is preferred. Prior full-time remote work experience is preferred.
Responsibilities:
We perform Static Application Security Testing (SAST) to uncover potential vulnerabilities in application code and infrastructure. We perform Dynamic Application Security Testing (DAST). We create and maintain threat models for FISMA systems. We assist with and lead security incident response efforts. We support documentation of System Security Plans and Contingency Plans for related projects. We ensure security systems remain current and maintain documentation and planning for incident response, disaster recovery, and other security information. We review policies and procedures for compliance with applicable standards and identify remediation opportunities. We work with senior leadership, including the ISSO. We use assessment tools such as Nessus, Snyk, AWS GuardDuty, and AWS Inspector. We apply our understanding of cryptography to secure web applications and data at rest. We collaborate with development teams to review and correct code written in higher-level programming languages and scripts. We partner with DevOps teams to harden Linux-based machines and cloud infrastructure. We develop and present secure solutions and guidance to both technical teams and leadership. We assess risk and advise on security standards, best practices, and remediation approaches. We document vulnerabilities and work with developers to resolve them. We support the path to production for new applications by ensuring required documentation, approvals, and security steps are completed.
Technologies:
AWS Azure Bash Cloud Cryptography DevOps Support Linux OWASP Perl Python REST Security Web AI VPN
More:
We are ICF, a global advisory and technology services provider that helps clients solve complex challenges, navigate change, and shape the future through a combination of deep expertise and advanced technology. This Security Engineer role supports our consulting team and focuses on helping our environments and applications meet federal security standards. The position is fully U.S.-based and requires work to be performed within the United States, with core hours centered on 10 a.m. to 4 p.m. Eastern Time and occasional earlier meetings due to client needs. Travel may be required about once a year for a conference or collaboration at another ICF location. We offer an inclusive workplace, are an equal opportunity employer, and consider qualified applicants with arrest and conviction records. The posted full-time pay range is $98,614 to $167,644, depending on experience, skills, certifications, location, education, and contract provisions.
last updated 30 week of 2026

