Jobs and Careers
IC

Senior AWS Security Engineer- Remote

ICF
Nationwide Remote Office (US99), United States, United StatesRemotefull_timeVerifiedPosted 28 Apr 2025
💰 $166,810/yr($98,124/yr$166,810/yr)

About the role

 *We are open to supporting 100% remote work anywhere within the continental US*

ICF’s Digital Modernization Division is a rapidly growing, entrepreneurial, technology department. Our team is a leading provider of Digital Transformation services for Federal agencies. Our services focus on enabling agency mission and business transformation using industry-leading low-code platforms, mobile applications, robotics process automation and data analytics platforms. We are partnered with some of the world’s leading and most innovative companies like Salesforce, ServiceNow, Microsoft and UiPath. We focus on offering a full range of architecture and planning, system implementation, integration, analytics and O&M for our customers. 

We are seeking a Senior Security Engineer to support our Federal customer’s CIO Cyber Security organization and manage all vulnerability remediation activities, including Binding Operational Directive (BOD) compliance. 

 

Responsibilities: 

  • Perform Security Impact Analyses on application releases and provide recommendations to federal leadership 

  • Perform software vulnerability scans, interpret the results, and provide vulnerability mitigation recommendations 

  • Support and develop analyses of alternatives and decisions on courses of action by providing security insights to project teams and federal leadership 

  • Review and provide recommendations on requests for AWS policy changes 

  • Work with development teams and other stakeholders to review code and accurately flag False Positives in SonarQube and improve the overall utility of the tool 

  • Perform new software evaluation for cyber compliance and mitigation, section 508 compliance and privacy reviews of the software for authorization Approved Software list. 

  • The ability to write and review policy documentation based on industry standards. 

  • Support regular updates to secure coding standards documentation and the ongoing assessment of the customer organization against the NIST Cyber Security Framework 

  • Support Information Security Center vulnerability management groups by performing asset inventory, secure configurations and continuous monitoring, tracking and reporting and vulnerability service catalog. 

  • Support Vulnerability Management activities related specifically to Cloud systems, High Value Assets (HVAs), Mobile Device, and Internet of Things (IoT) assets including testing, certifying, verification and authorization activities. 

  • Based on your experiences and interests, we may ask you as a technology professional to support growth-related activities, including (but not limited to) RFI, RFP, prototypes, and oral presentations. 

  • Team members are also expected to uphold and maintain appropriate certifications necessary for their practice expertise. 

 

Basic Qualifications: 

  • 4+ years of Cyber/Network security management activities, including developing, writing and implementing procedures to ensure compliance with FISMA and NIST requirements, 508 compliance and other Federal IT security management guidelines. 

  • 3+ years of experience with AWS Security  

  • 3+ years of Application Security experience 

  • 3+ years of experience with software vulnerability scanning tools such as Fortify WebInspect, Qualys, and SonarQube, and familiarity of AWS policy. 

  • 2+ years of experience using SDLC Methodologies 

  • Due to federal contract, candidate must have been US Citizen or Green Card holder for 3 or more years.

  • Must be able to obtain Public Trust clearance.

  • MUST RESIDE IN THE U

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ICF

View company profile →