ICF logo

Secure Software Assessment SME (Clearance Required) - Future Opportunity

ICFAlexandria, Virginia

$107,936 - $183,491 / year

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Job Description

ICF is seeking a Secure Software Assessment Subject Matter Expert (SME) to support a Defense Human Resources Activity (DHRA) cybersecurity program. In this role, you will oversee software assurance activities and lead efforts to ensure application security through secure coding practices, code reviews, and vulnerability analysis. The SME will advise developers and system owners on software security requirements, manage static and dynamic code analysis, and provide actionable recommendations to mitigate risk and strengthen DHRA’s secure development posture.

This is for an expected future opportunity. The role can be based in either Alexandria, VA or Seaside, CA.

What You’ll Do

  • Lead application security assessment and remediation activities across multiple DHRA software systems and environments.

  • Perform and oversee secure code reviews, static (SAST) and dynamic (DAST) analysis, and manual assessments to identify vulnerabilities.

  • Develop and maintain software security standards, secure coding guidelines, and review procedures consistent with DoD and NIST frameworks.

  • Advise development teams on remediation strategies, secure design patterns, and risk prioritization.

  • Coordinate integration of security tools into the software development lifecycle (CI/CD pipelines).

  • Support vulnerability tracking and closure through collaboration with developers, system owners, and RMF personnel.

  • Provide training and mentorship on secure coding principles and software assurance practices.

  • Generate detailed technical reports and executive summaries of findings, trends, and recommendations.

  • Evaluate and recommend application security technologies and techniques to improve software assurance capabilities.

  • Contribute to governance and continuous improvement of DHRA’s software security processes.

Required Qualifications

  • Bachelor’s degree required

  • 10 years of experience in software development, vulnerability analysis, or application security management.

  • Active DOD security clearance

  • Certifications:

    • CISSP-ISSEP

Desired Qualifications

  • Master’s degree in computer science, cybersecurity, or software engineering.

  • Demonstrated expertise in software assurance, secure coding, and vulnerability remediation.

  • Hands-on experience with SAST/DAST tools such as Fortify, Veracode, Checkmarx, or SonarQube.

  • Proficiency in one or more programming languages (e.g., Java, C#, Python, JavaScript).

  • Experience developing or reviewing secure applications in DoD or Federal environments.

  • Experience integrating security into Agile and DevSecOps pipelines.

  • Familiarity with NIST SP 800-218 (Secure Software Development Framework), OWASP Top 10, and DoD DevSecOps guidance.

  • Knowledge of container security, cloud-native application hardening, and supply chain risk management.

  • Strong communication and collaboration skills with developers and system owners.

  • Ability to convey technical findings clearly to both technical and executive audiences.

#icfns

Working at ICF

ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future.

We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer.Together, our employees are empowered to share theirexpertiseand collaborate with others to achieve personal and professional goals. For more information, please read our EEOpolicy.

We will consider for employment qualified applicants with arrest and conviction records.

Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals withsincerely heldreligious beliefs, in all phases of the application and employment process. To requestan accommodation,please email Candidateaccommodation@icf.com and we will be happy toassist. All information you provide will be kept confidential and will be used only to the extentto provide needed reasonable accommodations. 

Read more about workplace discrimination rightsor our benefit offerings which are included in the Transparency in (Benefits) CoverageAct.

Candidate AI Usage Policy

At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate orassistwith responses during interviews (whether in-person or virtual) is notpermitted. This policy is in place tomaintainthe integrity and authenticity of the interview process. 

However, we understand that some candidates may require accommodation that involves the use of AI. Ifsuch anaccommodation is needed, candidates are instructed to contact us in advance at candidateaccommodation@icf.com. Weare dedicated to providingthe necessary support to ensure that all candidates have an equal opportunity to succeed.

Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position.

The pay range for this position based on full-time employment is:

$107,936.00 - $183,491.00Virginia Client Office (VA88)

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall