> Markdown version of [/jobs/ext/1408451-secure-software-assessment-sme-clearance-required-future-opportunity](https://www.wearedevelopers.com/jobs/ext/1408451-secure-software-assessment-sme-clearance-required-future-opportunity). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Secure Software Assessment SME (Clearance Required) - Future Opportunity - **Company:** ICF Incorporated, L.L.C. - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Salary:** $108,476.0 - $184,409.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), Agile Methodology, C Sharp (Programming Language), Cloud Engineering, Static Program Analysis, Code Review, Information Systems Security Engineering Professional, Python (Programming Language), Open Web Application Security, Fortify (Software), Secure Coding, Software Engineering, Software Systems, SonarQube, Software Vulnerability Management, Software Security, Veracode, Information Technology, Checkmarx, Devsecops, Static Application Security Testing, Vulnerability Analysis, Programming Languages, Dynamic Application Security Testing - **Published:** July 23, 2026 - **Apply:** https://dejobs.org/x/x/F71EA9D6156646EAABAA44C4A329020A/job/ ## About the Role * Bachelor's degree required * 10 years of experience in software development, vulnerability analysis, or application security management. * Active DOD security clearance * Certifications: * CISSP-ISSEP, * Master's degree in computer science, cybersecurity, or software engineering. * Demonstrated expertise in software assurance, secure coding, and vulnerability remediation. * Hands-on experience with SAST/DAST tools such as Fortify, Veracode, Checkmarx, or SonarQube. * Proficiency in one or more programming languages (e.g., Java, C#, Python, JavaScript). * Experience developing or reviewing secure applications in DoD or Federal environments. * Experience integrating security into Agile and DevSecOps pipelines. * Familiarity with NIST SP 800-218 (Secure Software Development Framework), OWASP Top 10, and DoD DevSecOps guidance. * Knowledge of container security, cloud-native application hardening, and supply chain risk management. * Strong communication and collaboration skills with developers and system owners. * Ability to convey technical findings clearly to both technical and executive audiences. #icfns ## Description ICF is seeking a Secure Software Assessment Subject Matter Expert (SME) to support a Defense Human Resources Activity (DHRA) cybersecurity program. In this role, you will oversee software assurance activities and lead efforts to ensure application security through secure coding practices, code reviews, and vulnerability analysis. The SME will advise developers and system owners on software security requirements, manage static and dynamic code analysis, and provide actionable recommendations to mitigate risk and strengthen DHRA's secure development posture. This is for an expected future opportunity. The role can be based in either Alexandria, VA or Seaside, CA. What You'll Do * Lead application security assessment and remediation activities across multiple DHRA software systems and environments. * Perform and oversee secure code reviews, static (SAST) and dynamic (DAST) analysis, and manual assessments to identify vulnerabilities. * Develop and maintain software security standards, secure coding guidelines, and review procedures consistent with DoD and NIST frameworks. * Advise development teams on remediation strategies, secure design patterns, and risk prioritization. * Coordinate integration of security tools into the software development lifecycle (CI/CD pipelines). * Support vulnerability tracking and closure through collaboration with developers, system owners, and RMF personnel. * Provide training and mentorship on secure coding principles and software assurance practices. * Generate detailed technical reports and executive summaries of findings, trends, and recommendations. * Evaluate and recommend application security technologies and techniques to improve software assurance capabilities. * Contribute to governance and continuous improvement of DHRA's software security processes. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Why Security-First Development Helps You Ship Better Software Faster](https://www.wearedevelopers.com/videos/1568-why-security-first-development-helps-you-ship-better-software-faster) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)