> Markdown version of [/jobs/ext/2656751-senior-software-security-engineer-cloud-govcloud-top-secret-cleared](https://www.wearedevelopers.com/jobs/ext/2656751-senior-software-security-engineer-cloud-govcloud-top-secret-cleared). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Software Security Engineer- Cloud/GovCloud (Top Secret cleared) - **Company:** ICF Incorporated, L.L.C. - **Location:** Reston, VA, United States - **Experience:** Expert - **Salary:** $119,323.0 - $202,850.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Cyber Security, System Configuration, Dynamic Program Analysis, IP Addressing, Virtual Private Networks (VPN), Open Web Application Security, Secure Coding, Software Engineering, Cloud Platform System, Software Security, Information Technology, Devsecops, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0463319a5bea75fa ## About the Role * Active Top Secret clearance. * Proven experience (5+ years) in application security, secure software development, or cybersecurity engineering., * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related technical field. * 2 years' experience working with DCSA * 5 years' experience with working on/around cloud platforms in AWS. * Hands-on experience performing secure code reviews and vulnerability assessments using industry-standard tools (e.g., SAST, DAST, SCA). * Experience implementing security controls in cloud environments (e.g., AWS GovCloud or similar secure federal cloud environments). * Strong understanding of secure coding standards (e.g., OWASP, NIST, DoD STIGs). * Experience supporting systems within regulated or high-security environments. * Ability to self-organize, priorities and conduct research on multiple projects under tight deadlines in a fast-paced environment. * An ability to communicate and write clearly in English. Professional Skills: * Highly effective analytical, problem-solving, and decision-making capabilities. * Excellent communication and interpersonal skills to interface effectively at all levels of the business. #Li-cc1 ## Description The Work: ICF is seeking an experienced and driven Software Security Engineer to lead and oversee mission-critical initiatives in support of the Defense Counterintelligence and Security Agency (DCSA). In this role, you will help safeguard applications and cloud-based systems by integrating security best practices throughout the software development lifecycle. Job Location: This position is remote. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses and also prohibits personal VPN connections. You may be asked to travel once a quarter to an office or client site. Our core work hours are 8am - 5pm Eastern Time with the option to start earlier or work later depending on your time zone. What You Will Do: * Proactively monitor and assess application and system security to identify vulnerabilities and potential threats. * Perform secure code reviews and static/dynamic analysis to strengthen application security and ensure adherence to secure coding standards. * Test and evaluate security tools, applications, and system configurations to validate compliance with federal and DoD security requirements. * Investigate and remediate potential security vulnerabilities, recommending and implementing corrective actions to reduce risk. * Design and implement security controls, tools, and automation to enhance protection across cloud and on-premise environments. * Provide guidance and training to development teams on secure coding practices and DevSecOps principles. * Develop and maintain technical documentation related to security architecture, risk findings, and mitigation strategies. * Prepare and deliver executive-level briefings, status reports, and performance updates to government stakeholders and corporate leadership. * Maintain a positive, results-oriented work environment by building partnerships with internal and external partners. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [The Sound of Privacy – What Your Spotify Data Reveals About You](https://www.wearedevelopers.com/videos/100346-the-sound-of-privacy-what-your-spotify-data-reveals-about-you) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)