Security Software Engineer Jobs in Virginia
Security Software Engineer jobs in Virginia are concentrated in defense contracting, federal civilian agencies, and cybersecurity firms, making the state one of the most active markets in the country for this role at every level from associate to principal engineer. Northern Virginia, the Richmond metro, and Hampton Roads account for the majority of openings, anchored by employers such as Booz Allen Hamilton, General Dynamics Information Technology, and Leidos. The most in-demand specialties in Virginia are secure software development, cloud security engineering, and vulnerability research supporting classified and government programs. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 24+ Security Software Engineer jobs











Description
The Work: ICF is seeking an experienced and driven Software Security Engineer to lead and oversee mission-critical initiatives in support of the Defense Counterintelligence and Security Agency (DCSA). In this role, you will help safeguard applications and cloud-based systems by integrating security best practices throughout the software development lifecycle.
Job Location: This position is remote. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses and also prohibits personal VPN connections.
You may be asked to travel once a quarter to an office or client site.
Our core work hours are 8am - 5pm Eastern Time with the option to start earlier or work later depending on your time zone.
What You Will Do:
Proactively monitor and assess application and system security to identify vulnerabilities and potential threats.
Perform secure code reviews and static/dynamic analysis to strengthen application security and ensure adherence to secure coding standards.
Test and evaluate security tools, applications, and system configurations to validate compliance with federal and DoD security requirements.
Investigate and remediate potential security vulnerabilities, recommending and implementing corrective actions to reduce risk.
Design and implement security controls, tools, and automation to enhance protection across cloud and on-premise environments.
Provide guidance and training to development teams on secure coding practices and DevSecOps principles.
Develop and maintain technical documentation related to security architecture, risk findings, and mitigation strategies.
Prepare and deliver executive-level briefings, status reports, and performance updates to government stakeholders and corporate leadership.
Maintain a positive, results-oriented work environment by building partnerships with internal and external partners.
What You Will Bring With You:
Active Top Secret clearance.
Proven experience (5+ years) in application security, secure software development, or cybersecurity engineering.
What We Would Like You To Bring With You:
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related technical field.
2 years’ experience working with DCSA
5 years’ experience with working on/around cloud platforms in AWS.
Hands-on experience performing secure code reviews and vulnerability assessments using industry-standard tools (e.g., SAST, DAST, SCA).
Experience implementing security controls in cloud environments (e.g., AWS GovCloud or similar secure federal cloud environments).
Strong understanding of secure coding standards (e.g., OWASP, NIST, DoD STIGs).
Experience supporting systems within regulated or high-security environments.
Ability to self-organize, priorities and conduct research on multiple projects under tight deadlines in a fast-paced environment.
An ability to communicate and write clearly in English.
Professional Skills:
Highly effective analytical, problem-solving, and decision-making capabilities.
Excellent communication and interpersonal skills to interface effectively at all levels of the business.
#Li-cc1
#Indeed
#icfcleared
#dcsa2026
Working at ICF
ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future.We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy.
We will consider for employment qualified applicants with arrest and conviction records.
Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email Candidateaccommodation@icf.com and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
Read more about workplace discrimination rights or our benefit offerings which are included in the Transparency in (Benefits) Coverage Act.
Candidate AI Usage Policy
At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process.
However, we understand that some candidates may require accommodation that involves the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance at candidateaccommodation@icf.com. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed.
Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position.
The pay range for this position based on full-time employment is:
$119,323.00 - $202,850.00 Nationwide Remote Office (US99)See All 24 Security Software Engineer Jobs in Virginia
Find roles in Virginia that match your experience and apply in just a few clicks.
Find JobsSecurity Software Engineer Jobs by City in Virginia
Where Virginia roles are concentrated, by current openings.
Security Software Engineer Job Market in Virginia
A snapshot from current Virginia openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Retail
- Technology & Software
- Distribution & Wholesale
- E-Commerce & Online Marketplaces
- Banking & Financial Services
What Virginia Employers Look For
The qualifications that appear most often in security software engineer jobs across Virginia.
- Active security clearance at the Secret or Top Secret level required by most Virginia employers
- Bachelor's degree in computer science, cybersecurity, or a closely related engineering field
- Proficiency in secure coding practices across languages such as Java, Python, or C++
- Experience with NIST, RMF, or FedRAMP compliance frameworks common in federal contracting environments
- Relevant certifications such as CISSP, CEH, or CompTIA Security+ preferred or required
- Hands-on experience with penetration testing, threat modeling, or secure DevOps toolchains
Security Software Engineer Jobs in Virginia: Frequently Asked Questions
How do you become a security software engineer in Virginia?
Virginia does not require a state-issued license specifically for security software engineers, so the path runs through education and industry credentials. Most Virginia employers expect a bachelor's degree in computer science or cybersecurity, followed by certifications such as CompTIA Security+, CISSP, or CEH. Because so much of the Virginia market supports federal agencies and defense contractors, obtaining a security clearance early in your career is one of the most decisive steps you can take.
How much do security software engineers make in Virginia?
Security software engineers in Virginia earn a median of about $136,460 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $83,350 for the lowest 10% to over $211,930 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire security software engineers in Virginia?
Virginia security software engineer roles are posted by Amazon, Amazon Web Services, and ICF and others right now, based on current listings on Migrate Mate as of August 2026. Virginia's dense concentration of federal agencies and defense primes means a wide range of cleared and uncleared positions exist across the Northern Virginia corridor and beyond.
Which Virginia cities have the most security software engineer jobs?
Herndon, Reston, and Arlington have the most security software engineer openings in Virginia right now. Northern Virginia's proximity to the Pentagon, NSA facilities, and dozens of federal civilian agencies drives the dominant share of demand, while Richmond and Hampton Roads add significant volume through defense contractors and military installation support roles.
Are there remote security software engineer jobs in Virginia?
Yes, and more than most fields. About 80% of security software engineer openings tied to Virginia are remote or hybrid as of August 2026, reflecting the software-centric nature of the role. Work involving classified systems or secure enclaves typically requires on-site presence, while application security, cloud security architecture, and DevSecOps roles are the most likely to support remote arrangements.
How can I get hired as a security software engineer in Virginia with little or no experience?
The most realistic entry path is through an associate or junior security engineer role at a Virginia defense contractor or federal IT services firm, where cleared entry-level programs are common. Employers such as Booz Allen Hamilton and Leidos run structured new-graduate hiring programs out of their Northern Virginia offices. Lateral moves from software development, network administration, or IT support roles are common, and earning CompTIA Security+ before applying gives candidates a clear advantage without requiring prior security engineering experience.
Where can I find and apply to security software engineer jobs in Virginia?
You can find and apply to security software engineer jobs in Virginia on Migrate Mate, which lists current Virginia openings across defense contractors, federal agencies, and commercial cybersecurity firms. Find the roles that fit your background and apply directly to the employers posting them.
See All 24 Security Software Engineer Jobs in Virginia
Find roles in Virginia that match your experience and apply in just a few clicks.
Find Jobs