Senior Cyber Capability Developer - DOJ CJIS
Location
US-WV-Clarksburg
ID
2025-1384
Overview
JOB TITLE: Senior Cyber Capability Developer GOVERNMENT AGENCY: Federal Bureau of Investigation (FBI), CJIS Information Assurance Unit (CIAU) LOCATION: Hybrid Position at the FBI CJIS location in Clarksburg, WV; this is a primarily remote position, however, occasional travel to the site may be requested by the customer POSITION TIMING: Contingent on award; expected contract start date August 30, 2025 BENEFITS: Health, Dental and Vision, 401(k), Flexible Spending Account (FSA), 11 Paid Federal Holidays, PTO, education reimbursement CLEARANCE REQUIREMENT: Candidate must hold an active Top-Secret clearance. Additionally, the candidate must obtain FBI CJIS access, which typically takes3-4 weeks to processandmust be completed prior to startingon the program. ITC Federal is an information technology and consulting company focused on servicing the needs of the Federal Government. ITC's mission is to apply earned expertise in information technology and information assurance/security to assist this client in achieving its mission. ITC is located in Fairfax, VA and offers outstanding compensation and benefits plan and a challenging and rewarding professional work environment. We are seeking a highly skilled Senior Cyber Capability Developer to support the FBI CJIS Division in securing and validating mission-critical software systems and applications. This role is essential in identifying vulnerabilities, malicious logic, and weaknesses in both source code and compiled binaries. The ideal candidate brings deep expertise in reverse engineering, static/dynamic analysis, and secure development practices to enhance cyber resilience across CJIS systems and services.
Responsibilities
Assist Information System Security Officers (ISSOs) in the evaluation of delivered software for security risks and potential vulnerabilities.
- Perform static analysis of source code written in common programming and scripting languages including, but not limited to: C, C++, Java, C#, Groovy, Python, Perl, JavaScript, Bash, Powershell, Ruby, Pup, and Objective-C.
- Conduct dynamic, manual, and automated binary reverse engineering of applications to identify the presence of vulnerabilities or potentially malicious logic.
- Provide expert technical guidance on indicators of malicious behavior or logic in both source and compiled code.
- Analyze third-party and internal code libraries to assess for weaknesses and ensure alignment with OWASP Top 10 and other industry standards.
- Develop and maintain frameworks, internal tools, scripts, and application extensions that enhance software security analysis processes.
- Perform in-depth reverse engineering of known and unknown malicious binaries, as well as hardware/firmware analysis where applicable.
- Guide and support secure software development practices, providing recommendations for improving secure coding methodologies and defensive programming techniques.
- Advise stakeholders on secure web development, including secure interface design, data protection, and industry-standard web application security controls.
- Assist CJIS program teams in identifying and assessing operational and technical risks, threats, and vulnerabilities to CJIS applications and infrastructure.
- Deliver technical presentations, briefings, and knowledge transfers to technical and non-technical audiences in support of agency security awareness and education initiatives.
Qualifications
REQUIRED:
- Minimum of 6 years of experience in cybersecurity, secure software development, malware analysis, or reverse engineering.
- Demonstrated experience with both static and dynamic analysis of applications, binaries, and scripts.
- Strong technical proficiency in multiple programming and scripting languages, with the ability to identify logic flaws and security vulnerabilities.
- Hands-on experience conducting reverse engineering and binary analysis using commercial and open-source tools.
- Familiarity with secure coding standards, secure web development practices, and software assurance methodologies.
- Ability to clearly articulate technical findings and present them to a variety of audiences including developers, engineers, and leadership.
- Security Clearance: Active Top Secret clearance.
DESIRED:
- Masters Degree, preferred; Bachelors and 2+ years of additional work experience can be substituted in lieu of the advanced degree requirement
- Security+, CISSP, or CEH certification.
- Experience supporting federal cybersecurity programs or working in classified environments.
- Familiarity with Agile or DevSecOps software development environments and toolsets.
- Experience developing custom tools or automations to improve vulnerability identification and mitigation workflows.
WORK ENVIRONMENT AND PHYSICAL DEMANDS:
- Candidate must be able to function in general office environment.
ITC Federal is an equal opportunity employer and will not discriminate against any application for employment on the basis of age, race, color, gender, national origin, religion, creed, disability, veteran status, marital status, sexual orientation, genetic information, military status, disability, or sex including pregnancy and childbirth or related medical condition or on any other basis prohibited by law.
|