Information Security Engineer

Default Brand

Herndon (VA)

On-site

USD 100,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Comprehensive benefits
Flexible time off plans
Employee development opportunities

Job summary

A leading technology company in Herndon, Virginia is seeking a Senior Information Security Engineer. This role requires hands-on experience in security architecture and engineering for cloud and on-premise environments. The ideal candidate will possess over 7 years of IT security engineering experience and be adept in threat modeling, security risk assessments, and technical controls implementation. The role supports a hybrid work model with in-office work three times a week, offering a comprehensive benefits package and opportunities for professional growth.

Qualifications

  • 7+ years of demonstrated IT Security engineering experience providing guidance to technical teams.
  • 5+ years of experience performing threat modeling and security risk assessments.
  • Strong experience with secure SDLC practices in Agile and DevSecOps environments.
  • Significant experience working with ISO/IEC 27001/27002, NIST SP 800-171, and NIST SP 800-53.

Responsibilities

  • Assess, design, and provide guidance on secure architectures for on-premise and cloud environments.
  • Provide hands-on engineering support for the implementation of technical security controls.
  • Support internal and external audits and assessments, including direct interaction with auditors.

Skills

IT Security engineering
Threat modeling
Network engineering
Security controls implementation
Secure SDLC practices
Communication skills
Technical audit documentation
Jira
Confluence

Education

Bachelor's or master's degree in IT

Tools

Jira
Confluence
Core network services
Encryption technologies
Windows Active Directory

Job description

Overview

Position Title: Information Security Engineer
Location: Herndon, Virginia - Hybrid (in office 3x/week)

This senior-level Information Security Engineer will serve as a member of the Exostar Information Security Office and report to the Manager of Governance & Engineering. The role is hands-on with deep technical and architectural experience, translating that expertise into engineering, audit, policy, and compliance outcomes. The individual will independently assess risk, design and evaluate secure architectures, implement and validate technical security controls, and clearly articulate how those controls satisfy regulatory and audit requirements. The ideal candidate has strong engineering credibility across infrastructure, cloud, and identity-related systems, and is effective with customers, auditors, and technical stakeholders in high-visibility audit and customer-facing contexts.

Responsibilities: Your day if you join us:

  • Security Architecture & Engineering: Assess, design, and provide guidance on secure architectures for on-premise and cloud environments, including identity, access, network, and platform services.
  • Engage with infrastructure, platform, and development teams to translate security requirements into implementable technical designs and controls.
  • Provide hands-on engineering support for the implementation, validation, and remediation of technical security controls.
  • Perform threat modeling and security risk assessments and coordinate actionable mitigation strategies.
  • Audit, Compliance & Governance: Provide engineering support for controls aligned to frameworks such as CMMC L2, FedRAMP Moderate, ISO/IEC 27001, IAM, SOC 2, etc.
  • Write and maintain technical control descriptions based on current architecture and operational practices.
  • Support and lead internal and external audits and assessments, including direct interaction with auditors and customers.
  • Translate technical implementations into clear, accurate, and defensible audit evidence.
  • Create, review, and update information security policies, standards, procedures, and guidelines to reflect actual system architecture and operations.
  • Risk Management & Continuous Improvement: Identify, assess, and communicate security risks to technical and non-technical stakeholders.
  • Track remediation efforts and drive issues to closure across multiple teams.
  • Evaluate emerging technologies, regulatory changes, and industry trends to assess potential impact to Exostar’s security posture.
  • Identity Access Management Security: Provide subject matter expertise for IAM and PKI systems.
  • Support auditing and compliance of PKI, identity federation, and authentication services.
  • Collaborate on governance documentation related to identity, trusted roles, and access control programs.
Qualifications

You are a great fit for this role if you:

Required:

  • 7+ years of demonstrated IT Security engineering experience providing guidance to technical teams
  • 5+ years of demonstrated experience performing threat modeling and security risk assessments
  • 5+ years of demonstrated network engineering and administration experience
  • 5+ years of demonstrated experience designing and implementing security controls in on-premise and cloud environments
  • Strong experience with secure SDLC practices in Agile and DevSecOps environments
  • Demonstrated experience authoring SSPs, POA&Ms, and technical audit documentation
  • Significant experience working with ISO/IEC 27001/27002, NIST SP 800-171, and NIST SP 800-53
  • Experience supporting and participating in audits and assessments (e.g., SOC 2, ISO 27001, Cyber Essentials)
  • Strong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership, and business stakeholders
  • Significant experience working in Jira and Confluence
  • Ability to pass background investigation to attain and maintain Trusted Role access to company systems
  • Technical Experience / Familiarity: Core network services (HTTP, SMTP, DNS); Encryption technologies (IPSec, SSL/TLS); Network security controls (firewalls, proxies, NAC, phishing prevention, etc.); SIEM and logging architectures; Windows Active Directory and domain services

U.S. Citizens only

Due to customer requirements, U.S. Citizenship is required. Ability to gain and maintain Trusted Role is required

Preferred Qualifications:

You are exactly who we are looking for if you:

  • CMMC CCA or CCP
  • FedRAMP auditor / implementer
  • CISSP and other similar technical certifications
  • Experience with Governance, Risk, and Compliance tools
  • Cloud computing and architecture
  • Windows Domains and Active Directory
  • End-point Protections (HIPS/HIDS)
  • Web Application Programming (Java and related technologies)
  • Knowledge and demonstrated experience designing multi-tier, highly available, multi-threaded, scalable architectures
  • Secure development frameworks (e.g. OWASP SAMM, Microsoft Security Development Lifecycle, IBM Secure Engineering Framework, etc.)
  • Public Key Infrastructure (PKI)
  • Identity Federation Technologies (SAML, etc.)
  • Business Continuity and Disaster Recovery planning
  • SharePoint
  • Data Loss Prevention (DLP)
  • Data Labeling and Information Rights Management
  • S/MIME-based Secure Email
  • Windows Domains and Active Directory
  • Identity Access Management (IAM)

Education:

• Bachelor’s or master’s degree from an accredited university in IT related discipline

Exostar - The Company:

Exostar’s cloud-based platforms create exclusive communities within regulated industries where members securely collaborate, share information, and operate compliantly. We build trust by analyzing community data to provide insights and intelligence, enabling organizations to mitigate risk and operate more efficiently.

We believe in employee development: we promote internally and provide training and educational assistance

We provide a fun, engaged workplace with social and community-building events

We offer comprehensive benefits and flexible time off plans

Exostar is an Equal Opportunity Employment Employer. The company provides equal employment opportunities to all applicants without regard to race, color, religion, sex, national origin, age, marital status, disability status or genetic information. Exostar is committed to providing equal employment opportunities for all persons in all facets of employment including recruiting, hiring, compensation, promotion, training, benefits, transfers and working conditions.

Equal Opportunity Employer

This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Software Engineering
Manager, Software Engineering

Exostar • Cincinnati (OH)

Hybrid
USD 180,000 - 230,000
Compliance Program Manager
Compliance Program Manager

Exostar • Herndon (VA)

Hybrid
USD 90,000 - 120,000
Comprehensive benefits
Training and educational assistance
Social and community-building events
Director of DevOps
Director of DevOps

Default Brand • Herndon (VA)

On-site
USD 130,000 - 180,000
Comprehensive benefits
Flexible time off plans
Employee development and training
Sales Engineer
Sales Engineer

Exostar • Washington

Hybrid
USD 90,000 - 120,000
Employee development and training
Flexible time off plans
Community-building events
Director of DevOps
Director of DevOps

Exostar • Herndon (VA)

On-site
USD 140,000 - 180,000
Comprehensive benefits
Flexible time off
Employee development programs
+1
Training Analyst
Training Analyst

Exostar LLC • Herndon (VA)

On-site
USD 75,000 - 95,000
Health insurance
401(k) matching
Flexible time off
+2
Account Executive - A&D
Account Executive - A&D

Socket.dev • Herndon (VA)

Hybrid
USD 100,000 - 150,000
Health insurance
401(k) matching
Flexible time off
+1
Sr. Security Engineer
Sr. Security Engineer

United States Digital Space LLC • Hawthorne (CA)

On-site
USD 170,000 - 265,000
Stock options
Medical coverage
Dental coverage
+5
Account Executive - A&D
Account Executive - A&D

Default Brand • Herndon (VA)

Hybrid
USD 100,000 - 150,000
Health insurance
401(k) matching
Flexible time off
Sr. Security Engineer
Sr. Security Engineer

United States Digital Space LLC • El Segundo (CA)

On-site
USD 170,000 - 265,000
3 weeks of paid vacation
10+ paid holidays per year
Employee stock/long-term incentives