Sr Information Security Engineer

Posted 3 Days Ago
Be an Early Applicant
Herndon, VA, USA
Hybrid
130K-170K Annually
Senior level
Information Technology • Software • Cybersecurity
The Role
Design and implement technical security controls across cloud, application, identity, and PKI environments. Assess architectures, perform threat modeling and risk assessments, produce control narratives/SSPs/POA&Ms, support audits (FedRAMP, SOC 2, ISO 27001), and work hands-on with DevOps, engineering, and operations to remediate, validate, and collect defensible evidence.
Summary Generated by Built In

Position Overview:

This position will serve as a member of the Exostar Information Security Office and will report to the Manager of Governance & Engineering. This role is responsible for designing and implementing technical security controls across application, cloud, identity, and PKI environments. The successful candidate will work directly with DevOps, application, and operations teams to engineer controls and satisfy security framework requirements. This role is ideal for a security engineer who can assess architecture, identify control gaps, implement remediation, and technically validate implementation effectiveness.

This role is ideal for candidates that have a skillset focused on engineering credibility, architectural judgment, and the ability to operate confidently with technical teams, auditors, customers, and leadership.

Responsibilities: Your day if you join us:

Security Architecture & Control Implementation

  • Assess, design, and provide guidance on secure architecture for cloud environments, including IAM, PKI, access, network, and platform services.
  • Engage directly with infrastructure, platform, and development teams to translate security requirements into implementable technical designs and controls.
  • Review proposed system changes, architecture diagrams, network flows, identity integrations, and control implementations for security implications.
  • Develop technical control implementation guidance, including diagrams, control narratives, configuration expectations, and test procedures.
  • Provide hands-on engineering support for control effectiveness through configuration review, evidence inspection, technical testing, log review, and remediation verification.
  • Perform threat modeling and security risk assessments and coordinate actionable mitigation strategies.

Compliance Engineering & Governance

  • Provide engineering support for controls aligned to frameworks such as PKI, identity certification, CMMC L2, FedRAMP Moderate, ISO/IEC 27001, IAM, SOC 2, etc.
  • Produce technical control descriptions that reflect security architecture, implementation, and operational behavior to create defensible control narratives to auditors and customers.
  • Produce SSPs, POA&Ms, control narratives, and audit responses where engineering interpretation is required.
  • Support audits and customer assessments by explaining technical controls, gathering defensible evidence, and validating that evidence against control intent.
  • Improve the repeatability and quality of evidence collection, control validation, and remediation tracking.

Qualifications:

You are a great fit for this role if you:

Required Skills:

  • 10+ years of hands-on experience evaluating secure architecture and implementing security controls in cloud environments.
  • Experience evaluating system architecture, network diagrams, data flows, identity integrations, and technical design documentation.
  • Experience performing threat modeling, technical risk assessments, security design reviews, and control gap assessments.
  • Experience integrating security into the SDLC, including CI/CD pipelines, Agile delivery, and DevSecOps practices.
  • Experience collaborating with engineering, infrastructure, DevOps, cloud, IAM, and operations teams to drive remediation to closure.
  • Strong understanding of network security concepts, including segmentation, firewalls, proxies, DNS, TLS, VPN/IPSec, routing, ingress/egress control, and secure network design.
  • Experience with identity and access technologies such as Active Directory, Entra ID/Azure AD, SAML, OIDC, MFA, privileged access, role-based access control, and identity federation.
  • Demonstrated experience authoring technical control narratives, technical audit documentation, and supporting evidence.
  • Experience supporting audits and assessments such as SOC 2, ISO 27001, etc.
  • Strong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership, and business stakeholders.
  • Significant experience using Jira and Confluence.
  • U.S. Citizens only- Due to customer requirements, U.S. Citizenship is required.  Ability to gain and maintain Trusted Role is required.

     Hybrid: Herndon, VA (3x/week)

    Preferred Qualifications:

    You are exactly who we are looking for if you

    • CMMC CCA or CCP certification.
    • FedRAMP audit lead or hands-on control implementation experience
    • CISSP and other similar technical certifications
    • Experience implementing Governance, Risk, and Compliance (GRC) tools
    • Experience with managing, securing, and auditing Public Key Infrastructure (PKI), including the certificate lifecycle management.
    • End-point Protections (HIPS/HIDS)
    • Demonstrated experience designing multi-tier, highly available, multi-threaded, scalable architectures.
    • Experience with web application programming, Java, APIs, or application-adjacent security engineering.
    • Secure development frameworks (e.g. OWASP SAMM, Microsoft Security Development Lifecycle, IBM Secure Engineering Framework, etc.)
    • Business Continuity and Disaster Recovery planning
    • Data Loss Prevention (DLP)
    • Data Labeling and Information Rights Management

    Education:

    • Bachelor’s degree from an accredited university in IT related discipline

    Exostar - The Company:
    Exostar’s cloud-based platforms create exclusive communities within the Aerospace and Defense, Life Sciences, and other highly regulated industries where members securely collaborate, share information, and operate compliantly. Within these communities we build trust. By analyzing community data, we provide insights and intelligence, enabling organizations to make better, timelier decisions, to mitigate risk, and operate more efficiently.

    We believe in employee development: we promote internally and provide training and educational assistance
    We provide a fun, engaged workplace, with social and community-building events
    We offer comprehensive benefits and flexible time off plans

    Exostar is an Equal Opportunity Employment Employer. The company provides equal employment opportunities to all applicants without regard to race, color, religion, sex, national origin, age, marital status, disability status or genetic information. Exostar is committed to providing equal employment opportunities for all persons in all facets of employment including recruiting, hiring, compensation, promotion, training, benefits, transfers and working conditions.


    The pay range for this position is $130,000k - $170,000k/yr; however, the final compensation will be determined based on factors including experience, skills, qualifications, and location. Exostar also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance, EAP, Flexible Spending Accounts, 401(k) matching, flexible time off and sick leave).





    Equal Opportunity Employer
    This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

    Skills Required

    • 10+ years hands-on experience evaluating secure architecture and implementing security controls in cloud environments
    • Experience evaluating system architecture, network diagrams, and data flows
    • Experience performing threat modeling, technical risk assessments, and control gap assessments
    • Experience integrating security into the SDLC, including CI/CD and DevSecOps practices
    • Experience collaborating with engineering, infrastructure, DevOps, cloud, IAM, and operations teams to drive remediation to closure
    • Strong understanding of network security concepts (segmentation, firewalls, proxies, DNS, TLS, VPN/IPSec, routing)
    • Experience with identity and access technologies (Active Directory, Entra ID/Azure AD, SAML, OIDC, MFA, privileged access, RBAC, federation)
    • Demonstrated experience authoring technical control narratives, technical audit documentation, and supporting evidence
    • Experience supporting audits and assessments such as SOC 2 and ISO 27001
    • Strong written and verbal communication skills to explain technical concepts to auditors, leadership, and stakeholders
    • Significant experience using Jira and Confluence
    • U.S. Citizenship required and ability to gain and maintain Trusted Role
    • Bachelor's degree in an IT-related discipline
    • CMMC CCA or CCP certification
    • FedRAMP audit lead or hands-on FedRAMP control implementation experience
    • CISSP or similar technical certifications
    • Experience implementing GRC tools
    • Experience managing, securing, and auditing PKI and certificate lifecycle
    • Endpoint protection experience (HIPS/HIDS)
    • Experience with web application programming, Java, APIs, or application-adjacent security engineering
    • Familiarity with secure development frameworks (OWASP SAMM, Microsoft SDL, etc.)
    • Business continuity and disaster recovery planning experience
    • Data Loss Prevention (DLP) experience
    • Data labeling and Information Rights Management experience
    Am I A Good Fit?
    beta
    Get Personalized Job Insights.
    Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

    The Company
    HQ: Herndon, Virginia
    272 Employees
    Year Founded: 2000

    What We Do

    The Exostar Platform supports exclusive communities within highly regulated industries where organizations securely collaborate, share information, and operate compliantly. Within these communities, we build trust. Over 200,000 companies and agencies and 1,000,000 users in 175 countries trust Exostar to strengthen security, reduce expenditures, raise productivity, and help them achieve their digital transformation initiatives. More than half of the Defense Industrial Base, including 98 of the top 100 firms, transact business over The Exostar Platform.

    Similar Jobs

    General Dynamics Information Technology Logo General Dynamics Information Technology

    Security Engineer

    Aerospace • Information Technology • Professional Services • Security • Software
    In-Office
    Reston, VA, USA
    21625 Employees
    162K-219K Annually

    GRVTY Logo GRVTY

    Security Engineer

    Information Technology • Software • Cybersecurity • Defense
    In-Office
    Sterling, VA, USA
    1000 Employees
    175K-260K Annually

    Amentum Logo Amentum

    Security Engineer

    Security • Cybersecurity
    In-Office
    Chantilly, VA, USA
    18261 Employees
    190K-225K Annually

    TENICA Global Solutions Logo TENICA Global Solutions

    Security Engineer

    Information Technology • Professional Services • Cybersecurity • Defense
    In-Office
    Chantilly, VA, USA

    Similar Companies Hiring

    Golden Pet Brands Thumbnail
    Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
    El Segundo, California
    178 Employees
    Kepler  Thumbnail
    Fintech • Software
    New York, New York
    6 Employees
    Onshore Thumbnail
    Artificial Intelligence • Fintech • Software • Financial Services
    New York, New York
    60 Employees

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account