Information Security Engineer

Exostar LLC
Herndon, VA, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Access Java (Programming Language) Active Directory Application Programming Interfaces (APIs) Proxy Servers Cloud Computing Cyber Security Computer Programming Continuous Integration Information Leak Prevention Software Design Documents DevOps
+27 more
Domain Name System (DNS) Multi-Factor Authentication Identity and Access Management Internet Protocol Security (IP SEC) Virtual Private Networks (VPN) Information Systems Security Architecture Professional Network Security Microsoft Security Essentials Network Diagrams Routing OpenID Open Web Application Security Public Key Infrastructure Systems Development Life Cycle Role-Based Access Control Azure Active Directory Security Assertion Markup Language (SAML) Data Streaming Systems Architecture Systems Integration Web Applications Multithreading Transport Layer Security Cloud Platform System Firewalls (Computer Science) Atlassian Tools Devsecops

Job description

This position will serve as a member of the Exostar Information Security Office and will report to the Manager of Governance & Engineering. This role is responsible for designing and implementing technical security controls across application, cloud, identity, and PKI environments. The successful candidate will work directly with DevOps, application, and operations teams to engineer controls and satisfy security framework requirements. This role is ideal for a security engineer who can assess architecture, identify control gaps, implement remediation, and technically validate implementation effectiveness., * Assess, design, and provide guidance on secure architecture for cloud environments, including IAM, PKI, access, network, and platform services.

  • Engage directly with infrastructure, platform, and development teams to translate security requirements into implementable technical designs and controls.
  • Review proposed system changes, architecture diagrams, network flows, identity integrations, and control implementations for security implications.
  • Develop technical control implementation guidance, including diagrams, control narratives, configuration expectations, and test procedures.
  • Provide hands-on engineering support for control effectiveness through configuration review, evidence inspection, technical testing, log review, and remediation verification.
  • Perform threat modeling and security risk assessments and coordinate actionable mitigation strategies.

Compliance Engineering & Governance

  • Provide engineering support for controls aligned to frameworks such as PKI, identity certification, CMMC L2, FedRAMP Moderate, ISO/IEC 27001, IAM, SOC 2, etc.
  • Produce technical control descriptions that reflect security architecture, implementation, and operational behavior to create defensible control narratives to auditors and customers.
  • Produce SSPs, POA&Ms, control narratives, and audit responses where engineering interpretation is required.
  • Support audits and customer assessments by explaining technical controls, gathering defensible evidence, and validating that evidence against control intent.
  • Improve the repeatability and quality of evidence collection, control validation, and remediation tracking.

Requirements

This role is ideal for candidates that have a skillset focused on engineering credibility, architectural judgment, and the ability to operate confidently with technical teams, auditors, customers, and leadership., You are a great fit for this role if you:

  • 5+ years of hands-on experience evaluating secure architecture and implementing security controls in cloud environments.
  • Experience evaluating system architecture, network diagrams, data flows, identity integrations, and technical design documentation.
  • Experience performing threat modeling, technical risk assessments, security design reviews, and control gap assessments.
  • Experience integrating security into the SDLC, including CI/CD pipelines, Agile delivery, and DevSecOps practices.
  • Experience collaborating with engineering, infrastructure, DevOps, cloud, IAM, and operations teams to drive remediation to closure.
  • Strong understanding of network security concepts, including segmentation, firewalls, proxies, DNS, TLS, VPN/IPSec, routing, ingress/egress control, and secure network design.
  • Experience with identity and access technologies such as Active Directory, Entra ID/Azure AD, SAML, OIDC, MFA, privileged access, role-based access control, and identity federation.
  • Demonstrated experience authoring technical control narratives, technical audit documentation, and supporting evidence.
  • Experience supporting audits and assessments such as SOC 2, ISO 27001, etc.
  • Strong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership, and business stakeholders.
  • Significant experience using Jira and Confluence.
  • Ability to pass background investigation to attain and maintain Trusted Role access to company systems.

Preferred Qualifications:

You are exactly who we are looking for if you

  • CMMC CCA or CCP certification.
  • FedRAMP audit lead or hands-on control implementation experience
  • CISSP and other similar technical certifications
  • Experience implementing Governance, Risk, and Compliance (GRC) tools
  • Experience with managing, securing, and auditing Public Key Infrastructure (PKI), including the certificate lifecycle management.
  • End-point Protections (HIPS/HIDS)
  • Demonstrated experience designing multi-tier, highly available, multi-threaded, scalable architectures.
  • Experience with web application programming, Java, APIs, or application-adjacent security engineering.
  • Secure development frameworks (e.g. OWASP SAMM, Microsoft Security Development Lifecycle, IBM Secure Engineering Framework, etc.)
  • Business Continuity and Disaster Recovery planning
  • Data Loss Prevention (DLP)
  • Data Labeling and Information Rights Management

Education:

  • Bachelor’s degree from an accredited university in IT related discipline

Benefits & conditions

Pulled from the full job description

  • Tuition reimbursement, Exostar’s cloud-based platforms create exclusive communities within the Aerospace and Defense, Life Sciences, and other highly regulated industries where members securely collaborate, share information, and operate compliantly. Within these communities we build trust. By analyzing community data, we provide insights and intelligence, enabling organizations to make better, timelier decisions, to mitigate risk, and operate more efficiently.
  • We believe in employee development: we promote internally and provide training and educational assistance
  • We provide a fun, engaged workplace, with social and community-building events
  • We offer comprehensive benefits and flexible time off plans

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo ¡ LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum ¡ WWC Europe 2026

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos ¡ LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas SßdbrÜcker ¡ LIVE

Videos

See all

Related articles

See all