> Markdown version of [/jobs/ext/1212567-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/1212567-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - **Company:** Exostar LLC - **Location:** Herndon, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Java (Programming Language), Active Directory, Application Programming Interfaces (APIs), Proxy Servers, Cloud Computing, Cyber Security, Computer Programming, Continuous Integration, Information Leak Prevention, Software Design Documents, DevOps, Domain Name System (DNS), Multi-Factor Authentication, Identity and Access Management, Internet Protocol Security (IP SEC), Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Network Security, Microsoft Security Essentials, Network Diagrams, Routing, OpenID, Open Web Application Security, Public Key Infrastructure, Systems Development Life Cycle, Role-Based Access Control, Azure Active Directory, Security Assertion Markup Language (SAML), Data Streaming, Systems Architecture, Systems Integration, Web Applications, Multithreading, Transport Layer Security, Cloud Platform System, Firewalls (Computer Science), Atlassian Tools, Devsecops - **Published:** July 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6680fb59564ac110 ## About the Role This role is ideal for candidates that have a skillset focused on engineering credibility, architectural judgment, and the ability to operate confidently with technical teams, auditors, customers, and leadership., You are a great fit for this role if you: * 5+ years of hands-on experience evaluating secure architecture and implementing security controls in cloud environments. * Experience evaluating system architecture, network diagrams, data flows, identity integrations, and technical design documentation. * Experience performing threat modeling, technical risk assessments, security design reviews, and control gap assessments. * Experience integrating security into the SDLC, including CI/CD pipelines, Agile delivery, and DevSecOps practices. * Experience collaborating with engineering, infrastructure, DevOps, cloud, IAM, and operations teams to drive remediation to closure. * Strong understanding of network security concepts, including segmentation, firewalls, proxies, DNS, TLS, VPN/IPSec, routing, ingress/egress control, and secure network design. * Experience with identity and access technologies such as Active Directory, Entra ID/Azure AD, SAML, OIDC, MFA, privileged access, role-based access control, and identity federation. * Demonstrated experience authoring technical control narratives, technical audit documentation, and supporting evidence. * Experience supporting audits and assessments such as SOC 2, ISO 27001, etc. * Strong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership, and business stakeholders. * Significant experience using Jira and Confluence. * Ability to pass background investigation to attain and maintain Trusted Role access to company systems. Preferred Qualifications: You are exactly who we are looking for if you * CMMC CCA or CCP certification. * FedRAMP audit lead or hands-on control implementation experience * CISSP and other similar technical certifications * Experience implementing Governance, Risk, and Compliance (GRC) tools * Experience with managing, securing, and auditing Public Key Infrastructure (PKI), including the certificate lifecycle management. * End-point Protections (HIPS/HIDS) * Demonstrated experience designing multi-tier, highly available, multi-threaded, scalable architectures. * Experience with web application programming, Java, APIs, or application-adjacent security engineering. * Secure development frameworks (e.g. OWASP SAMM, Microsoft Security Development Lifecycle, IBM Secure Engineering Framework, etc.) * Business Continuity and Disaster Recovery planning * Data Loss Prevention (DLP) * Data Labeling and Information Rights Management Education: * Bachelor's degree from an accredited university in IT related discipline ## Description This position will serve as a member of the Exostar Information Security Office and will report to the Manager of Governance & Engineering. This role is responsible for designing and implementing technical security controls across application, cloud, identity, and PKI environments. The successful candidate will work directly with DevOps, application, and operations teams to engineer controls and satisfy security framework requirements. This role is ideal for a security engineer who can assess architecture, identify control gaps, implement remediation, and technically validate implementation effectiveness., * Assess, design, and provide guidance on secure architecture for cloud environments, including IAM, PKI, access, network, and platform services. * Engage directly with infrastructure, platform, and development teams to translate security requirements into implementable technical designs and controls. * Review proposed system changes, architecture diagrams, network flows, identity integrations, and control implementations for security implications. * Develop technical control implementation guidance, including diagrams, control narratives, configuration expectations, and test procedures. * Provide hands-on engineering support for control effectiveness through configuration review, evidence inspection, technical testing, log review, and remediation verification. * Perform threat modeling and security risk assessments and coordinate actionable mitigation strategies. Compliance Engineering & Governance * Provide engineering support for controls aligned to frameworks such as PKI, identity certification, CMMC L2, FedRAMP Moderate, ISO/IEC 27001, IAM, SOC 2, etc. * Produce technical control descriptions that reflect security architecture, implementation, and operational behavior to create defensible control narratives to auditors and customers. * Produce SSPs, POA&Ms, control narratives, and audit responses where engineering interpretation is required. * Support audits and customer assessments by explaining technical controls, gathering defensible evidence, and validating that evidence against control intent. * Improve the repeatability and quality of evidence collection, control validation, and remediation tracking. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)