> Markdown version of [/jobs/ext/1440587-security-infrastructure-exposure-engineer](https://www.wearedevelopers.com/jobs/ext/1440587-security-infrastructure-exposure-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Infrastructure & Exposure Engineer - **Company:** AnaVation, LLC - **Location:** Reston, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Comptia Cloud+, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cloud Engineering, CompTIA Security+, Cyber Security, Continuous Integration, DevOps, Network Topologies, Inventory Management Software, Python (Programming Language), Azure Active Directory, Signalling Connection Control Part (SCCP), Scripting, Okta, Infrastructure Automation Frameworks, Enterprise Integration, Terraform, GPT, Programming Languages - **Published:** July 25, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87842233/1 ## About the Role * Clearance: Active TS/SCI Clearance with CI Polygraph * Education & Years of Experience: Bachelor's degree and 8 years of experience related to specific functional area. * Certifications: Active certifications for both IAT Level II (e.g. CompTIA Security+) and Cyber Security Service Provider (CSSP) Infrastructure Support (e.g. CompTIA Cloud+) by program onboarding date. * The following individual certifications cover both certification requirements for this program: CompTIA Cybersecurity Analyst, CySA+; EC-Council Certified Network Defender (CND); GlAC Global Industrial Cyber Security Professional, GICSP; (ISC)2 System Security Certified Practitioner (SCCP). * Hands-on experience and knowledge with the following: + Asset Discovery: Proven experience with CAASM tooling and building inventory systems. + Network & Graph Modeling: Deep understanding of network topology, segmentation verification, and graph-based attack path analysis. + Scanning & Identity: Hands-on experience with active/passive network scanning and correlating data with identity registries (e.g., Okta, Azure AD). + Cloud & DevOps: Strong background in cloud security architecture (AWS, GCP, or Azure), IaC (Terraform, OpenTofu), and CI/CD security validation. Preferred Qualifications: * Experience leveraging advanced AI models (e.g., ChatGPT, Grok, Claude) to automate security workflows: (ChatGPT, Grok, Claude, Claude Code, Codex) * Multiple scripting and development languages * Familiarity with developer-focused AI tools like Claude Code or OpenAI Codex to accelerate engineering velocity ## Description * Attack Surface Management: Architect and maintain Continuous Asset Attack Surface Management (CAASM) solutions for real-time asset discovery. * Attack Path Modeling: Map network topologies, analyze segmentation, and build automated attack path graphs to identify choke points. * Telemetry & Correlation: Integrate active/passive scanning data with Identity Provider (IdP) telemetry to pinpoint exposed or unmanaged infrastructure. * Pipeline Integration: Embed automated vulnerability and exposure testing into Infrastructure-as-Code (IaC) and CI/CD deployment pipelines. * Cloud Architecture Defense: Evaluate and harden complex cloud architectures against emerging exposure techniques. Primary Languages & Technical Stack * Go, Rust, and Python (at least one required) ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Speak, Code, Deploy: Transforming Developer Experience with Voice Commands](https://www.wearedevelopers.com/videos/1159-speak-code-deploy-transforming-developer-experience-with-voice-commands) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)