> Markdown version of [/jobs/ext/1849046-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/1849046-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - **Company:** Babel - **Location:** Hopewell, VA, United States - **Experience:** Experienced - **Salary:** $100,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Linux, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Log Analysis, Networking Basics, Windows PowerShell, Azure Active Directory, Phishing, Kusto Query Language, Runbook, Security Information and Event Management, Software Vulnerability Management, Scripting, Google Cloud, Enterprise Software Applications, GitHub Copilot, Mitre Att&ck, Information Technology, Cybercrime, ArcSight Event Correlation, Restful APIs, Cyber Warfare, Splunk, GPT, Security Orchestration, Automation & Response - **Published:** July 11, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17552245?backUrl=%2Fcareer%2F17552245%2FInformation-Security-Engineer-Virginia-Reston ## About the Role * Bachelor's degree in Cybersecurity, Cyber Operations, Systems Security Engineering, Computer Science, Information Assurance, or a related technical discipline. * Three (3) or more years of experience in Information Security, Security Operations, or Security Engineering. * Experience with Microsoft XDR. * Experience with CrowdStrike Falcon. * Experience with Microsoft Entra ID, including Risky Users and Identity Protection. * Working knowledge of AWS, Microsoft Azure, and Google Cloud Platform (GCP). * Experience investigating security incidents. * Experience writing PowerShell, Python, or similar scripting languages. * Experience developing automations and operational workflows. * Experience creating, maintaining, and improving security run books, Standard Operating Procedures (SOPs), and incident response playbooks. Technical Competencies The ideal candidate should have experience with, or the ability to quickly become proficient in, the following: * Security incident response and investigation. * Endpoint Detection and Response (EDR/XDR) platforms. * Security Information and Event Management (SIEM) platforms. * Log analysis, event correlation, and threat hunting. * Detection engineering and alert tuning. * Identity and authentication investigations. * Microsoft 365 and Microsoft Entra ID security investigations. * Email security and phishing investigations. * Vulnerability management and remediation workflows. * PowerShell, Python, or similar scripting languages. * Kusto Query Language (KQL) and/or Splunk Processing Language (SPL). * Microsoft Graph API, REST APIs, and security automation. * Cloud security investigations across AWS, Azure, and GCP. * Developing and maintaining security run books, Standard Operating Procedures (SOPs), and incident response playbooks. * Working knowledge of the NIST Cybersecurity Framework (CSF). * Familiarity with the MITRE ATT&CK Framework and common adversary tactics, techniques, and procedures (TTPs). * Strong understanding of enterprise technology, including Windows, Linux, networking fundamentals, identity systems, cloud infrastructure, and common enterprise architectures., We're looking for an engineer. The ideal candidate is naturally curious and enjoys solving difficult technical problems. They don't stop at identifying an issue or escalating it to someone else. They take ownership, investigate thoroughly, and work toward implementing practical, long-term solutions., If you're the type of engineer who enjoys figuring things out, building new capabilities, and leaving systems better than you found them, you'll fit in well on this team. Desired Characteristics * Excellent verbal and written communication skills. * Highly proactive with a strong sense of ownership and accountability. * Strong analytical, troubleshooting, and critical thinking skills. * Exceptional organizational and documentation skills. * Ability to communicate effectively with both technical and non-technical audiences. * Comfortable collaborating across multiple technical teams. * Positive attitude and continuous improvement mindset. * High attention to detail and commitment to operational excellence. ## Description The Information Security Engineer is responsible for supporting and advancing the organization's information security program through security operations, incident response, automation, and continuous improvement initiatives. Working directly with the Information Security Manager, this role helps protect the organization's users, systems, applications, and data by monitoring security events, investigating incidents, administering security technologies, and improving operational capabilities. This position is highly technical and hands-on. Successful candidates possess a strong understanding of enterprise technologies, enjoy solving complex technical problems, and are driven to improve systems through engineering, automation, and process optimization. The ideal candidate is intellectually curious, communicates effectively, learns new technologies rapidly, and takes ownership of problems from initial investigation through implementation of practical, long-term solutions. They are comfortable working across infrastructure, cloud, identity, and endpoint technologies while collaborating with multiple technical teams to strengthen the organization's overall security posture. Responsibilities * Monitor, investigate, and respond to security alerts and incidents. * Administer Microsoft XDR, CrowdStrike Falcon, and Microsoft Entra ID. * Investigate phishing, identity attacks, endpoint detections, account compromise activity, and other security events. * Develop scripts, automations, and operational workflows to improve efficiency and reduce manual effort. * Create, maintain, and improve security run books, Standard Operating Procedures (SOPs), and incident response playbooks. * Document investigations, findings, technical procedures, and operational processes. * Assist with vulnerability management and remediation efforts. * Coordinate with Infrastructure, Cloud, IT, and Engineering teams to resolve security findings. * Research emerging threats, attack techniques, and security technologies. * Utilize AI tools to improve research, scripting, documentation, troubleshooting, and engineering productivity. * Recommend and implement improvements to security processes, detections, workflows, and automations. * Participate in security projects and perform additional duties as assigned., You do not need to know everything. What matters is the ability to learn quickly, research effectively, experiment, and solve problems that don't already have documented answers. Successful candidates will: * Take ownership of complex technical challenges and drive them through resolution. * Think critically, identify root causes, and solve problems rather than treating symptoms. * Independently research unfamiliar technologies, products, APIs, and attack techniques. * Build scripts, automations, and workflows that improve security operations. * Develop practical solutions when existing tools or processes are insufficient. * Continuously identify opportunities to improve security operations and business processes. * Learn new technologies exceptionally quickly and apply them with minimal supervision. * Be comfortable working through ambiguity, incomplete documentation, and unfamiliar technical environments. * Leverage AI tools such as OpenCode, Claude, Gemini, GitHub Copilot, ChatGPT, or similar platforms to accelerate research, scripting, engineering, documentation, and troubleshooting while maintaining sound technical judgment. * Demonstrate persistence and resourcefulness when solving problems that have no obvious solution. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top Characteristics of a Software Engineer](https://www.wearedevelopers.com/magazine/166-top-characteristics-of-a-software-engineer) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)