Information Security Engineer
Listed on 2026-07-26
-
IT/Tech
Cybersecurity, Systems Engineer, Information Security & Data Protection
Overview:
This senior-level Information Security Engineer will serve as a member of the Exostar Information Security Office and report to the Manager of Governance & Engineering. This role is designed for
hands-on security
engineer with strong architecture and implementation experience who can partner directly with infrastructure, platform, and product teams to design and build secure systems.
The primary focus of this role is
security architecture, control design, and engineering enablement
across cloud and on-premise environments. The ideal candidate is comfortable working in complex technical environments, translating security requirements into practical implementations, and validating that controls are operating effectively. While this role will support audit and compliance activities, its core function is to ensure systems are secure by design and continuously verifiable, rather than relying on manual audit processes.
Your day if you join us:
Security Architecture & Engineering
- Design and evaluate secure architectures across cloud and on-premise environments, including identity, access, network, and platform services.
- Partner with infrastructure, Dev Ops, and application teams to embed security into system design and delivery pipelines.
- Translate security requirements into enforceable technical controls.
- Provide hands‑on support for implementation and validation of security controls.
- Perform threat modeling and technical risk assessments for new and existing systems.
- Integrate security controls into CI/CD pipelines and infrastructure-as-code workflows.
- Partner with engineering teams to ensure secure deployment patterns are practical and scalable.
- Support secure implementation of identity federation, privileged access, and authentication services.
- Enable continuous validation of security controls, including configuration drift detection and policy enforcement.
- Reduce reliance on manual review by designing automated control validation and monitoring mechanisms.
- Support internal and external audits (e.g., ISO 27001, SOC 2, Cyber Essentials, Kantara, FPKI, FedRAMP, CMMC) by translating technical implementations into defensible evidence.
- Contribute to the development of technical control narratives aligned with system architecture.
- Implement and validate controls and remediation of findings across engineering teams.
- Drive in audit readiness activities, with a focus on engineering-driven evidence and automation rather than manual collection.
You are a great fit for this role if you
- 7+ years of demonstrated IT Security engineering experience providing guidance to technical teams
- 5+ years of demonstrated experience performing threat modeling and security risk assessments.
- 5+ years of demonstrated network engineering and administration experience
- 5+ years of demonstrated experience designing and implementing security controls in on-premise and cloud environments.
- Strong experience with secure SDLC practices in Agile and Dev Sec Ops environments.
- Demonstrated experience authoring SSPs, POA&Ms, and technical audit documentation.
- Significant experience working with ISO/IEC 27001/27002, NIST SP 800-171, and NIST SP 800-53.
- Experience supporting and participating in audits and assessments (e.g., SOC 2, ISO 27001, Cyber Essentials).
- Strong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership, and business stakeholders.
- Significant experience working in Jira and Confluence.
- Ability to pass background investigation to attain and maintain Trusted Role access to company systems.
- Core network services (HTTP, SMTP, DNS) and supporting server technologies.
- Encryption technologies (IPSec, SSL/TLS).
- Network security controls (firewalls, proxies, NAC, phishing prevention, etc.).
- SIEM and logging architectures; familiarity with FIM technologies.
- Windows Active Directory and domain services.
- U.S. Citizens only
- Due to customer requirements, U.S. Citizenship is required. Ability to gain and maintain Trusted Role is required
You are…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).