×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Engineer

Job in Herndon, Fairfax County, Virginia, 22070, USA
Listing for: Default Brand
Full Time position
Listed on 2026-09-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Systems Engineer, IT Consultant
Salary/Wage Range or Industry Benchmark: 100000 - 150000 USD Yearly USD 100000.00 150000.00 YEAR
Job Description & How to Apply Below

Overview

Position Title:

Information Security Engineer

Location:

Herndon, Virginia - Hybrid (in office 3x/week)

This senior-level Information Security Engineer will serve as a member of the Exostar Information Security Office and report to the Manager of Governance & Engineering. The role is hands-on with deep technical and architectural experience, translating that expertise into engineering, audit, policy, and compliance outcomes. The individual will independently assess risk, design and evaluate secure architectures, implement and validate technical security controls, and clearly articulate how those controls satisfy regulatory and audit requirements.

The ideal candidate has strong engineering credibility across infrastructure, cloud, and identity-related systems, and is effective with customers, auditors, and technical stakeholders in high-visibility audit and customer-facing contexts.

Responsibilities:
Your day if you join us:

  • Security Architecture & Engineering:
    Assess, design, and provide guidance on secure architectures for on-premise and cloud environments, including identity, access, network, and platform services.
  • Engage with infrastructure, platform, and development teams to translate security requirements into implementable technical designs and controls.
  • Provide hands-on engineering support for the implementation, validation, and remediation of technical security controls.
  • Perform threat modeling and security risk assessments and coordinate actionable mitigation strategies.
  • Audit, Compliance & Governance:
    Provide engineering support for controls aligned to frameworks such as CMMC L2, FedRAMP Moderate, ISO/IEC 27001, IAM, SOC 2, etc.
  • Write and maintain technical control descriptions based on current architecture and operational practices.
  • Support and lead internal and external audits and assessments, including direct interaction with auditors and customers.
  • Translate technical implementations into clear, accurate, and defensible audit evidence.
  • Create, review, and update information security policies, standards, procedures, and guidelines to reflect actual system architecture and operations.
  • Risk Management & Continuous Improvement:
    Identify, assess, and communicate security risks to technical and non-technical stakeholders.
  • Track remediation efforts and drive issues to closure across multiple teams.
  • Evaluate emerging technologies, regulatory changes, and industry trends to assess potential impact to Exostar’s security posture.
  • Identity Access Management Security:
    Provide subject matter expertise for IAM and PKI systems.
  • Support auditing and compliance of PKI, identity federation, and authentication services.
  • Collaborate on governance documentation related to identity, trusted roles, and access control programs.
Qualifications

You are a great fit for this role if you
:

Required:

  • 7+ years of demonstrated IT Security engineering experience providing guidance to technical teams
  • 5+ years of demonstrated experience performing threat modeling and security risk assessments
  • 5+ years of demonstrated network engineering and administration experience
  • 5+ years of demonstrated experience designing and implementing security controls in on-premise and cloud environments
  • Strong experience with secure SDLC practices in Agile and Dev Sec Ops  environments
  • Demonstrated experience authoring SSPs, POA&Ms, and technical audit documentation
  • Significant experience working with ISO/IEC 27001/27002, NIST SP 800-171, and NIST SP 800-53
  • Experience supporting and participating in audits and assessments (e.g., SOC 2, ISO 27001, Cyber Essentials)
  • Strong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership, and business stakeholders
  • Significant experience working in Jira and Confluence
  • Ability to pass background investigation to attain and maintain Trusted Role access to company systems
  • Technical Experience / Familiarity:
    Core network services (HTTP, SMTP, DNS);
    Encryption technologies (IPSec, SSL/TLS);
    Network security controls (firewalls, proxies, NAC, phishing prevention, etc.); SIEM and logging architectures;
    Windows Active Directory and domain services

U.S. Citizens only

Due to…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary