Exostar logo
ExostarPosted 1 month ago

Sr Information Security Engineer

HybridHerndon, Virginia, United States

Full TimeSenior LevelMedium

Job Summary

Assess, design, and implement secure architecture for cloud environments including IAM, PKI, and network services. Engage with DevOps and engineering teams to translate security requirements into technical controls, review system changes and diagrams for implications, and develop implementation guidance. Perform threat modeling, risk assessments, and gap analyses while providing hands-on support through configuration reviews, evidence inspection, and remediation verification. Produce control narratives, SSPs, and audit responses to satisfy frameworks like FedRAMP, SOC 2, CMMC L2, and ISO 27001. Validate control effectiveness and coordinate actionable mitigation strategies for auditors and customers. Requires 10+ years of experience, U.S. citizenship, and trusted role clearance.

Required Qualifications

  • 10+ years of hands-on experience evaluating secure architecture and implementing security controls in cloud environments
  • Experience evaluating system architecture, network diagrams, data flows, identity integrations, and technical design documentation
  • Experience performing threat modeling, technical risk assessments, security design reviews, and control gap assessments
  • Experience integrating security into the SDLC, including CI/CD pipelines, Agile delivery, and DevSecOps practices
  • Experience collaborating with engineering, infrastructure, DevOps, cloud, IAM, and operations teams to drive remediation to closure
  • Strong understanding of network security concepts, including segmentation, firewalls, proxies, DNS, TLS, VPN/IPSec, routing, ingress/egress control, and secure network design
  • Experience with identity and access technologies such as Active Directory, Entra ID/Azure AD, SAML, OIDC, MFA, privileged access, role-based access control, and identity federation
  • Demonstrated experience authoring technical control narratives, technical audit documentation, and supporting evidence
  • Experience supporting audits and assessments such as SOC 2, ISO 27001, etc.
  • Strong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership, and business stakeholders
  • Significant experience using Jira and Confluence
  • U.S. Citizens only
  • Ability to gain and maintain Trusted Role

Desired Qualifications

  • CMMC CCA or CCP certification
  • FedRAMP audit lead or hands-on control implementation experience
  • CISSP and other similar technical certifications
  • Experience implementing Governance, Risk, and Compliance (GRC) tools
  • Experience with managing, securing, and auditing Public Key Infrastructure (PKI), including the certificate lifecycle management
  • End-point Protections (HIPS/HIDS)
  • Demonstrated experience designing multi-tier, highly available, multi-threaded, scalable architectures
  • Experience with web application programming, Java, APIs, or application-adjacent security engineering
  • Secure development frameworks (e.g. OWASP SAMM, Microsoft Security Development Lifecycle, IBM Secure Engineering Framework, etc.)
  • Business Continuity and Disaster Recovery planning
  • Data Loss Prevention (DLP)
  • Data Labeling and Information Rights Management
  • Bachelor's degree from an accredited university in IT related discipline

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce