JOBSEARCHER

Information Security Engineer

ExostarMcLean, VAL6 LeadSeptember 15th, 2026
Overview In this role, you design and implement technical security controls across cloud, application, identity, and PKI environments to protect Exostar’s platforms. You’ll work with DevOps, engineering, and ops teams to translate security requirements into practical designs and verify control effectiveness. You’ll assess architectures, identify gaps, and drive remediation while engaging with auditors and leadership. This position offers meaningful impact in securing regulated communities and shaping secure engineering practices. Compensation / Benefitstraining and educational assistanceengaging workplace with eventscomprehensive benefitsflexible time off plans ResponsibilitiesAssess secure cloud architectures (IAM, PKI, access, networking) and translate requirements into technical designs and controlsCollaborate with infrastructure, platform, and development teams to ensure security in system changes and architecturesCreate technical control guidance, diagrams, narratives, configurations, and test proceduresProvide hands-on engineering support for control effectiveness, including configuration reviews and evidence validationPerform threat modeling, risk assessments, and coordinate mitigation strategiesDevelop control narratives and evidence for audits and customer assessmentsSupport audits by explaining controls, gathering defensible evidence, and validating evidence against control intentImprove evidence collection, control validation, and remediation tracking Key requirements5+ years hands-on experience evaluating secure cloud architectures and implementing security controlsExperience evaluating architecture diagrams, data flows, and identity integrationsThreat modeling, technical risk assessments, and control gap assessmentsExperience integrating security into SDLC, CI/CD, Agile, and DevSecOpsCollaborating with engineering, DevOps, cloud, IAM, and operations teams to drive remediationStrong knowledge of network security concepts and secure network designExperience with identity tech (AD, Entra ID/Azure AD, SAML, OIDC, MFA, RBAC) and identity federationExperience authoring technical control narratives, audit documentation, and defensible evidenceExperience supporting audits such as SOC 2, ISO 27001Strong written and verbal communication; able to explain technical concepts to non-technical audiencesExperience with Jira and ConfluenceAble to pass background check for Trusted Role accessExcellent written and verbal communicationCollaborative and stakeholder-engagedAuditor-facing and customer-focusedSecurity architecture design in cloud environmentsPKI and certificate lifecycle managementIdentity and access management (SAML, OIDC, MFA)