{"id":1927833,"url":"https://alion.io/job/exostar-information-security-engineer","title":"Information Security Engineer","company":{"id":1806763,"name":"Exostar","domain":"exostar.com","url":"https://alion.io/company/exostar","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"UltiPro","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"explicit","locations":["Herndon, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":117000,"max_usd":232000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":974},"experience_years_min":6,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Active Directory","optional":false},{"name":"Agile","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"Confluence","optional":false},{"name":"DNS","optional":false},{"name":"FedRAMP","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Jira","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"PKI","optional":false},{"name":"SOC 2","optional":false},{"name":"Threat Modeling","optional":false},{"name":"VPN","optional":false},{"name":"DLP","optional":true},{"name":"Java","optional":true},{"name":"OWASP","optional":true},{"name":"OWASP SAMM","optional":true}],"status":"live","first_seen_at":"2026-09-15T14:08:28Z","employer_posted_date":"2026-09-15","last_verified_at":"2026-10-07T01:52:44Z","board_verified":true,"closed_at":null,"days_open":21,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":21},"description":"Position Overview:\nThis position will serve as a member of the Exostar Information Security Office and will report to the Manager of Governance & Engineering. This role is responsible for designing and implementing technical security controls across application, cloud, identity, and PKI environments. The successful candidate will work directly with DevOps, application, and operations teams to engineer controls and satisfy security framework requirements. This role is ideal for a security engineer who can assess architecture, identify control gaps, implement remediation, and technically validate implementation effectiveness.\nThis role is ideal for candidates that have a skillset focused on engineering credibility, architectural judgment, and the ability to operate confidently with technical teams, auditors, customers, and leadership.\nResponsibilities: Your day if you join us:\nSecurity Architecture & Control Implementation\nAssess, design, and provide guidance on secure architecture for cloud environments, including IAM, PKI, access, network, and platform services.\nEngage directly with infrastructure, platform, and development teams to translate security requirements into implementable technical designs and controls.\nReview proposed system changes, architecture diagrams, network flows, identity integrations, and control implementations for security implications.\nDevelop technical control implementation guidance, including diagrams, control narratives, configuration expectations, and test procedures.\nProvide hands-on engineering support for control effectiveness through configuration review, evidence inspection, technical testing, log review, and remediation verification.\nPerform threat modeling and security risk assessments and coordinate actionable mitigation strategies.\nCompliance Engineering & Governance\nProvide engineering support for controls aligned to frameworks such as PKI, identity certification, CMMC L2, FedRAMP Moderate, ISO/IEC 27001, IAM, SOC 2, etc.\nProduce technical control descriptions that reflect security architecture, implementation, and operational behavior to create defensible control narratives to auditors and customers.\nProduce SSPs, POA&Ms, control narratives, and audit responses where engineering interpretation is required.\nSupport audits and customer assessments by explaining technical controls, gathering defensible evidence, and validating that evidence against control intent.\nImprove the repeatability and quality of evidence collection, control validation, and remediation tracking.\nQualifications:\nYou are a great fit for this role if you:\n6+ years of hands-on experience evaluating secure architecture and implementing security controls in cloud environments.\nExperience evaluating system architecture, network diagrams, data flows, identity integrations, and technical design documentation.\nExperience performing threat modeling, technical risk assessments, security design reviews, and control gap assessments.\nExperience integrating security into the SDLC, including CI/CD pipelines, Agile delivery, and DevSecOps practices.\nExperience collaborating with engineering, infrastructure, DevOps, cloud, IAM, and operations teams to drive remediation to closure.\nStrong understanding of network security concepts, including segmentation, firewalls, proxies, DNS, TLS, VPN/IPSec, routing, ingress/egress control, and secure network design.\nExperience with identity and access technologies such as Active Directory, Entra ID/Azure AD, SAML, OIDC, MFA, privileged access, role-based access control, and identity federation.\nDemonstrated experience authoring technical control narratives, technical audit documentation, and supporting evidence.\nExperience supporting audits and assessments such as SOC 2, ISO 27001, etc.\nStrong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership, and business stakeholders.\nSignificant experience using Jira and Confluence.\nU.S. Citizens only- Due to customer requirements, U.S. Citizenship is required. Ability to gain and maintain Trusted Role is required.\n Hybrid: Herndon, VA (3x/week)\nPreferred Qualifications:\nYou are exactly who we are looking for if you\nCMMC CCA or CCP certification.\nFedRAMP audit lead or hands-on control implementation experience\nCISSP and other similar technical certifications\nExperience implementing Governance, Risk, and Compliance (GRC) tools\nExperience with managing, securing, and auditing Public Key Infrastructure (PKI), including the certificate lifecycle management.\nEnd-point Protections (HIPS/HIDS)\nDemonstrated experience designing multi-tier, highly available, multi-threaded, scalable architectures.\nExperience with web application programming, Java, APIs, or application-adjacent security engineering.\nSecure development frameworks (e.g. OWASP SAMM, Microsoft Security Development Lifecycle, IBM Secure Engineering Framework, etc.)\nBusiness Continuity and Disaster Recovery planning\nData Loss Prevention (DLP)\nData Labeling and Information Rights Management\nEducation:\nBachelor’s degree from an accredited university in IT related discipline\n\nExostar - The Company:\nExostar’s cloud-based platforms create exclusive communities within the Aerospace and Defense, Life Sciences, and other highly regulated industries where members securely collaborate, share information, and operate compliantly. Within these communities we build trust. By analyzing community data, we provide insights and intelligence, enabling organizations to make better, timelier decisions, to mitigate risk, and operate more efficiently.\n\nWe believe in employee development: we promote internally and provide training and educational assistance \nWe provide a fun, engaged workplace, with social and community-building events \nWe offer comprehensive benefits and flexible time off plans\nExostar is an Equal Opportunity Employment Employer. The company provides equal employment opportunities to all applicants without regard to race, color, religion, sex, national origin, age, marital status, disability status or genetic information. Exostar is committed to providing equal employment opportunities for all persons in all facets of employment including recruiting, hiring, compensation, promotion, training, benefits, transfers and working conditions.\nThe pay range for this position is $120,000k - $150,000k/yr; however, the final compensation will be determined based on factors including experience, skills, qualifications, and location. Exostar also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance, EAP, Flexible Spending Accounts, 401(k) matching, flexible time off and sick leave).","description_format":"text","description_chars":6739,"description_truncated":false,"requirements":{"experience_years_min":6,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Flexible time off","Health insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Biotechnology","Cybersecurity","Team Communication & Collaboration"],"lifecycle":[{"event":"open","at":"2026-10-05T20:49:03Z"}],"visa":[],"liveness":{"score":71,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.79,"p_room":0.9,"age_days":20,"expected_fill_days":39,"reasons":["conf:1","win:mid"],"computed_at":"2026-10-06T05:45:30Z"},"pay":null,"html_url":"https://alion.io/job/exostar-information-security-engineer","json_url":"https://alion.io/job/exostar-information-security-engineer.json","meta":{"generated_at":"2026-10-07T01:54:40Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3081,"day_limit":5000,"remaining_today":1919,"minute_limit":60,"resets_at":"2026-10-08T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":1806763},"rest":"https://alion.io/mcp/rest/get_company?id=1806763"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fexostar-information-security-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fexostar-information-security-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fexostar-information-security-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/exostar-information-security-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fexostar-information-security-engineer"}]}