1,336,187open jobs
78,338companies
214,727added this week
Browse all
Salary
$145k – $175k per year
Location
In office (Arlington)
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 7, 2026. First seen by Alion on Oct 5, 2026. Umbra scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Umbra operates synthetic aperture radar satellites offering very high resolution imagery. Customers task collections through an open API and receive data quickly. The company also releases open imagery datasets for research.

Umbra is an American space technology company delivering advanced systems, from sensors to spacecraft, that empower customers worldwide with unmatched access to critical information from space. Our mission is simple and ambitious: redefine space-for people, systems, and missions in every domain. Umbra’s ecosystem operates through three business units: Remote Sensing (the data), Space Systems (the components), and Mission Solutions (the platforms). Together, our teams develop capabilities that deliver persistent access, resilient performance, and mission-ready solutions, advancing U.S. space leadership while keeping the world safe and informed.

About the Team

Umbra’s Information Technology organization operates as a shared service and strategic capability, embedding security, automation, and operational rigor directly into the platforms the business depends on. Security is not an overlay, it is designed, implemented, and evidenced through IT platforms.

About the Role

The Security Operations Engineer is a hands-on technical role responsible for designing, implementing, operating, and continuously improving security controls across Umbra’s corporate technology platforms. This position serves as the primary conduit between Information Security (InfoSec) and IT execution, ensuring security policy is translated into durable, auditable technical controls.

Sitting within Core Infrastructure, this role owns the security configuration control plane for corporate IT: identity, access, email security, data protection, network security, endpoint posture, vulnerability management, logging, and detection. The role partners closely with InfoSec on risk management, program deployment, POA&M execution, and audit readiness.

This is an engineering-first role focused on building and integrating secure-by-default platforms, not a SOC-only or alert-triage position.

This position is based on-site in either our Arlington, VA office or Reston, VA office.

Key Responsibilities

  • Security Engineering: Design, implement, and operate technical security controls across identity, endpoint, network, cloud, email, and SaaS environments, translating InfoSec policies and standards into enforceable configurations and platform guardrails.
  • Vulnerability Management: Own the technical vulnerability management lifecycle across corporate IT platforms, including scanning and coverage, risk-based prioritization, remediation coordination, validation, exception tracking, and reporting.
    • Administer vulnerability scanning tools and partner with infrastructure and application owners to drive remediation of vulnerabilities, configuration issues, and critical or actively exploited exposures.
  • Email Security: Design and maintain email security controls, including SPF, DKIM, DMARC, secure mail routing, monitoring, and protection against phishing, spoofing, and domain abuse.
  • Data Loss Prevention: Design, implement, and tune DLP controls across email, endpoints, cloud storage, messaging, and SaaS platforms, including controls supporting CUI and other regulated data.
  • Identity & Access: Secure and operate IAM capabilities including SSO, MFA, SCIM/JIT, PAM, least-privilege access, and access-review remediation.
  • Endpoint Security: Partner with IT teams to implement and maintain security baselines across Windows and macOS environments, including encryption, patching, device trust, and endpoint security tooling.
  • Network & Cloud Security: Implement and maintain security controls across network and cloud environments, including segmentation, firewalls, ZTNA/VPN, logging, and cloud security guardrails.
  • Detection & Incident Response: Operate and tune security monitoring and detection capabilities, integrating signals across identity, endpoint, email, and DLP platforms and supporting investigation and remediation of security incidents.
  • Compliance & Audit Readiness: Maintain technical documentation, configuration artifacts, and evidence supporting NIST, CMMC, FedRAMP, and other applicable security and compliance requirements.
  • Automation & Continuous Improvement: Automate security controls, vulnerability management, evidence collection, and compliance workflows to improve reliability and reduce manual effort.
  • Cross-Functional Collaboration: Partner closely with InfoSec, Core Infrastructure, Digital Workplace, Enterprise Applications, Legal, and other stakeholders to implement security requirements and remediate technical risks.
  • Participate in security-related change reviews, CABs, and other governance forums as needed.
  • Perform other duties as assigned.

Requirements

Required Qualifications

  • 5+ years of experience in security engineering, security operations, or infrastructure security roles.
  • Hands-on experience managing the vulnerability lifecycle, including authenticated scanning, finding validation, risk-based prioritization, remediation coordination, and verification of closure.
  • Strong hands-on experience designing and deploying:
    • Email authentication: SPF, DKIM, and DMARC
    • Enterprise DLP controls
  • Strong hands-on experience implementing security controls across:
    • Identity & Access Management
    • Endpoint management (Windows/macOS)
    • Network and cloud platforms
  • Demonstrated ability to translate security policy into enforceable technical implementation.
  • Experience coordinating patches, upgrades, and configuration changes across technical teams while balancing security risk, operational availability, and change-management requirements.
  • Experience supporting & automating audit and compliance evidence collection.
  • Strong troubleshooting and incident response skills.

Desired Qualifications

  • 10+ years of experience in security engineering, security operations, or infrastructure security roles.
  • Experience with vulnerability assessment platforms, such as Tenable/Nessus, and patch management tooling, such as BigFix.
  • Experience with Okta: IdP, SSO, MFA, SCIM, and workflows.
  • Strong hands on experience designing and deploying eDiscovery and retention workflows.
  • Experience with FortiGate & Cisco network technologies.
  • Strong understanding of TCP/IP, DNS, HTTP/S, VPNs, SD-WAN, and routing/switching.
  • Experience deploying DLP in regulated environments.
  • Familiarity with NIST, CMMC, and FedRAMP.
  • Experience automating security controls, vulnerability remediation workflows, or evidence collection.
  • Exposure to cloud security tooling and observability platforms.
  • Proficiency in Python, Bash, or PowerShell.

Benefits

  • Flexible Time Off, Sick, Family & Medical Leave
  • Medical, Dental, Vision, Life, LTD, STD (employer funded)
  • Vol Life, Critical Illness, Accidental, Hospital Indemnity, Pet Insurance (employee funded)
  • 401k with 3% non-elective company contribution
  • Stock Options
  • Free Parking
  • Free lunch daily in office

Umbra is an Equal Opportunity Employer. We do not discriminate in hiring on the basis of sex, gender identity, sexual orientation, race, color, religious creed, national origin, physical or mental disability, protected veteran status, or any other characteristic protected by federal, state, or local law.

Employment Eligibility Verification

In compliance with federal laws, all hired persons will be required to verify their identity and eligibility to work in the United States by completing the required Employment Eligibility Verification Form (I-9 Form) upon hire.

ITAR/EAR Requirements

This position may include access to technology and/or data that is subject to U.S. export controls pursuant to ITAR and EAR. To comply with federal export controls, all persons hired must be a U.S. citizen, U.S. national, U.S. lawful permanent resident, refugee or asylee as defined by 8 U.S.C. § 1324b(a)(3), or must otherwise be eligible to obtain the required authorizations from the U.S. Department of State and/or U.S. Department of Commerce as applicable.

Pay Transparency

This job posting may cover multiple career levels. To ensure greater transparency, we provide base salary ranges for all roles, regardless of location. Our standard pay ranges are based on the role’s function and level, benchmarked against similar growth-stage companies. Compensation may vary based on geographical location, as certain regions may have different cost-of-living factors. The final offer will also be influenced by the candidate's skills, responsibilities, and relevant experience.

Compensation Range

The Compensation Range for this role is $145,000 - $175,000 DOE.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,336,187 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Arlington
$135k – $216k per year • In office • TS/SCI • Washington
Apply
$80k – $118k per year • Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Scottsdale
DevOps
Linux
Windows
Unix
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
Apply
$150k – $240k per year • In office • 5+ years exp • San Francisco
Python
Java
TypeScript
DevOps
Wi-Fi
Cybersecurity
ISO 27001
Ghidra
OWASP Top 10
PCI DSS
SOC 2
STRIDE
Threat Modeling
Chips/EDA
OpenOCD
Apply
$60k – $139k per year • In office • Full-Time • 2+ years exp • United States
Python
PowerShell
AI/ML
Claude
AI Agents
Anthropic
DevOps
SLI/SLO/SLA
Cybersecurity
SIEM
Apply
$128k – $139k per year • Hybrid • Full-Time • 3+ years exp • New York
Python
PowerShell
DevOps
Azure
CI/CD
Git
AWS
Incident Management
IAM
Cybersecurity
Okta
CyberArk
Zero Trust
Microsoft Entra ID
Active Directory
Management
ITIL
Apply
≈ $33k – $62k per year (Estimated) • In office • Full-Time • Knutsford
Python
PowerShell
Apply
≈ $55k – $132k per year (Estimated) • Remote (United Kingdom, Greece) • Athens
Python
SQL
Python
pySpark
Databases
Databricks
Delta Lake
MS SQL
Microsoft Fabric
AI/ML
Spark
Machine Learning
DevOps
Azure DevOps
Azure
CI/CD
Git
FinOps
Analytics
Power BI
ETL/ELT
Azure Data Factory
Dimensional Modeling
Master Data Management
Management
Agile
Apply
≈ $87k – $231k per year (Estimated) • In office • Full-Time • Bachelor's Degree • United Kingdom
Python
Java
DevOps
CI/CD
Apply
≈ $17k – $33k per year (Estimated) • In office • Full-Time • Gurgaon
Python
SQL
SAS
AI/ML
AI Agents
Machine Learning
Apply
≈ $19k – $38k per year (Estimated) • Equity • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Hyderabad
Python
Databases
PostgreSQL
MS SQL
Amazon Redshift
AI/ML
Pandas
NumPy
DevOps
Terraform
AWS
AWS Fargate
AWS Lambda
Amazon EC2
GitHub
Amazon S3
Amazon Kinesis
Linux
Unix
Analytics
AWS Glue
Management
Confluence
Jira
Agile
Scrum
Apply
$160k – $200k per year • Equity • In office • TS/SCI • Full-Time • Arlington
Cybersecurity
SIEM
DLP
Management
Agile
Apply
$125k – $150k per year • Equity • In office • Full-Time • Bachelor's Degree • Santa Barbara
Python
C++
MATLAB
Management
Agile
Apply
$135k – $165k per year • Equity • In office • Full-Time • Bachelor's Degree • Santa Barbara
Design
SolidWorks
Apply
$76k – $90k per year • Equity • In office • Full-Time • Santa Barbara
Management
Microsoft Office
Apply
$185k – $225k per year • Equity • In office • TS/SCI • Full-Time • Bachelor's Degree • Reston
Python
Rust
C++
DevOps
RTOS
Linux
TCP/IP
Apply
$99k – $206k per year • In office • TS/SCI • Full-Time • 5+ years exp • Bachelor's Degree • Arlington
Databases
PostgreSQL
DevOps
GCP
Red Hat
AWS
Linux
Apply
$110k – $120k per year • In office • TS/SCI • 2+ years exp • Bachelor's Degree • Arlington
Cybersecurity
SIEM
Apply
$117k – $243k per year • In office • 7+ years exp • Arlington
DevOps
Linux
Windows
Cybersecurity
SIEM
DLP
Apply
$117k – $243k per year • In office • 5+ years exp • Arlington
DevOps
Incident Management
Linux
Windows
Apply
$86k – $138k per year • In office • TS/SCI • 5+ years exp • Bachelor's Degree • Arlington
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
SIEM
Management
Agile
Apply
See all jobs
This is one of many
1,336,187 more open roles from verified company boards, updated every day.