1

Senior Information Security Engineer Jobs in Virginia

Sr Information Security Engineer

Herndon, VA · On-site

$109K - $148K/yr

This position will serve as a member of the Exostar Information Security Office and will report to the Manager of Governance & Engineering. This role is responsible for designing and implementing ...

The Senior IT Security Engineer works closely with the IT Security Administrator, IT Operations, and IT Systems Engineering teams, and reports to the Director of IT. Key ResponsibilitiesSecurity ...

New

Senior IT Security Engineer

Chesapeake, VA · On-site

$92K - $126K/yr

The Senior IT Security Engineer works closely with the IT Security Administrator, IT Operations, and IT Systems Engineering teams, and reports to the Director of IT. Key Responsibilities Security ...

Senior IT Security Engineer

Chesapeake, VA · On-site

$92K - $126K/yr

The Senior IT Security Engineer works closely with the IT Security Administrator, IT Operations, and IT Systems Engineering teams, and reports to the Director of IT. Key Responsibilities Security ...

Position overview The Information Security Engineer is responsible for supporting and advancing the organization's information security program through security operations, incident response ...

Position overview The Information Security Engineer is responsible for supporting and advancing the organization's information security program through security operations, incident response ...

next page

Showing results 1-20

Senior Information Security Engineer information

See Virginia salary details

$22.3K

$125.7K

$185.9K

How much do senior information security engineer jobs pay per year?

As of Aug 21, 2026, the average yearly pay for senior information security engineer in Virginia is $125,724.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,600.00 and $143,300.00 per year, depending on experience, location, and employer.

What does a senior information security engineer do?

A Senior Information Security Engineer is responsible for designing, implementing, and maintaining an organization's security infrastructure. They assess risks, develop security policies, and ensure compliance with regulations. Additionally, they monitor networks for vulnerabilities, respond to security incidents, and provide guidance to junior staff. Their expertise helps protect sensitive data and maintain the integrity of IT systems.

What are the key skills and qualifications needed to thrive as a senior information security engineer?

To thrive as a Senior Information Security Engineer, you need deep expertise in cybersecurity principles, risk assessment, and network security, often supported by a relevant degree and certifications like CISSP or CISM. Familiarity with security information and event management (SIEM) systems, firewalls, vulnerability scanning tools, and scripting languages is typically required. Strong analytical thinking, problem-solving, and effective communication skills help you proactively identify threats and collaborate with IT teams. These skills and qualities are critical to protect organizational assets, ensure regulatory compliance, and respond effectively to evolving cyber threats.

How does a senior information security engineer typically collaborate with other departments to enhance organizational security?

Senior Information Security Engineers often work closely with teams across IT, development, and business units to identify potential security risks and implement effective controls. They participate in cross-functional meetings, review architectural changes, and provide guidance on secure coding practices. This collaboration ensures that security is embedded early in project lifecycles and that all staff are aware of best practices. Building strong relationships with other departments is essential for developing comprehensive security policies and responding effectively to incidents.

What is the difference between Senior Information Security Engineer vs Security Analyst?

AspectSenior Information Security EngineerSecurity Analyst
CertificationsCISSP, CISA, CEHCISSP, Security+
Work EnvironmentDesigning security systems, implementing security measures, managing security projectsMonitoring security alerts, analyzing threats, conducting security assessments
Employer & Industry UsageTech companies, finance, healthcare, governmentIT departments, cybersecurity firms, corporate security teams

The main difference is that Senior Information Security Engineers focus on designing and implementing security solutions, while Security Analysts primarily monitor and analyze security threats. Both roles require relevant certifications and are vital in maintaining organizational security, but they differ in responsibilities and daily tasks.

What are popular job titles related to Senior Information Security Engineer jobs in Virginia?

For Senior Information Security Engineer jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Senior Information Security Engineer jobs in Virginia look for?

The top searched job categories for Senior Information Security Engineer jobs in Virginia are:

What cities in Virginia are hiring for Senior Information Security Engineer jobs?

Cities in Virginia with the most Senior Information Security Engineer job openings:

Infographic showing various Senior Information Security Engineer job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 69% Full Time, 28% Part Time, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $125,724 per year, or $60.4 per hour.

Sr Information Security Engineer

Exostar

Herndon, VA • On-site

$109K - $148K/yr

Full-time

Medical, Dental, Vision, Life, Retirement

Re-posted 13 days ago


Job description

Position Overview:
This position will serve as a member of the Exostar Information Security Office and will report to the Manager of Governance & Engineering. This role is responsible for designing and implementing technical security controls across application, cloud, identity, and PKI environments. The successful candidate will work directly with DevOps, application, and operations teams to engineer controls and satisfy security framework requirements. This role is ideal for a security engineer who can assess architecture, identify control gaps, implement remediation, and technically validate implementation effectiveness.
This role is ideal for candidates that have a skillset focused on engineering credibility, architectural judgment, and the ability to operate confidently with technical teams, auditors, customers, and leadership.
Responsibilities: Your day if you join us:
Security Architecture & Control Implementation
  • Assess, design, and provide guidance on secure architecture for cloud environments, including IAM, PKI, access, network, and platform services.
  • Engage directly with infrastructure, platform, and development teams to translate security requirements into implementable technical designs and controls.
  • Review proposed system changes, architecture diagrams, network flows, identity integrations, and control implementations for security implications.
  • Develop technical control implementation guidance, including diagrams, control narratives, configuration expectations, and test procedures.
  • Provide hands-on engineering support for control effectiveness through configuration review, evidence inspection, technical testing, log review, and remediation verification.
  • Perform threat modeling and security risk assessments and coordinate actionable mitigation strategies.

Compliance Engineering & Governance
  • Provide engineering support for controls aligned to frameworks such as PKI, identity certification, CMMC L2, FedRAMP Moderate, ISO/IEC 27001, IAM, SOC 2, etc.
  • Produce technical control descriptions that reflect security architecture, implementation, and operational behavior to create defensible control narratives to auditors and customers.
  • Produce SSPs, POA&Ms, control narratives, and audit responses where engineering interpretation is required.
  • Support audits and customer assessments by explaining technical controls, gathering defensible evidence, and validating that evidence against control intent.
  • Improve the repeatability and quality of evidence collection, control validation, and remediation tracking.

Qualifications:
You are a great fit for this role if you:
Required Skills:
  • 10+ years of hands-on experience evaluating secure architecture and implementing security controls in cloud environments.
  • Experience evaluating system architecture, network diagrams, data flows, identity integrations, and technical design documentation.
  • Experience performing threat modeling, technical risk assessments, security design reviews, and control gap assessments.
  • Experience integrating security into the SDLC, including CI/CD pipelines, Agile delivery, and DevSecOps practices.
  • Experience collaborating with engineering, infrastructure, DevOps, cloud, IAM, and operations teams to drive remediation to closure.
  • Strong understanding of network security concepts, including segmentation, firewalls, proxies, DNS, TLS, VPN/IPSec, routing, ingress/egress control, and secure network design.
  • Experience with identity and access technologies such as Active Directory, Entra ID/Azure AD, SAML, OIDC, MFA, privileged access, role-based access control, and identity federation.
  • Demonstrated experience authoring technical control narratives, technical audit documentation, and supporting evidence.
  • Experience supporting audits and assessments such as SOC 2, ISO 27001, etc.
  • Strong written and verbal communication skills with the ability to explain technical concepts to auditors, leadership, and business stakeholders.
  • Significant experience using Jira and Confluence.
  • U.S. Citizens only- Due to customer requirements, U.S. Citizenship is required. Ability to gain and maintain Trusted Role is required.

Hybrid: Herndon, VA (3x/week)
Preferred Qualifications:
You are exactly who we are looking for if you
  • CMMC CCA or CCP certification.
  • FedRAMP audit lead or hands-on control implementation experience
  • CISSP and other similar technical certifications
  • Experience implementing Governance, Risk, and Compliance (GRC) tools
  • Experience with managing, securing, and auditing Public Key Infrastructure (PKI), including the certificate lifecycle management.
  • End-point Protections (HIPS/HIDS)
  • Demonstrated experience designing multi-tier, highly available, multi-threaded, scalable architectures.
  • Experience with web application programming, Java, APIs, or application-adjacent security engineering.
  • Secure development frameworks (e.g. OWASP SAMM, Microsoft Security Development Lifecycle, IBM Secure Engineering Framework, etc.)
  • Business Continuity and Disaster Recovery planning
  • Data Loss Prevention (DLP)
  • Data Labeling and Information Rights Management

Education:
  • Bachelor's degree from an accredited university in IT related discipline

Exostar - The Company:
Exostar's cloud-based platforms create exclusive communities within the Aerospace and Defense, Life Sciences, and other highly regulated industries where members securely collaborate, share information, and operate compliantly. Within these communities we build trust. By analyzing community data, we provide insights and intelligence, enabling organizations to make better, timelier decisions, to mitigate risk, and operate more efficiently.
We believe in employee development: we promote internally and provide training and educational assistance
We provide a fun, engaged workplace, with social and community-building events
We offer comprehensive benefits and flexible time off plans
Exostar is an Equal Opportunity Employment Employer. The company provides equal employment opportunities to all applicants without regard to race, color, religion, sex, national origin, age, marital status, disability status or genetic information. Exostar is committed to providing equal employment opportunities for all persons in all facets of employment including recruiting, hiring, compensation, promotion, training, benefits, transfers and working conditions.
The pay range for this position is $130,000k - $170,000k/yr; however, the final compensation will be determined based on factors including experience, skills, qualifications, and location. Exostar also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance, EAP, Flexible Spending Accounts, 401(k) matching, flexible time off and sick leave).
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.