Expoint – all jobs in one place
Finding the best job has never been easier

Security Engineer jobs in United States, Virginia, Arlington

Unlock your potential in the high tech industry with Expoint. Search for job opportunities as a Security Engineer in United States, Virginia, Arlington and join the network of leading companies. Start your journey today and find your dream job as a Security Engineer with Expoint.
Company
Job type
Job categories
Job title (1)
United States
Virginia
Arlington
735 jobs found
09.12.2025
EY

EY Chief Information Security Officer CISO - US Government & Pu... United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
Description:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Must have government sector experience
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
09.12.2025
EY

EY GPS - Azure Cloud Platform Engineer Supervising Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Designing cloud platform architectures and infrastructure as code for secure Azure / Azure Gov environments. Building DevSecOps automation and CI/CD pipelines. Enabling containerized workloads and hardened base images at scale....
Description:

Our GPS Technology Organization is a structure within the US GPS practice that implements and maintains a new operate and technology model designed specifically to support U.S. defense and Government engagements.

This role focuses on:

  • Designing cloud platform architectures and infrastructure as code for secure Azure / Azure Gov environments
  • Building DevSecOps automation and CI/CD pipelines
  • Enabling containerized workloads and hardened base images at scale
  • Helping teams adopt modern cloud practices without accumulating technical debt

You’ll collaborate with architects, security teams, and product managers, and coach junior engineers in a highly regulated mission environment. You’ll thrive in this role if you’re a self-starter who’s comfortable with ambiguity, likes to automate wherever it makes sense, and is committed to continuous learning and helping others grow.

Cloud Platform & Infrastructure as Code (IaC)

  • Design and maintain reusable IaC (Bicep, ARM templates) for scalable, secure Azure / Azure Gov environments
  • Implement and improve Azure Policies and initiatives to enforce standards and guardrails
  • Apply modern engineering and security standards across platform components

Containers & DevSecOps

  • Engineer, automate, and deploy platform solutions and applications using platforms such as Kubernetes, Azure Kubernetes Service (AKS), Azure Container Apps, with supporting technologies like Docker or Helm
  • Develop and maintain base container images and hardened OS images aligned to DISA STIGs and other security baselines
  • Evolve and promote DevSecOps practices across teams

Automation & CI/CD

  • Build and operate CI/CD pipelines using Azure DevOps, Git, and automation tooling (e.g., Ansible)
  • Automate repeatable infrastructure and application deployment tasks
  • Use both manual and automated quality controls to ensure reliable releases

Operations, risk & collaboration

  • Troubleshoot and remediate issues in cloud and container platforms
  • Identify and communicate risks, assumptions, issues, and decisions throughout the product lifecycle
  • Document and improve processes, and collaborate closely with product managers, architects, and security teams
  • Mentor junior engineers and help build a high-performing DevSecOps culture

What you bring (required)

  • Bachelor’s degree in Computer Science, IT, or equivalent experience
  • Microsoft Certified: Azure Administrator Associate (AZ-104)
  • 5+ years in engineering roles working with private/public cloud IaaS, PaaS, and/or SaaS
  • Eligibility to obtain and maintain a Top Secret security clearance
  • Strong hands-on experience with (in order of importance):
    • Infrastructure as Code & CI/CD– designing and delivering with tools such as Bicep, Azure DevOps, ARM templates, or Ansible
    • Containers and orchestration– experience building and running containerized workloads using technologies such as Docker, Kubernetes, Azure Kubernetes Service (AKS), Azure Container Apps, or Helm for packaging and deploying services at scale
    • Networking fundamentals– strong foundation designing and troubleshooting VNets, subnets, network security groups (NSGs), routing (UDRs), and basic load-balancing scenarios, with enough depth to reason about hub-and-spoke or similar topologies and diagnose common connectivity issues
    • Cloud security principles– solid understanding of concepts such as shared responsibility, least privilege, identity-driven security, network segmentation, encryption, and logging/monitoring, and how to apply them for customers driven by regulatory compliance requirements, such as: NIST, Fedramp
    • Identity and access– understanding of Microsoft Entra ID, Azure RBAC, Entra ID RBAC, Privileged Identity Management (PIM), and managed identities for Azure resources
    • Windows and Linux administration– hands-on experience managing, troubleshooting, and hardening server workloads, including patching, performance tuning, and applying security baselines (e.g., DISA STIG or equivalent)
    • Scripting / programming– practical automation experience using PowerShell (Python or similar scripting languages is a plus but not required)
  • Additional expectations:
    • Experience with government security frameworks (e.g., NIST controls)
    • Hands-on delivery in Agile environments (Scrum, Kanban, SAFe, or similar)
    • Strong written and verbal communication and the ability to work effectively on distributed teams

What will make you stand out (preferred)

  • Deeper hands-on experience with:
    • Git-based source controland branching strategies
    • Azure DevOps Pipelinesand broader Azure platform services
    • Ansible and Bicepfor advanced automation and configuration
    • Azure Policyand multi-tenant / multi-subscription design patterns
    • Advanced Azure networking experience– hands-on exposure to one or more of: VPN Gateway or ExpressRoute, Azure Firewall or other NVAs, Virtual WAN hubs, Application Gateway or similar L7 gateways, and more complex hybrid or multi-region network designs
  • Additional relevant certifications, such as:
    • AZ-400, AZ-500, AZ-700
    • Certified Kubernetes Administrator (CKA)or CKAD / CKNS
    • Red Hat Certified Specialist in Ansible Automation


At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn .

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $89,600 to $167,600. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $107,600 to $190,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

08.12.2025
EY

EY GPS - Cyber Security Engineer Supervising Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Supporting the run state of our security technologies. Bringing operational expertise into efforts which introduce new technologies and upgrade current ones. Providing technical oversight of Information Security technologies that fall...
Description:

Our GPS Technology Organization is a structure within the US GPS practice that implements and maintains a new operate and technology model designed specifically to support U.S. defense and Government engagements.

As the Cyber Security Engineer, you’ll be part of our Security Engineering & Operations team. In this role you’ll be involved in leading and coordinating activities related to multi-functional security technologies for our US Government and Public Sector (GPS) Practice. You’ll also work with internal security teams including IAM and Cyber Defense to ensure the related systems are secure, robust and compliant. You’ll spend most of your time supporting the run state of our security technologies. The remainder of your time will be spent bringing operational expertise into efforts which introduce new technologies and upgrade current ones.

Your key responsibilities

  • Supporting the run state of our security technologies
  • Bringing operational expertise into efforts which introduce new technologies and upgrade current ones
  • Providing technical oversight of Information Security technologies that fall under the team’s responsibilities, confirming they are operating within agreed service levels, compliance specifications and at peak performance
  • Managing and coordinating planned maintenance activities as well as incidents for Information Security technologies
  • Representing the team in specific project activities, including leading projects and managing the activity of others towards successful completion
  • Articulating technology issues/concerns that may emerge at any level of the technical stack, and from any component across the ecosystem, to technology leaders
  • The role will likely be 100% remote and require <10% travel
  • Occasional weekend and off hours work to support the business. It will also require a rotational on-call schedule.

Skills and attributes for success

  • Operational experience in an environment of more than 3000 users
  • Perform detailed troubleshooting of issues, by using their analytical skills and collaborating with other technical teams, stakeholders and internal and external customers
  • Ability to work and solve issues independently, finding solutions to problems.
  • Strong ability to document processes, procedures and security controls clearly and accurately for distribution to internal teams and customers
  • Comfortable working remotely in a large, global virtual environment
  • Ability to react appropriately during stressful and ambiguous situations and communicate clearly to senior leadership when the situation requires
  • Strong problem solving, decision making and collaboration skills
  • Functional and/or technical experience in supporting security technologies including detailed knowledge of many of the following: Cloud Operations especially Azure, O365 Tenants, networking concepts & mechanisms, EDR, DLP, AV/AM, DNS, Encryption, E-Mail technologies including DMARC, DKIM, SMTP, TLS, EVM, SYSLOG, PKI, as well as a myriad of other related security and desktop technologies:
    • Azure networking and platform protection
    • Azure architectural design.
    • Diagnostic logging & log retention and complex logging solutions with varied vendors and environments.
    • Vulnerability and compliance scanning solutions and policies
    • Virtual networks and Network Security Groups
    • Application gateways and load balancing
    • Traffic Manager and Azure DDoS protection
    • Host Security and VM Hardening
    • Serverless Computing (Kubernetes)
    • Subscription security and policies
    • Azure resource policies and resource locks
    • Azure information protection
    • Access control and key management for storage accounts
  • Basic Scripting and Automation Skills
  • Experience with CI/CD pipelines deployment, DevSecOps and Policy as Code
  • Experience with Containers
  • Experience with WDAC

To qualify for the role, you must have

  • Bachelor’s degree in computer related field or equivalent work experience
  • At least 5 years of experience in managing Information Systems and Security, including demonstratable knowledge of the various platforms and interactions
  • Strong English language skills – written and verbal
  • Experience in training and coaching staff in technical processes and practices
  • Proven experience in configuration of the following Microsoft and Azure security services:
    • Microsoft Sentinel
    • Microsoft Defender XDR
      • Microsoft Defender for Endpoint
      • Microsoft Defender for O365
      • Microsoft Defender for Identity
      • Microsoft Defender for Cloud Apps
      • Microsoft Defender Vulnerability Management
      • Microsoft Defender for Cloud
      • Microsoft Entra ID Protection
      • Microsoft Data Loss Prevention (Purview)
      • App Governance
    • Microsoft O365 DLP
    • Microsoft Intune
    • Azure Monitor Log Analytics
    • Azure Firewall
    • Azure WAF
    • Azure EventHub
    • Azure Network Watcher
  • Eligible to obtain and maintain Top Secret Security Clearance

Ideally, you’ll also have

  • Experience with MS Exchange, O365,Azure, AWS, and GCP.
  • Advanced skills in troubleshooting cloud environments
  • General Knowledge of FedRAMP, NIST SP 800-53, and NIST SP 800-171 and other frameworks.
  • Federal Government experience, including CMMC Maturity Level 3
  • Strong ability to document processes, procedures and security controls clearly and accurately for distribution to internal teams and customers
  • GSEC/CISSP or other security related generalist certification from ISC2 or GIAC
  • Experience in incident, problem and change management
  • Certifications:
    • AZ-900: Azure Fundamentals
    • AZ-500: Azure Security Technologies
    • AZ-303: Azure Architect Technologies
    • SANS SEC401: Security Essentials - Network, Endpoint, and Cloud
    • SANS SEC 510, Public Cloud Security: AWS, Azure, and GCP
    • Sans SEC 540: Cloud Security and DevSecOps Automation

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $91,100 to $170,400. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $109,300 to $193,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

19.11.2025
EY

EY Azure Cloud Platform Engineer - GPS United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Have experience in the infrastructure sector, particularly in transport, power and utilities, health, and education projects. Experience in the UK, Australia, or Canada in the PPP/PFI and project financing sector...
Description:

By joining this team, you will support our clients from the earliest stages of project analysis and evaluation through procurement, financial close, construction, and operations.

You will assist clients in devising and comparing financial plans and delivery approaches for projects involving public, federal, or private financing, project revenues, and/or grants, while providing support for the implementation of those plans.

As part of our project finance team, you will enhance your commercial capabilities by working with our global networks and fast-moving, emerging clients.

Our diverse client portfolio will help you build skills in pitching, briefing, managing relationships, and challenging assumptions.

In our friendly and collaborative environment, you will receive the support, formal training, and coaching needed to progress quickly along your chosen career path.

Your key responsibilities

In Infrastructure Advisory you will:

  • Have experience in the infrastructure sector, particularly in transport, power and utilities, health, and education projects. Experience in the UK, Australia, or Canada in the PPP/PFI and project financing sector is advantageous, as is experience in Asia.
  • Develop and manage key client relationships and deal origination capabilities, from securing advisory mandates to achieving transaction closure, acting on government and private sector transactions in the infrastructure sector.
  • Possess knowledge of PPP/PFI, concessions, and acquisition and project financing structures/contracts related to the infrastructure sector.
  • Work on project delivery covering feasibility, design, procurement, construction, and handover.
  • Have project financing knowledge, with an understanding of project financial modeling and financing markets, which would be highly valued.
  • Understand economic or social infrastructure procurement and delivery.

To qualify for the role you must have

  • More than 8 years of experience in a top-tier advisory firm, infrastructure service provider, bank, relevant government agency or other relevant sector.
  • A university degree, preferably majoring in Economics, Finance, Accounting, Management, Law, or Engineering from reputable local or overseas universities. A Master's degree is ideal.
  • Professional qualifications such as CFA, FRM, ASIA, CPA, CA, or CMA are considered advantageous.
  • A high-performance professional who can articulate a value proposition, developing business cases/ models and lead and advise on projects in the infrastructure sector from bid stage to financial close
  • Advanced financial modelling skills, project finance modelling experience s an advantage.
  • Willingness and ability to travel when necessary.

What’s most important is that you’re dedicated to supporting your colleagues as part of a high-performing team. You’ll need to thrive in picking up new skills and talents as you go, so natural curiosity, a lot of questions and the confidence to speak up when you see something that could be improved are essential.

If you’ve got the right combination of technical knowledge and communication skills, this role is for you.

Show more

These jobs might be a good fit

18.11.2025
EY

EY GPS - Assistant Facility Security Officer Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Oversee daily security operations and NISP/32 CFR Part 117 NISPOM compliance. Maintain and mature the facility’s industrial security program for Department of Defense (DoD) elements in compliance with applicable policies,...
Description:

As Assistant Facility Security Officer (AFSO) you will be responsible for ensuring the protection of National Security Information in accordance with the National Industrial Security Program Operating Manual (NISPOM)/32 CFR Part 117. Responsibilities include program oversight, evaluations, and educating cleared employees on promulgated government and company initiatives, policies and procedures. The candidate will serve as the primary security liaison with government agencies, sponsor representatives and integrate security solutions across business portfolios.

Your key responsibilities

  • Oversee daily security operations and NISP/32 CFR Part 117 NISPOM compliance.
  • Maintain and mature the facility’s industrial security program for Department of Defense (DoD) elements in compliance with applicable policies, and established regulations.
  • Enforce procedures for accounting, controlling, transmitting, safeguarding, and destroying classified information.
  • Support a security education, training, and awareness program.
  • Support the FSO with preparing reports and presentations for all levels of Management.
  • Maintains data compliance in DISS, NISS, NBIS, SWFT and other system of records.
  • Maintain and update Standard Practices and Procedures (SPP) documentation.
  • Support and mature the NISP annual security self-inspection, coordinating with internal stakeholders and DCSA representatives.
  • Provide support for classified meetings, including coordination and visitor management (e.g., processing Visitor Approval Requests (VARs)).
  • Lead security incident investigations in accordance with EY policy, NISPOM/32 CFR Part 117, and DCSA guidelines, collaborating with internal and external stakeholders.
  • Analyze and validate security processes, procedures, and standards to ensure compliance, identify trends and root-causes and facilitate multi-disciplinary teams to address gaps.
  • Prepare, track, and maintain Prime and Subcontractor DD-254s forms to ensure accuracy of security requirements. Coordinate with applicable stakeholders to facilitate actions necessary to execute and update such documentation.
  • Demonstrate professionalism, independent engagement, and collaboration with peers and external personnel to ensure adherence to regulations and guidelines.
  • Exhibit strong decision-making, individual initiative, organizational skills, and the ability to function with minimal supervision.

Skills and attributes for success

  • The AFSO must be a strategic thinker who can exercise independent judgment and knowledge to manage risks, deliver Industrial security support and align security solutions with business needs.
  • Candidate will collaborate with Senior security staff, employees and government clients to meet objectives while ensuring EY security program remains effective, compliant with Defense Counterintelligence and Security Agency (DCSA) standards, and aligned with corporate security requirements
  • In addition to technical expertise and independent initiative, the ideal AFSO will demonstrate a collaborative spirit and the ability to work seamlessly within multidisciplinary teams. Strong interpersonal skills are essential, enabling the candidate to foster open communication, support colleagues in joint problem solving, and cultivate an environment of mutual respect and shared accountability. A commitment to partnership—both within the security staff and across business units—ensures robust information exchange, effective coordination, and unified progress toward security and organizational objectives.

To qualify for the role you must have

  • Bachelor’s degree (Criminal Justice preferred) or equivalent experience
  • Strong organizational and communications skills, and the ability to effectively interact with staff and customers at all levels.
  • Proficiency in Microsoft Office products is required, with particular emphasis on Microsoft Access for database management and Microsoft Copilot for workflow optimization and automation.
  • DCSA Center for Development of Security Excellence (CDSE) FSO Program Management for Possessing Facilities courses.
  • Ability to obtain and maintain a TS/SCI Fullscope polygraph clearance
  • This position has an on-site requirement of 5 days a week on-site in the Tysons, VA and Arlington, VA office locations

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $57,400 to $104,100. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $68,800 to $118,300. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

07.10.2025
EY

EY GPS - IAM Engineer Supervising Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Maintaining ongoing knowledge and support of Azure infrastructure and aligned applications such as:Azure Cloud hosted services, Bastion, Keyvault, Recovery Services Vault, Storage accountsAzure Role Based Access Control (RBAC)Power Automate, App...
Description:

Our GPS Technology Organization is a structure within the US GPS practice that implements and maintains a new operate and technology model designed specifically to support U.S. defense and Government engagements.

You’ll have responsibilities within the Identity and Access Management (IAM) team that supports various applications in cloud platform services across the Government and Public Sector (GPS) business unit. You’ll support the end-to-end aspects of services including but not limited to service engineering, break/fix support, service roadmaps and standards, vendor management. You’ll also have responsibilities to include ensuring stability for application platforms and/or services under their responsibility including resolution of incidents and problems, maintenance and support, application platform change control, and automation of processes and procedures. Working closely with other teams within EY, you’ll drive technology standards and consistency across IT Services.

Your key responsibilities

  • Maintaining ongoing knowledge and support of Azure infrastructure and aligned applications such as:
    • Azure Cloud hosted services, Bastion, Keyvault, Recovery Services Vault, Storage accounts
    • Azure Role Based Access Control (RBAC)
    • Power Automate, App Service Plan, Function Apps, Application Insights
    • Azure networking; Vnets, network security groups (NSG), private and public endpoints, Azure Private DNS
    • Microsoft Entra Domain Services (MEDS)
    • Access reviews, reporting and Audit compliance
  • Deploying MEDS on Azure VM’s and install replica Domain Controllers or Forests in an Azure virtual network
  • Maintain ongoing knowledge and support of servers and networks aligned to the Active Directory environments including but not limited to:
    • Single Sign-On (SSO) configuration and remediation
    • Native Microsoft tools including but not limited to ADSI, ADUC, DNS, Domains and Trusts,
    • DISA STIG remediation with Group Policy Objects (GPO)
    • Public Key Infrastructure (PKI)
  • Creating and configuring Microsoft Entra Domain Services (IAAS & PAAS) for authenticating applications in Azure Cloud
  • Entra services management including application proxy, Licensing, Azure PIM
  • Application Registrations; OAuth/OpenID, API Permissions, Client ID/Secrets, JWT Tokens/Claims, JSON, App Roles
  • API Gateways, Enterprise Databases, SSO and Access Management systems, identity federation protocols (SAML), OIDC, OAuth2 and LDAP/LDAPS
  • Enterprise Applications; SAML, SCIM Provisioning
  • Managing data stored in Entra ID via Graph and Powershell.
  • Multi Factor Authentication (MFA) such as Entra ID MFA integration into the authentication, authorization, and single sign-on process for applications and systems
  • Account, Group, and entitlement management with SailPoint Identity Security Cloud (ISC) or IdentityIQ (IIQ)
  • Integrating SailPoint ISC or IIQ and other Identity Infrastructure with Entra ID
  • Design and configuration of Entra Conditional Access using Zero Trust principles
  • Entra ID external collaboration; B2B, Entra External ID
  • The role may also require the periodic allocation of additional time on the job to support multiple demands and escalating issues or to accommodate teams or staff in other time zones

Skills and attributes for success

  • Core understanding of Entra ID Tenant deployment and Active Directory management
  • Understanding of aligning Microsoft Entra / Azure services with security governance frameworks and guidelines such as CMMC, Fedramp, and NIST SP 800.53, 800.63, and 800.171
  • Understanding of application registration and Key Management using the Entra ID Admin portal
  • Understanding of Entra ID Privileged Roles, Units and emergency accounts to enable policies at a granular level for access administration
  • Strong organizational skills, self-motivated and able to work to tight deadlines
  • Strong analytical and problem-solving skills
  • Effective teaming and knowledge sharing skills
  • Advanced skills in planning, designing and troubleshooting complex cloud environments
  • Solid understanding of Cloud environment and security best practices
  • Good understanding of ITIL
  • Exceptional ability to document processes, procedures and security designs clearly and accurately for distribution to internal teams and customers
  • Understanding of other technologies required to run a secure enterprise level infrastructure
  • Demonstrated experience in dealing with external vendors and suppliers in the security industry
  • Cloud Infrastructure Security enthusiast
  • Self-motivated with an aptitude to learn quickly
  • Ability to deal with ambiguity
  • Have a global mind-set for working with different cultures and backgrounds

you must have

  • Bachelor’s degree in Computer Science or a related discipline, or equivalent work experience required
  • 5-8+ years of cloud infrastructure
  • 3 or more years of hands on experience in designing and implementing Cloud services like Azure AD, Entra ID, Azure MFA, Entra Conditional Access, Azure B2B and Azure PIM
  • Demonstrated deep expertise in cloud infrastructure
  • Experience with writing custom, scripting tools (Python, PowerShell, etc.), interacting with API’s and shell scripting
  • Excellent interpersonal, communication and presentation skills
  • Strong English language skills are required – written and verbal
  • Good judgment, tact, and decision-making ability
  • Ability to work in a diverse, multi-cultural, environment
  • Ability to obtain and maintain Top secret security clearance

Ideally, you’ll also have

  • Azure certification for implementing Microsoft Azure Infrastructure Solutions will be an added advantage
  • Involved in large scale IT deployments or cloud infrastructure
  • At least one technical certification in Azure platform

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $91,100 to $170,400. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $109,300 to $193,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
Description:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Must have government sector experience
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
Find your next career move in the high tech industry with Expoint. Our platform offers a wide range of Security Engineer job opportunities in the United States, Virginia, Arlington area, giving you access to the best companies in the field. Whether you're looking for a new challenge or a change of scenery, Expoint makes it easy to find your perfect job match. With our easy-to-use search engine, you can quickly find job opportunities in your desired location and connect with top companies. Sign up today and take the next step in your high tech career with Expoint.