Security Infrastructure & Exposure Engineer
About the role
The Security Infrastructure & Exposure Engineer will design, build, and scale our attack surface management and threat exposure detection capabilities. You will engineer internal tools and automated pipelines that proactively map assets, model attack paths, and eliminate security blind spots before they can be exploited.
Responsibilities
- Architect and maintain Continuous Asset Attack Surface Management (CAASM) solutions for real-time asset discovery
- Map network topologies, analyze segmentation, and build automated attack path graphs to identify choke points
- Integrate active/passive scanning data with Identity Provider (IdP) telemetry to pinpoint exposed or unmanaged infrastructure
- Embed automated vulnerability and exposure testing into Infrastructure-as-Code (IaC) and CI/CD deployment pipelines
- Evaluate and harden complex cloud architectures against emerging exposure techniques
Requirements
- Active TS/SCI Clearance with CI Polygraph
- Bachelor’s degree and 8 years of experience related to the functional area
- Active certifications for both IAT Level II (e.g., CompTIA Security+) and Cyber Security Service Provider (CSSP) Infrastructure Support (e.g., CompTIA Cloud+) by program onboarding date. The following individual certifications cover both requirements: CompTIA Cybersecurity Analyst (CySA+), EC-Council Certified Network Defender (CND), GIAC Global Industrial Cyber Security Professional (GICSP), (ISC)² Systems Security Certified Practitioner (SSCP)
- Proven experience with CAASM tooling and building inventory systems
- Deep understanding of network topology, segmentation verification, and graph-based attack path analysis
- Hands-on experience with active/passive network scanning and correlating data with identity registries (e.g., Okta, Azure AD)
- Strong background in cloud security architecture (AWS, GCP, or Azure), IaC (Terraform, OpenTofu), and CI/CD security validation
- Proficiency in at least one of the following languages: Go, Rust, or Python
Preferred Qualifications
- Experience leveraging advanced AI models (e.g., ChatGPT, Grok, Claude) to automate security workflows
- Multiple scripting and development languages
- Familiarity with developer-focused AI tools like Claude Code or OpenAI Codex to accelerate engineering velocity
Benefits
- Generous cost sharing for medical insurance for the employee and dependents
- 100% company paid dental insurance for employees and dependents
- 100% company paid long-term and short-term disability insurance
- 100% company paid vision insurance for employees and dependents
- 401k plan with generous match and 100% immediate vesting
- Competitive pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance
About AnaVation
AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US-owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team.