Information Security Analyst Jobs in District of Columbia
Information Security Analyst jobs in District of Columbia are among the most active markets in the country, concentrated in federal contracting, defense agencies, and financial services across Washington D.C. proper. The heaviest hiring comes from established employers like Booz Allen Hamilton, Leidos, and SAIC, with strong demand at every level from junior analysts to senior architects holding clearances. Incident response, cloud security, and compliance with federal frameworks like FedRAMP and FISMA are the most sought-after specialties. Scan the live roles below and apply to whichever ones fit.
Find JobsOverview
Showing 5 of 83+ Information Security Analyst jobs





- Washington DC Metro Area, District of Columbia
- Point Mugu, California
- Patuxent River, Maryland
- Huntsville, Alabama
Title:
Information System Security Manager (ISSM)KBR is seeking an Information System Security Manager (ISSM) to join our team. This position is primarily remote, however the ISSM must be able to go into the DoD installation space for meetings and work on ad ad-hoc and sometimes immediate basis
Why Join Us?
- Innovative Projects: KBR’s work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.
- Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace.
- Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense.
The selected applicant will provide cybersecurity and Risk Management Framework (RMF) support to systems and applications for the Test Resource Management Center (TRMC). Will work with military, government, and contractor personnel to provide technical and policy direction grounded in Department of Defense (DoD) policy, and act as the Subject Matter Expert (SME) with the cybersecurity domain and lead ISSOs. The application will, at times, be the liaison between end users, application developers, and senior leadership within the DoD and across the Test and Evaluation community.
Responsibilities:
- Deliver documentation to include: Executive level briefings, Assessments, Self-Assessments, RMF packages, and supporting RMF documentation
- Review Cybersecurity tool reports, ACAS, HBSS, for the purposes of reporting and compliance
- Software Certification package development
- Work directly with the TRMC SISO on all TRMC RMF packages and ATO Status updates
- Support security engineering projects and solution delivery.
- Lead security audit and compliance activities for each system responsible for
- Responsible for auditing all artifacts provided in each RMF package to determine system readiness for ATO packet submissions.
- Provide recommendations to the SISO, PM, and AO regarding remediation and mitigation of identified vulnerabilities on test reports and plan of action and milestones (POA&Ms).
- Monitor system status updates and report to senior leadership.
- Includes monthly executive reports, vulnerability reports, JFHQ DODIN reporting and briefing.
- Monthly executive briefing to SISO, PM on security metrics
- Interface with PMs and SISO on issues needing input/concurrence
- Draft and present RMF deliverables to senior leadership
- Attending Executive Program Reviews as the ISSM
- Work with outside agencies on Memorandums of Understanding / Interconnection Service Agreements, and other senior level agreements etc.
- Work directly with a distributed team to reduce travel
- Travel 25% of time
Basic Qualifications:
- *TS/SCI required*
- A minimum of 2 years of Information Technology Information Assurance, or Cyber Security engineering experience.
- A minimum of 2 years of experience in conducting security assessments by reviewing security controls with the ISSO/ISSM and guide programs through RMF process.
- Bachelor’s Degree in Engineering, Computer Science, or 8 years IT field experience in lieu of degree; Master’s Degree preferred
- Experience working with Special Access Programs (SAP)
- Proven expertise with assessing security controls in accordance with NIST Special Publications (i.e.: NIST 800 Series)
- Proven in-depth knowledge of Cybersecurity principles technologies, and processes.
- Experience with NIST 800-53, Security Development
- Familiarity with performing assessments for Unclassified and Classified environments
- Ability to adapt to process changes
- Ability to interface with senior leadership
- Ability to support high visibility or high priority projects
- Possession of excellent oral and written communication skills
Basic Compensation:
$155,000 - $190,000 (For DC area Only)
$155.000 - $190,000 (For Point Mugu, California Only)
$145,000 - $185,000 (For Maryland only)
The offered rate will be based on the selected candidate’s knowledge, skills, abilities and/or experience and in consideration of internal parity.
Additional Compensation:
KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short-term incentives, long-term incentives, or discretionary payments for exceptional performance.
KBR Benefits
KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.
Belong, Connect and Grow at KBR
At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together.
KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.
See All 83 Information Security Analyst Jobs in District of Columbia
Find roles in District of Columbia that match your experience and apply in just a few clicks.
Find JobsInformation Security Analyst Jobs by City in District of Columbia
Where District of Columbia roles are concentrated, by current openings.
Information Security Analyst Job Market in District of Columbia
A snapshot from current District of Columbia openings, updated as new roles post.
Who's Hiring


What District of Columbia Employers Look For
The qualifications that appear most often in information security analyst jobs across District of Columbia.
- Active security clearance at the Secret or Top Secret level required or preferred
- Bachelor's degree in cybersecurity, computer science, or a closely related field
- CISSP, Security+, or CISM certification expected for mid-level and senior roles
- Hands-on experience with SIEM platforms, endpoint detection, and vulnerability scanning tools
- Demonstrated knowledge of NIST, FedRAMP, and FISMA compliance frameworks
- Experience supporting federal government or defense contractor environments
Information Security Analyst Jobs in District of Columbia: Frequently Asked Questions
How do you become an information security analyst in District of Columbia?
There is no D.C.-specific state license required to work as an information security analyst, so the path runs through education and industry credentials. Most employers in D.C. expect at minimum a bachelor's degree in cybersecurity, computer science, or information systems, followed by certifications such as CompTIA Security+, CISSP, or CISM. Because the market is dominated by federal contractors and agencies, obtaining or being eligible for a government security clearance is often the single most important step for moving into the D.C. market.
How much do information security analysts make in District of Columbia?
Information security analysts in District of Columbia earn a median of about $135,090 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $86,280 for the lowest 10% to over $189,510 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire information security analysts in District of Columbia?
Employers hiring information security analysts in District of Columbia right now include Peraton, MANTECH, and Everforth ECS, based on current listings on Migrate Mate as of September 2026. The D.C. market is heavily anchored by large federal contractors and defense firms with long-term government contracts that sustain consistent analyst hiring across cleared and uncleared roles.
Which District of Columbia cities have the most information security analyst jobs?
The cities with the most information security analyst openings in District of Columbia are Washington and Pentagon. Washington D.C. itself drives the bulk of postings given its concentration of federal agencies, defense contractors, and financial regulators, while surrounding areas in the metro pull volume from major contractor campuses and intelligence community facilities that require a large cleared workforce.
Are there remote information security analyst jobs in District of Columbia?
Yes, and more than many fields, though it is not universal. About 50% of information security analyst openings tied to District of Columbia are remote or hybrid as of September 2026, reflecting the analytical and desk-based nature of much of the work. Roles involving compliance monitoring, threat intelligence, and policy tend to carry the most remote flexibility, while positions requiring hands-on access to classified networks or government facilities remain on-site.
How can I get hired as an information security analyst in District of Columbia with little or no experience?
The most realistic entry path in D.C. is through an associate or junior analyst role at a mid-size federal contractor, where training pipelines exist for candidates who hold a CompTIA Security+ certification and are eligible for a security clearance. Large contractors like Booz Allen Hamilton and Leidos run early-career programs specifically designed to bring in candidates without deep experience and put them through internal training tied to government contracts. Adjacent roles in IT support, network administration, or help desk at federal agencies also serve as common stepping stones, with internal transfers into security teams once foundational skills are demonstrated.
Where can I find and apply to information security analyst jobs in District of Columbia?
You can find and apply to information security analyst jobs in District of Columbia on Migrate Mate, which lists current D.C. openings updated in real time. Search the listings to find roles that match your experience level, clearance status, and specialty area, then apply directly to the ones that fit.
See All 83 Information Security Analyst Jobs in District of Columbia
Find roles in District of Columbia that match your experience and apply in just a few clicks.
Find Jobs