Information Security Engineer Jobs
Information Security Engineer jobs are open across finance, healthcare, government contracting, and technology, from entry-level analyst roles to principal and staff engineer, with specializations in cloud security, penetration testing, and security operations. Find a role that fits from the openings below and apply directly.
Find JobsLooking for remote work? View remote information security engineer jobs →Student or new grad? View information security engineer internships →Overview
Showing 5 of 1,324+ Information Security Engineer jobs











- 543768
- PHOENIX
- DEPT OF EDUCATION
- Full-time
- Closing at: Sep 22 2026 - 23:55 MST
Department of Education
The Arizona Department of Education is a service organization committed to raising academic outcomes and empowering parents.
Information Technology Security Manager
Address: Information Technology Division
Phoenix, AZ 85007
Salary: $100,000 - $109,700
Grade: 28
Closing Date: 09/22/23
- This position serves as the agency's Information Technology Security Manager responsible for establishing, operating, and continuously improving the organization's security program. This position combines cybersecurity governance, risk management, compliance, security architecture, and operational security responsibilities into a hands-on leadership role.
- The position serves as the primary technical security authority for the agency and works closely with executive leadership, infrastructure teams, security analysts, and business stakeholders to reduce cybersecurity risk and ensure compliance with applicable regulatory and security requirements.
- This position is expected to maintain direct technical involvement in security operations, architecture, incident response, vulnerability management, identity management, and audit remediation activities.
- Occasional in-state travel is required for this position.
The Arizona Department of Education currently utilizes a hybrid work environment, with up to two days of remote work (contingent upon business needs). Candidates should apply with an ability and willingness to work in-office up to five days per week as business needs necessitate.
- Track audit findings, corrective action plans, risk acceptances, and remediation activities through closure.
- Develop and maintain agency cybersecurity compliance roadmaps aligned to NIST, CIS Controls, statutory requirements, Homeland Security requirements, and organizational risk priorities.
- Manage security awareness, phishing testing, and mandatory cybersecurity training programs across the agency.
- In conjunction with Data Governance provide support for eDiscovery, litigation holds, forensic data preservation, and legal investigations.
- Lead day-to-day cyber security operations.
- Develop and maintain security monitoring strategies across cloud, server, endpoint, network, and application environments.
- Identify logging gaps and establish enterprise standards for security: log collection, retention, monitoring, and alerting.
- Coordinate security incident response activities including detection, containment, eradication, recovery, and post-incident reviews.
- Responsible to provide day-to-day leadership and guidance to the cyber security staff.
- Lead the digital forensic investigations and evidence preservation following cyber security incidents along side the analyst.
- Develop and maintain security incident response playbooks and operational procedures.
- Perform threat modeling utilizing STRIDE, PASTA, attack trees, abuse cases, and adversarial risk analysis methodologies.
- Map MITRE ATT&CK techniques to security controls, detections, response capabilities, and defensive gaps.
- Responsible for all internal software reviews and operational approval/denial.
- Lead vulnerability management activities including vulnerability identification, prioritization, remediation tracking, risk acceptance, and executive reporting.
- Establish risk-based vulnerability remediation standards leveraging CVSS, exploit intelligence, asset criticality, and threat exposure.
- Coordinate internal and external security scanning activities including network, cloud, application, configuration, and penetration testing assessments.
- Develop and maintain the agency cybersecurity roadmap ensuring integration with operational priorities, and technology modernization efforts.
- Provide quarterly cybersecurity risk assessments, security posture reporting, and strategic recommendations to executive leadership.
- Primary contact for cybersecurity vendors, managed security service providers, and consulting partners.
- Develop security standards, procedures, and security baselines, in alignment with NIST, CIS Controls, statutory requirements, Homeland Security requirements. Measure and report cybersecurity performance through metrics, KPIs, risk indicators, and maturity assessments.
- Identify, analyze, prioritize, and implement security controls necessary to reduce organizational risk.
- Provide cyber security guidance to all IT disciplines as it relates to all security initiatives.
- Work within established IT Governance processes to drive cross functional security initiatives.
- Serve as the primary cybersecurity advisor to IT leadership regarding risk, operational security, and compliance matters.
- Contribute to the security architecture reviews for new technologies, major projects, and system implementations.
- Other duties as assigned as related to the position.
- NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-61, and NIST Risk Management Framework principles, CIS Critical Security Controls and cybersecurity maturity assessment methodologies, and state government cybersecurity requirements.
- Risk management principles, risk acceptance processes, corrective action planning, and audit remediation tracking.
- Security policies, standards, procedures, and baseline development.
- Monitoring strategies and threat detection methodologies.
- Security logging, SIEM technologies, alerting frameworks, and event correlation techniques.
- Incident response frameworks, evidence handling, chain of custody requirements, and forensic investigation practices.
- MITRE ATT&CK, cyber kill chain concepts, adversary tactics, techniques, and procedures (TTPs).
- Threat modeling methodologies including STRIDE, PASTA, attack trees, and abuse cases.
- Vulnerability assessment methodologies and remediation processes.
- CVSS scoring, exploit intelligence, threat priorities, and risk-based vulnerability management.
- Penetration testing concepts, attack surface analysis, and security scanning tools.
- Cloud security concepts for Microsoft Azure, Microsoft 365, and hybrid environments.
- Network security architecture, endpoint security, identity and access management, and cloud security controls.
- Zero Trust security principles.
- MS Defender, MS Sentinel, Entra ID, Intune, and related MS security technologies.
- Enterprise systems, infrastructure, networking, and application security principles.
- A Bachelors degree, plus four or more years of related experience, or equivalent experience to substitute for the degree, is required.
- Applicants must have supervisory experience in an Information Technology discipline such as Security, Operations, or Infrastructure
Skills in:
- Managing competing priorities, projects, and security initiatives.
- Building collaborative relationships across IT teams, business units, leadership, and external partners.
- Facilitating decision-making and driving accountability for remediation activities.
- Performing cybersecurity risk assessments and risk analysis.
- Developing compliance roadmaps.
- Auditing security controls and tracking remediation activities to closure.
- Developing and managing incident response processes and playbooks.
- Investigating and coordinating responses to cybersecurity incidents.
- Identifying monitoring gaps and designing detection strategies.
- Conducting threat analysis and mapping controls to MITRE ATT&CK techniques.
- Prioritizing vulnerabilities based on risk, exploitability, and business impact.
- Coordinating remediation activities across technical teams.
- Analyzing vulnerability and penetration testing results.
- Developing executive reporting and metrics related to security posture.
- Presenting cybersecurity risk information to executive leadership.
- Writing standards, procedures, and technical documentation.
- Implementing cybersecurity awareness and training programs.
- Communicating effectively with auditors, regulators, vendors, and law enforcement when necessary.
- Intermediate to advanced skill in using Microsoft Outlook, Word, and Excel.
Ability to:
- Analyze complex cybersecurity incidents and determine appropriate response actions.
- Assess security risks and prioritize mitigation efforts based on organizational impact.
- Identify security control gaps and recommend effective compensating controls.
- Interpret threat intelligence and apply it to organizational defenses.
- Lead cross-functional cybersecurity initiatives without direct authority.
- Build consensus among technical and non-technical stakeholders.
- Function as the agency's trusted cybersecurity advisor.
- Manage multiple security programs simultaneously while meeting deadlines.
- Coordinate response activities during high-pressure cybersecurity incidents.
- Preserve confidentiality and handle sensitive information appropriately.
- Produce accurate and meaningful security metrics, dashboards, and executive reports.
- Preferred Certifications: CISSP: Certified Information Systems Security Professional; CISM: Certified Information Security Manager; CEH: Certified Ethical Hacker; GSEC / GCIH / GCIA: GIAC Security Certifications
Offers are contingent upon successful completion of all background and reference checks, required documents and, if applicable, a post-offer medical/physical evaluation.
If this position requires driving or the use of a vehicle as an essential function of the job to conduct State business, then the following requirements apply: Driver’s License Requirements.
All newly hired State employees are subject to and must successfully complete the Electronic Employment Eligibility Verification Program (E-Verify).
- Affordable medical, dental, life, and short-term disability insurance plans
- Top-ranked retirement and long-term disability plans
- Ten paid holidays per year
- Vacation time accrued at 4.00 hours bi-weekly for the first 3 years
- Sick time accrued at 3.70 hours bi-weekly
- Paid Parental Leave-Up to 12 weeks per year paid leave for newborn or newly-placed foster/adopted child (pilot program).
- Deferred compensation plan
- Wellness plans
Learn more about the Paid Parental Leave program here. For a complete list of benefits provided by The State of Arizona, please visit our benefits page
You will be required to participate in the Arizona State Retirement System (ASRS) upon your 27th week of employment, subject to waiting period. On or shortly after, your first day of employment you will be provided with enrollment instructions and effective date.
The State of Arizona is an Equal Opportunity/Reasonable Accommodation Employer. Persons with a disability may request a reasonable accommodation such as a sign language interpreter or an alternative format by calling (602) 542-3186 or emailing Human.Resources@azed.gov. Requests should be made as early as possible to allow sufficient time to arrange the accommodation.
Information Security Engineer Jobs by Experience Level
Top Cities Hiring Information Security Engineers
Explore information security engineer openings in the cities hiring most right now.
See All 1,324+ Information Security Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsInformation Security Engineer Job Market
Who's Hiring
- Ryder System49

- CACI International26

- Peraton25

- Booz Allen Hamilton25

- Leidos23

Top Industries Hiring
- Technology & Software13
- Education5
- Healthcare & Medical Services5
- Biotechnology & Pharmaceuticals5
- Electronics & Hardware4
What Employers Look For
The qualifications that appear most often in information security engineer jobs.
- 3-5 years of experience in information security, network security, or a related discipline
- Proficiency with SIEM platforms such as Splunk, Microsoft Sentinel, or IBM QRadar
- Hands-on experience with vulnerability management tools like Tenable Nessus or Qualys
- Relevant certification such as CISSP, CompTIA Security+, CEH, or equivalent
- Working knowledge of NIST CSF, ISO 27001, or SOC 2 compliance frameworks
- Bachelor's degree in computer science, cybersecurity, information systems, or a related field
Tips for Your Information Security Engineer Job Search
Tailor your resume to the framework
Hiring managers scan for frameworks like NIST CSF, ISO 27001, or SOC 2 before reading anything else. Name the specific frameworks you've worked within and call out whether you led the implementation or operated within an existing program.
List certifications where recruiters look first
Put active certifications like CISSP, CEH, CompTIA Security+, or OSCP in your resume header or a dedicated line above your work history. Screeners filter on these before reading job descriptions, so burying them in a skills list costs you interviews.
Apply early to roles that fit
Migrate Mate lists information security engineer openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Decode the job posting before applying
Posts that list both offensive and defensive tools in the same opening are often written by non-technical HR staff. Read the day-to-day responsibilities, not just the requirements, to tell whether the role is blue team, red team, or a generalist position before you spend time customizing.
Prepare a breach scenario walkthrough
Nearly every technical interview for this role includes a scenario question: walk me through how you'd respond to a detected intrusion or data leak. Rehearse a structured answer using a detection, containment, eradication, and recovery sequence with a real or realistic example from your background.
Negotiate scope before accepting an offer
Security engineers frequently find the actual attack surface or team headcount differs from what was described. Ask directly how many endpoints the team monitors, what percentage of work is reactive versus proactive, and whether the budget for tooling is already allocated before you sign.
Information Security Engineer Jobs: Frequently Asked Questions
Which companies are hiring the most information security engineers?
The companies hiring the most information security engineers right now include Ryder System, CACI International, and Peraton, with the largest share of openings in Virginia, Maryland, and District of Columbia, based on current listings on Migrate Mate as of September 2026. Demand is especially concentrated in financial services, federal contractors, and large healthcare systems.
How many information security engineer jobs are remote?
About 55% of information security engineer openings are fully remote or hybrid as of September 2026, though roles involving classified systems or on-site security operations centers are almost always in-person. Cloud security, application security, and GRC-focused positions tend to have the highest share of remote-eligible postings.
How do you become an information security engineer?
Start by building a foundation in networking and operating systems, then pursue an entry-level security certification like CompTIA Security+ to validate core knowledge. Gain hands-on experience through a help desk, IT support, or junior analyst role. Move into security-specific work, pursue advanced certifications like CISSP or CEH, and build a portfolio demonstrating real incident response or vulnerability work.
Can you get hired as an information security engineer with little experience?
Yes, employers hire candidates with limited professional experience when they can demonstrate hands-on skills. Building a home lab, completing capture-the-flag challenges on platforms focused on offensive security practice, earning a foundational certification, and documenting that work in a portfolio gives hiring managers evidence of capability that compensates for a short work history.
What does the information security engineer interview process look like?
Most processes include a recruiter screen, a technical phone interview covering security fundamentals and tool familiarity, and a take-home or live scenario exercise such as analyzing a packet capture or walking through an incident response. Final rounds typically involve a panel with both the security team and a hiring manager focused on judgment calls and past experience.
Where can I find and apply to information security engineer jobs?
You can find and apply to information security engineer jobs on Migrate Mate, which lists current openings from employers across the United States. Search the listings to find roles that match your experience and specialization, then apply directly to each one that fits.
See All 1,324+ Information Security Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs