Information Security Engineer Jobs in California
Information Security Engineer jobs in California are among the most active in the country, concentrated in technology, defense, finance, and healthcare sectors, with openings from entry-level analysts through principal and staff engineers. The largest hiring metros are the San Francisco Bay Area, Los Angeles, and San Diego, where established employers like Lockheed Martin, Wells Fargo, and Kaiser Permanente maintain substantial security teams. Cloud security, application security, and threat detection and response are the most consistently sought specializations across California. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 96+ Information Security Engineer jobs











Description
Leidos' Corporate Information Security Office (CISO), reporting through our Digital sector, is seeking an Information Systems Security Manager in our San Diego, CA Campus Point office.
In this role, you will oversee Information Systems supporting Special Access Programs (SAPs) and maintain system authorization and cybersecurity compliance throughout the system lifecycle in accordance with the Joint Special Access Program Implementation Guide (JSIG), Risk Management Framework (RMF), applicable DoD SAP security requirements, and customer-specific guidance.
As the ISSM, you will serve as a Subject Matter Expert (SME) within the Information Assurance (IA) technical domain, supporting SAP Information Systems and enclaves across the enterprise. You will oversee day-to-day information system security operations, manage IA and IT personnel supporting SAP environments, resolve complex cybersecurity challenges, and develop innovative solutions to meet evolving program, customer, and security requirements.
The ideal candidate must be able to work independently while effectively collaborating with cybersecurity analysts, system administrators, engineers, program management, security personnel, site leadership, Program Security Officers (PSOs), Security Control Assessors (SCAs), and Authorizing Official (AO) representatives.
Location: All work will be performed on-site at our San Diego, CA office.
Clearance: You must currently hold an active Top Secret security clearance and be eligible for Special Access Program (SAP) clearance.
Primary Responsibilities
This role may include a combination of duties to protect SAP information, maintain cybersecurity controls, manage risk, and ensure Information Systems operate in accordance with approved authorization documentation and applicable SAP cybersecurity requirements.
Develop, implement, maintain, and enforce cybersecurity policies, procedures, Standard Operating Procedures (SOPs), and system-specific security documentation supporting SAP Information Systems.
Develop and conduct cybersecurity education and training for Information System users, privileged users, Information System Security Officers (ISSOs), system administrators, and other personnel supporting SAP environments.
Mentor ISSOs, system administrators, and other Information Assurance professionals regarding JSIG, RMF, secure system administration, vulnerability management, configuration management, and cybersecurity best practices.
Coordinate technical training on cybersecurity tools, software, technologies, and procedures used within SAP Information System environments.
Develop and lead training related to cybersecurity incident response, including identification, reporting, containment, remediation, recovery, documentation, and lessons learned.
Develop and lead Information Security projects from conceptualization through implementation, authorization, deployment, and operational acceptance.
Provide cybersecurity risk information and recommendations to program and senior site leadership to support risk-informed decisions regarding SAP Information Systems.
Demonstrated experience managing the cybersecurity and compliance posture of complex, multi-site Wide Area Networks (WANs), including interconnected systems across geographically dispersed locations.
Experience applying RMF, NIST, and applicable DoD security requirements to WAN architectures, boundary protections, network infrastructure, continuous monitoring, vulnerability management, and authorization activities.
Basic Qualifications
Must currently hold an active DoD Top Secret clearance to be considered and you must be able to meet applicable eligibility and access requirements for Special Access Program information.
Bachelor’s degree in an IT-related subject matter area from an accredited college or university and 12+ years of experience in an operational cybersecurity-specific role (e.g., Information Systems Security Manager, Information Systems Security Officer, cybersecurity specialist), or 16+ years of experience in an IT-related position with at least 10 years in an operational cybersecurity-specific role.
At least 10 years of Information Assurance/Cybersecurity management experience.
Current DoD 8570/8140 CISSP or CISM certification.
Previous ISSM and/or senior ISSO experience supporting classified Information Systems.
Detailed understanding and practical application of the Risk Management Framework (RMF), Joint Special Access Program Implementation Guide (JSIG), National Institute of Standards and Technology (NIST) security controls, and Committee on National Security Systems Instruction (CNSSI) 1253 requirements.
Working knowledge of DoD Special Access Program cybersecurity requirements, policies, processes, and procedures applicable to the authorization and operation of SAP Information Systems.
Experience developing, maintaining, and managing RMF authorization packages and associated cybersecurity documentation, including SSPs, security control implementation statements, POA&Ms, risk assessments, continuous monitoring artifacts, and supporting Body of Evidence.
Experience preparing Information Systems for cybersecurity assessments and supporting Security Control Assessors (SCAs), Authorizing Officials (AOs), Program Security Officers (PSOs), and customer cybersecurity representatives throughout the authorization process.
Familiarity with network technologies (LAN and WAN), network architecture, encryption technologies, key management, and cybersecurity best practices within classified and SAP environments.
Working knowledge of Microsoft Windows workstation/server and Linux operating systems within secure network environments.
Experience implementing and validating DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), security configuration baselines, and system hardening requirements.
Experience with compliance, security monitoring, and vulnerability assessment tools such as Tenable/Nessus, ACAS, Splunk, and STIG Viewer.
Experience with workflow, documentation, configuration management, and change management tools such as JIRA and Confluence, as well as applicable RMF authorization management tools.
Ability to evaluate vulnerabilities, system changes, security control deficiencies, and cybersecurity risks and develop appropriate mitigation and remediation strategies.
Must be able to work in a constantly changing regulatory and mission environment with short-, mid-, and long-term timelines for resolving cybersecurity risks and compliance deficiencies.
Must work effectively within multidisciplinary teams and adapt quickly to changing program, customer, and mission requirements.
Excellent verbal and written communication skills with the ability to communicate cybersecurity risks and technical information to technical and non-technical stakeholders.
Preferred Qualifications
Experience working directly with PSOs, SCAs, AOs/DAOs, government cybersecurity representatives, and SAP program management.
Experience supporting SAP Information System Assessment and Authorization activities from initial system design through ATO and continuous monitoring.
Experience developing JSIG/RMF authorization documentation and providing supporting artifacts and evidence for security control assessments.
Experience with SAP cybersecurity assessments, compliance inspections, and remediation of assessment findings.
Proficient with Microsoft Windows and Linux operating systems, virtualization technologies, and secure computing environments.
Experience with network security architecture, classified network design, secure communications, encryption, and key management.
Experience developing cybersecurity policies, procedures, SOPs, CONOPS, and other technical documentation supporting SAP Information Systems.
Experience using JIRA and Confluence for cybersecurity workflow, continuous monitoring, vulnerability tracking, POA&M management, and documentation.
Experience leading or mentoring ISSOs, system administrators, cybersecurity analysts, and other technical personnel supporting SAP Information Systems.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
September 17, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $107,900.00 - $195,050.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
See All 96 Information Security Engineer Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find JobsInformation Security Engineer Jobs by City in California
Where California roles are concentrated, by current openings.
Information Security Engineer Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Electronics & Hardware
- Technology & Software
- Retail
- Education
- Manufacturing
What California Employers Look For
The qualifications that appear most often in information security engineer jobs across California.
- Bachelor's degree in computer science, information security, or a related technical field
- Active CISSP, CISM, or CompTIA Security+ certification preferred or required
- Hands-on experience with SIEM platforms, firewalls, and intrusion detection systems
- Familiarity with California Consumer Privacy Act compliance and data protection requirements
- Proficiency in cloud security practices across AWS, Azure, or Google Cloud environments
- Experience conducting vulnerability assessments, penetration testing, or security audits
Information Security Engineer Jobs in California: Frequently Asked Questions
How do you become a information security engineer in California?
California does not issue a state license specific to information security engineers, so the path runs through education and industry credentials. Most California employers expect a bachelor's degree in computer science, information systems, or cybersecurity, followed by certifications such as CISSP, CEH, or CompTIA Security+. Starting as a security analyst or IT administrator at a California technology company, healthcare system, or defense contractor is the most common way to build toward an engineer-level role.
How much do information security engineers make in California?
Information security engineers in California earn a median of about $138,570 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $66,070 for the lowest 10% to over $221,000 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire information security engineers in California?
Employers hiring information security engineers in California right now include Lam Research, Apple, and Raytheon, based on current listings on Migrate Mate as of September 2026. California's concentration of defense contractors in San Diego, major technology firms in the Bay Area, and large health systems throughout the state keeps demand for this role consistently high across multiple industries.
Which California cities have the most information security engineer jobs?
San Diego, San Francisco, and Fremont have the most information security engineer openings in California. The Bay Area's density of technology headquarters and fintech firms drives the largest share of postings, while Los Angeles draws demand from entertainment, aerospace, and financial services, and San Diego's strong defense contracting sector anchors hiring in the south.
Are there remote information security engineer jobs in California?
Yes, and more than most fields. About 51% of information security engineer openings tied to California are remote or hybrid as of September 2026, reflecting the largely desk-based and analytical nature of the work. Roles focused on cloud security architecture, threat intelligence, and security operations center monitoring are the most consistently offered on a remote basis.
How can I get hired as a information security engineer in California with little or no experience?
The most realistic entry path is a security analyst or IT support role at a California technology company, health system, or government contractor, then moving into engineering responsibilities over time. Large California employers including county government agencies, UC system campuses, and mid-size defense contractors in San Diego regularly hire entry-level security analysts. Earning a CompTIA Security+ or associate-level cloud security credential before applying gives candidates a concrete edge over others without hands-on experience.
Where can I find and apply to information security engineer jobs in California?
You can find and apply to information security engineer jobs in California on Migrate Mate, which lists current California openings across technology, defense, finance, and healthcare employers. Find roles that fit your experience and specialization and apply directly.
See All 96 Information Security Engineer Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Jobs