Information Security Engineer Jobs in District of Columbia
Information Security Engineer jobs in District of Columbia are concentrated in Washington DC and its immediate suburbs, where federal agencies, defense contractors, and major consulting firms like Booz Allen Hamilton, Leidos, and Northrop Grumman maintain large security operations and continuously recruit at every level. The market is among the most active in the country, driven by the concentration of government and intelligence-sector work, with the strongest demand in cloud security, security operations center analysis, and compliance-focused roles tied to federal frameworks like NIST and FedRAMP. Openings range from associate-level positions to senior architects and team leads. Scan the live roles below and apply to whichever ones fit.
Find JobsOverview
Showing 5 of 83+ Information Security Engineer jobs





- Washington DC Metro Area, District of Columbia
- Point Mugu, California
- Patuxent River, Maryland
- Huntsville, Alabama
Title:
Information System Security Manager (ISSM)KBR is seeking an Information System Security Manager (ISSM) to join our team. This position is primarily remote, however the ISSM must be able to go into the DoD installation space for meetings and work on ad ad-hoc and sometimes immediate basis
Why Join Us?
- Innovative Projects: KBR’s work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.
- Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace.
- Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense.
The selected applicant will provide cybersecurity and Risk Management Framework (RMF) support to systems and applications for the Test Resource Management Center (TRMC). Will work with military, government, and contractor personnel to provide technical and policy direction grounded in Department of Defense (DoD) policy, and act as the Subject Matter Expert (SME) with the cybersecurity domain and lead ISSOs. The application will, at times, be the liaison between end users, application developers, and senior leadership within the DoD and across the Test and Evaluation community.
Responsibilities:
- Deliver documentation to include: Executive level briefings, Assessments, Self-Assessments, RMF packages, and supporting RMF documentation
- Review Cybersecurity tool reports, ACAS, HBSS, for the purposes of reporting and compliance
- Software Certification package development
- Work directly with the TRMC SISO on all TRMC RMF packages and ATO Status updates
- Support security engineering projects and solution delivery.
- Lead security audit and compliance activities for each system responsible for
- Responsible for auditing all artifacts provided in each RMF package to determine system readiness for ATO packet submissions.
- Provide recommendations to the SISO, PM, and AO regarding remediation and mitigation of identified vulnerabilities on test reports and plan of action and milestones (POA&Ms).
- Monitor system status updates and report to senior leadership.
- Includes monthly executive reports, vulnerability reports, JFHQ DODIN reporting and briefing.
- Monthly executive briefing to SISO, PM on security metrics
- Interface with PMs and SISO on issues needing input/concurrence
- Draft and present RMF deliverables to senior leadership
- Attending Executive Program Reviews as the ISSM
- Work with outside agencies on Memorandums of Understanding / Interconnection Service Agreements, and other senior level agreements etc.
- Work directly with a distributed team to reduce travel
- Travel 25% of time
Basic Qualifications:
- *TS/SCI required*
- A minimum of 2 years of Information Technology Information Assurance, or Cyber Security engineering experience.
- A minimum of 2 years of experience in conducting security assessments by reviewing security controls with the ISSO/ISSM and guide programs through RMF process.
- Bachelor’s Degree in Engineering, Computer Science, or 8 years IT field experience in lieu of degree; Master’s Degree preferred
- Experience working with Special Access Programs (SAP)
- Proven expertise with assessing security controls in accordance with NIST Special Publications (i.e.: NIST 800 Series)
- Proven in-depth knowledge of Cybersecurity principles technologies, and processes.
- Experience with NIST 800-53, Security Development
- Familiarity with performing assessments for Unclassified and Classified environments
- Ability to adapt to process changes
- Ability to interface with senior leadership
- Ability to support high visibility or high priority projects
- Possession of excellent oral and written communication skills
Basic Compensation:
$155,000 - $190,000 (For DC area Only)
$155.000 - $190,000 (For Point Mugu, California Only)
$145,000 - $185,000 (For Maryland only)
The offered rate will be based on the selected candidate’s knowledge, skills, abilities and/or experience and in consideration of internal parity.
Additional Compensation:
KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short-term incentives, long-term incentives, or discretionary payments for exceptional performance.
KBR Benefits
KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.
Belong, Connect and Grow at KBR
At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together.
KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.
See All 83 Information Security Engineer Jobs in District of Columbia
Find roles in District of Columbia that match your experience and apply in just a few clicks.
Find JobsInformation Security Engineer Jobs by City in District of Columbia
Where District of Columbia roles are concentrated, by current openings.
Information Security Engineer Job Market in District of Columbia
A snapshot from current District of Columbia openings, updated as new roles post.
Who's Hiring


What District of Columbia Employers Look For
The qualifications that appear most often in information security engineer jobs across District of Columbia.
- Active security clearance, or eligibility to obtain one, often required
- Bachelor's degree in computer science, cybersecurity, information systems, or related field
- Certifications such as CISSP, CEH, CompTIA Security+, or equivalent strongly preferred
- Hands-on experience with SIEM tools, intrusion detection, and vulnerability management platforms
- Familiarity with federal compliance frameworks including NIST, RMF, FedRAMP, or FISMA
- Proficiency in scripting or programming languages such as Python, PowerShell, or Bash
Information Security Engineer Jobs in District of Columbia: Frequently Asked Questions
How do you become a information security engineer in District of Columbia?
Information security engineering in DC does not require a state-issued license, but the market strongly favors candidates who hold a bachelor's degree in cybersecurity, computer science, or a related field alongside recognized certifications like CISSP, Security+, or CISM. The federal and defense focus of DC employers means obtaining or being eligible for a security clearance is often the most decisive qualification, and many candidates begin that process through entry-level contractor or government IT roles.
How much do information security engineers make in District of Columbia?
Information security engineers in District of Columbia earn a median of about $135,090 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $86,280 for the lowest 10% to over $189,510 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire information security engineers in District of Columbia?
District of Columbia information security engineer roles are posted by Peraton, MANTECH, and Everforth ECS and others right now, based on current listings on Migrate Mate as of September 2026. DC's concentration of federal agencies, intelligence community contractors, and large systems integrators makes it one of the most consistently active hiring markets for this role in the country.
Which District of Columbia cities have the most information security engineer jobs?
Washington and Pentagon account for the most information security engineer openings in District of Columbia. Washington DC anchors the market as the home of federal agencies and their prime contractors, while nearby areas like Arlington and Bethesda carry significant volume due to the headquarters of major defense and consulting firms with long-term government contracts.
Are there remote information security engineer jobs in District of Columbia?
Yes, and more than many technical roles. About 50% of information security engineer openings tied to District of Columbia are remote or hybrid as of September 2026, though positions requiring access to classified systems or sensitive federal networks are typically on-site or restricted to specific cleared facilities. Cloud security, risk assessment, and compliance-focused roles tend to offer the most remote flexibility.
How can I get hired as a information security engineer in District of Columbia with little or no experience?
The most realistic entry path in DC is through a junior IT security analyst or SOC analyst role with a federal contractor, where firms like Booz Allen Hamilton, SAIC, and ManTech regularly hire early-career candidates and support the clearance process. A Security+ certification combined with any hands-on lab experience, such as a capstone project or a home lab, gives a candidate a measurable edge, and programs at DC-area universities like George Mason and George Washington often have direct relationships with government contractors for internships and new-grad placements.
Where can I find and apply to information security engineer jobs in District of Columbia?
You can find and apply to information security engineer jobs in District of Columbia on Migrate Mate, which lists current openings in the area. Search the available roles, identify the ones that match your background and clearance level, and apply directly to the ones that fit.
See All 83 Information Security Engineer Jobs in District of Columbia
Find roles in District of Columbia that match your experience and apply in just a few clicks.
Find Jobs