A cybersecurity firm is seeking experienced cybersecurity professionals to evaluate AI-generated security content, solve technical problems, and provide feedback to improve AI systems. This is a flexible remote position,…
Security Engineer jobs in Washington, DC
Security engineers protect systems and data by finding vulnerabilities, building defenses, and responding to incidents. The work spans application security, infrastructure hardening, and threat detection.
No email, no resume, no sign-up. Save any listing below and you start anonymously.
You're signed in. Saving a listing drops it straight into your pipeline.
Open security engineer roles
7 shown of 1,948 · sorted by freshness
Deloitte's Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across complex enterprise environments. This role will focus on bui…
from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first approach safeguards... ...What you bring to the table ~5+ years of engineering and pre-sales experience…
and problem solvers to help us create it. Who you are Metropolis is seeking a highly technical, developer-oriented Senior Security Engineer to focus on securing our software engineering and product environments across we…
Paid time off ~ Vision insurance Position Summary Celestial Innovations Group (CIG) is seeking a skilled Cortex XSIAM Security Engineer to deploy, configure, and operationalize Palo Alto Networks Cortex XSIAM for federal…
opportunity to serve as a critical component of our nation’s safety and security. Make an impact by using your expertise to protect our country... ...technology into opportunity as a Cybersecurity Systems Engineer/ Infor…
business development efforts for upcoming opportunities with the U.S. Department of State's Bureau of Diplomatic Security (DS) – Training – Technical Security Engineering. The Advisor will play a critical role in refinin…
What security engineers earn in Washington
Hourly first — that's how the offer arrives
| Experience | Hourly | Annual, full-time |
|---|---|---|
| Entry level | $48–$66 | $100k–$138k |
| Mid level | $66–$93 | $138k–$194k |
| Senior | $90–$126 | $188k–$262k |
Adjusted for the Washington market from national ranges.
What employers ask for
The skills these listings keep naming
Interview questions worth rehearsing
With the thing the interviewer is actually listening for
Walk me through how you would threat model a new feature.
Use a structure — assets, entry points, attacker goals — and show that you rank risks rather than listing everything. STRIDE is a fine scaffold if you actually apply it.
You find a critical vulnerability in production. What are your next steps?
Verify, assess exposure, contain, and coordinate disclosure and fix — with communication throughout. Panic-free process is the whole answer.
Explain a recent vulnerability class or breach and what you took from it.
Staying current is part of the job. Pick something real, explain the root cause simply, and connect it to a defense you would build.
How do you get developers to fix security issues they see as low priority?
Show empathy for delivery pressure: translate risk into business impact, make fixes easy, and build guardrails so the secure path is the default.
How would you secure a cloud environment from scratch?
Cover identity first, then network segmentation, logging, encryption, and automated policy checks. Saying 'IAM is where most cloud breaches start' shows you know the terrain.
What is the difference between authentication and authorization, and where do systems commonly get it wrong?
Define both crisply, then give a real failure mode like broken object-level authorization. The follow-through example is what distinguishes the answer.
Tell me about a security control you built or improved.
Describe the risk it addressed and evidence it worked — findings reduced, detection time improved. Controls without measurement are just hopes.
Resume tips that move the needle
For security engineers specifically — generic advice costs you here
Lead with concrete defensive wins: vulnerabilities remediated, detection coverage added, incident response times improved.
List relevant certifications (Security+, OSCP, CISSP) prominently; this field still screens on them.
Name the domains you cover — appsec, cloud security, detection — since 'security' alone is too broad to place you.
Mention responsible disclosures, CTF results, or published research if you have them; they are strong credibility signals.
Show you can work with engineers, not just audit them — secure code reviews, training, or paved-road tooling you built.
Where this role goes
Typical progression
Applying for security engineer jobs in Washington?
Robbi carries this page into your first day: your role, your city, your shift preference. Then it hands you a few small things each morning and keeps the pipeline honest.
Save what looks right here, then let Robbi hand you a few small things each morning and keep the follow-ups honest.