OverviewAs a Senior Cloud Security Engineer, you will work within our growing DevSecOps practice delivering features to support developing, testing, and monitoring secure cloud architectures for cloud migration, cloud op…
Security Engineer jobs in Washington, DC
Security engineers protect systems and data by finding vulnerabilities, building defenses, and responding to incidents. The work spans application security, infrastructure hardening, and threat detection.
No email, no resume, no sign-up. Save any listing below and you start anonymously.
You're signed in. Saving a listing drops it straight into your pipeline.
Open security engineer roles
8 shown of 836 · sorted by freshness
automation, assessment, and management tool sets to drive effectiveness and efficiencies Provide expert knowledge of Nessus, Splunk and Security Center tools Provide expert knowledge of Service Now (SNOW), eMASS, and oth…
Undersea Systems Security EngineerThe Opportunity: Join our team as a Systems Security Engineer supporting cybersecurity and systems security analysis for U.S. Navy afloat and undersea platforms. You will help design, as…
specialized Information Technology support for our strategic business partners within the client Corporate Center. Job Title: IAM Security Engineer Location: Seattle, WA, 98101 Duration: 3 Months Work Type: Onsite Job Ty…
opportunity to serve as a critical component of our nation’s safety and security. Make an impact by using your expertise to protect our country... ...technology into opportunity as a Cybersecurity Systems Engineer/ Infor…
and other Microsoft 365 workloads. Design and implement data security and governance controls for Microsoft 365 Copilot and AI-... ...with Security Operations, Legal, Privacy, Compliance, and Cloud Engineering teams to t…
The Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services that support our business. You will understand data and automation are important ingredients to our missi…
cFocus Software seeks a Blue Team Security Engineer to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC.…
What security engineers earn in Washington
Hourly first — that's how the offer arrives
| Experience | Hourly | Annual, full-time |
|---|---|---|
| Entry level | $48–$66 | $100k–$138k |
| Mid level | $66–$93 | $138k–$194k |
| Senior | $90–$126 | $188k–$262k |
Adjusted for the Washington market from national ranges.
What employers ask for
The skills these listings keep naming
Interview questions worth rehearsing
With the thing the interviewer is actually listening for
Walk me through how you would threat model a new feature.
Use a structure — assets, entry points, attacker goals — and show that you rank risks rather than listing everything. STRIDE is a fine scaffold if you actually apply it.
You find a critical vulnerability in production. What are your next steps?
Verify, assess exposure, contain, and coordinate disclosure and fix — with communication throughout. Panic-free process is the whole answer.
Explain a recent vulnerability class or breach and what you took from it.
Staying current is part of the job. Pick something real, explain the root cause simply, and connect it to a defense you would build.
How do you get developers to fix security issues they see as low priority?
Show empathy for delivery pressure: translate risk into business impact, make fixes easy, and build guardrails so the secure path is the default.
How would you secure a cloud environment from scratch?
Cover identity first, then network segmentation, logging, encryption, and automated policy checks. Saying 'IAM is where most cloud breaches start' shows you know the terrain.
What is the difference between authentication and authorization, and where do systems commonly get it wrong?
Define both crisply, then give a real failure mode like broken object-level authorization. The follow-through example is what distinguishes the answer.
Tell me about a security control you built or improved.
Describe the risk it addressed and evidence it worked — findings reduced, detection time improved. Controls without measurement are just hopes.
Resume tips that move the needle
For security engineers specifically — generic advice costs you here
Lead with concrete defensive wins: vulnerabilities remediated, detection coverage added, incident response times improved.
List relevant certifications (Security+, OSCP, CISSP) prominently; this field still screens on them.
Name the domains you cover — appsec, cloud security, detection — since 'security' alone is too broad to place you.
Mention responsible disclosures, CTF results, or published research if you have them; they are strong credibility signals.
Show you can work with engineers, not just audit them — secure code reviews, training, or paved-road tooling you built.
Where this role goes
Typical progression
Applying for security engineer jobs in Washington?
Robbi carries this page into your first day: your role, your city, your shift preference. Then it hands you a few small things each morning and keeps the pipeline honest.
Save what looks right here, then let Robbi hand you a few small things each morning and keep the follow-ups honest.