1

Cyber Security Practitioner Jobs in California (NOW HIRING)

Senior DevSecOps Cybersecurity Engineer

El Segundo, CA · On-site +1

$122K - $167K/yr

This role serves as a senior cybersecurity practitioner embedded within Agile and DevSecOps development teams responsible for delivering capabilities into government-owned production environments ...

Cybersecurity Program Manager

San Jose, CA · On-site +1

$151K - $184K/yr

This role sits at the intersection of cybersecurity operations, risk management, governance, and executive-level communication - ideal for a structured, strategic, and highly organized practitioner ...

Cybersecurity Program Manager

San Jose, CA · Remote

$151K - $184K/yr

This role sits at the intersection of cybersecurity operations, risk management, governance, and executivelevel communication - ideal for a structured, strategic, and highly organized practitioner ...

next page

Showing results 1-20

Cyber Security Practitioner information

See California salary details

$41K

$128.6K

$197.4K

How much do cyber security practitioner jobs pay per year?

As of Sep 8, 2026, the average yearly pay for cyber security practitioner in California is $128,589.00, according to ZipRecruiter salary data. Most workers in this role earn between $106,600.00 and $148,000.00 per year, depending on experience, location, and employer.

What is a cyber security practitioner?

Cyber Security Practitioners are professionals responsible for protecting computer systems, networks, and data from cyber threats such as hacking, malware, and unauthorized access. They analyze vulnerabilities, implement security measures, monitor for security breaches, and respond to incidents. These practitioners may specialize in areas like network security, information security, or ethical hacking, and work in a variety of industries to help organizations safeguard sensitive information. Their role is crucial in ensuring the confidentiality, integrity, and availability of digital assets.

What are some common challenges faced by cyber security practitioners in a fast-paced enterprise environment?

Cyber Security Practitioners in enterprise settings often face the challenge of balancing proactive threat detection with responding to real-time incidents. Keeping up with constantly evolving attack methods and ensuring all systems comply with security policies can be demanding. Additionally, practitioners must collaborate closely with IT, development, and business teams to implement security controls without disrupting operations. Effective communication and continuous learning are key to overcoming these challenges and maintaining a strong security posture.

What are the key skills and qualifications needed to thrive as a cyber security practitioner, and why are they important?

To thrive as a Cyber Security Practitioner, you need a solid understanding of network security, threat analysis, and risk management, typically supported by a degree in computer science or information security. Familiarity with security tools like firewalls, SIEM systems, penetration testing software, and certifications such as CISSP or CEH are usually required. Strong analytical thinking, attention to detail, and effective problem-solving skills help practitioners anticipate and respond to evolving threats. These competencies are crucial for protecting organizational assets, maintaining regulatory compliance, and minimizing the impact of cyber attacks.

What is the difference between Cyber Security Practitioner vs Cyber Security Analyst?

AspectCyber Security PractitionerCyber Security Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Work EnvironmentHands-on security implementation, system monitoringSecurity monitoring, incident response, analysis
Employer & Industry UsageIT departments, cybersecurity firms, government agenciesIT security teams, corporate security departments

Both roles often require similar certifications and work in cybersecurity environments, but Cyber Security Practitioners focus more on implementing security measures and configuring systems, while Cyber Security Analysts primarily monitor, analyze, and respond to security incidents. Understanding these differences helps organizations assign the right responsibilities and professionals for their cybersecurity needs.

Infographic showing various Cyber Security Practitioner job openings in California as of August 2026, with employment types broken down into 89% Full Time, 9% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $128,589 per year, or $61.8 per hour.

Senior DevSecOps Cybersecurity Engineer

El Segundo, CA • On-site

KBR, Inc.
IT Services • 10K+ employees

$113K - $153K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 19 days ago


KBR rating

8.3

Company rating: 8.3 out of 10

Based on 48 frontline employees who took The Breakroom Quiz

141st of 454 rated engineering


Job description

Title:
Senior DevSecOps Cybersecurity Engineer
Belong. Connect. Grow. with KBR!
KBR's National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have a profound impact on the country's most critical role - protecting our national security.
KBR is seeking a motivated and experienced Senior DevSecOps Cybersecurity Engineer to join our team. The primary work locations are El Segundo, CA and Colorado Spring, CO, but work-from-home flexibility is available. This role serves as a senior cybersecurity practitioner embedded within Agile and DevSecOps development teams responsible for delivering capabilities into government-owned production environments operating at IL5 and IL6.
The Cybersecurity Engineer will work closely with software developers, cloud engineers, mission owners, systems engineers, Information System Security Managers (ISSMs), Authorizing Officials (AOs), and government cybersecurity personnel to ensure software releases meet security, compliance, and operational requirements.
The position requires deep expertise in RMF implementation, vulnerability management, CVE assessment and remediation, secure deployment methodologies, and cybersecurity activities necessary to support Authority to Operate (ATO) accredited environments.
The successful candidate must be capable of explaining cybersecurity risk to both technical and non-technical stakeholders, developing mitigation strategies for identified vulnerabilities, and ensuring mission capabilities can be rapidly and securely deployed into operational environments.
This role is a senior cybersecurity and RMF expert embedded within DevSecOps software delivery teams responsible for enabling secure deployment of mission capabilities into accredited IL5 and IL6 production environments. The emphasis is on CVE analysis and remediation, RMF execution, cybersecurity documentation, deployment approval activities, security compliance, and effective communication of cyber risk to government stakeholders while enabling rapid and secure mission capability delivery.
KBR (formerly LinQuest) is the prime contractor on the Military Satellite Communications (MILSATCOM) Systems Engineering, Integration and Test (MSEIT) contract. The MSEIT effort provides leading-edge Systems Engineering & Integration (SE&I) for the United States Space Force's (USSF) Space Systems Command (SSC). We acquire state-of-the-art Military and Commercial Satellite Communications (SATCOM) systems, providing global, secure, survivable, and protected communications for our nation's warfighters. We seek technical individuals who will thrive in a highly collaborative work environment of small teams, using the most modern tools and methodologies to tackle the challenges of integrating complex space and ground communications systems.
Why Join Us?
  • Innovative Projects: KBR's work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.
  • Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace.
  • Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense.

Work Environment:
  • Location: El Segundo, CA or Colorado Springs, CO (work-from-home flexibility with on-site support as required)
  • Travel Requirements: Minimal
  • Working Hours: Standard

Responsibilities
Cybersecurity Engineering
  • Serve as the primary cybersecurity engineering lead supporting DevSecOps software delivery efforts.
  • Provide cybersecurity guidance throughout the software development lifecycle from design through production deployment.
  • Evaluate system architectures, software components, and deployment pipelines for compliance with DoD and Department of the Air Force cybersecurity requirements.
  • Partner with development, platform, cloud, and infrastructure teams to ensure security is integrated into all phases of delivery.

CVE Analysis & Remediation
  • Assess Common Vulnerabilities and Exposures (CVEs) identified through automated scanning, security testing, and cybersecurity reviews.
  • Analyze operational impact, exploitability, mission risk, and remediation options for vulnerabilities affecting mission systems.
  • Develop mitigation strategies and Plans of Action and Milestones (POA&M) recommendations when immediate remediation is not feasible.
  • Provide technical justification and risk-based explanations to government stakeholders regarding vulnerability disposition decisions.
  • Support vulnerability review boards and release decisions for software entering production environments.

RMF & Compliance
  • Support Risk Management Framework (RMF) activities across development, test, staging, and production environments.
  • Assist with implementation and maintenance of NIST 800-53 security controls.
  • Develop and maintain cybersecurity artifacts required to support system authorization and continuous monitoring activities.
  • Prepare material supporting cybersecurity assessments, authorization reviews, and package updates.
  • Assist with security control assessments and remediation activities associated with authorization findings.

Secure Deployment & Operations
  • Support secure software release processes into IL5 and IL6 production environments.
  • Collaborate with DevSecOps teams to establish compliant deployment methodologies and release procedures.
  • Validate cybersecurity readiness prior to production deployments and major software releases.
  • Review security impacts of infrastructure, software, and configuration changes.
  • Ensure application, container, platform, and infrastructure security requirements are met prior to deployment.

Security Documentation & Readiness Activities
  • Support development and maintenance of cybersecurity documentation including Cybersecurity Strategies (CSS), System Security Plans (SSPs), authorization package artifacts, and supporting cybersecurity documentation.
  • Participate in Cyber Vulnerability Identification (CVI) events, cybersecurity assessments, security audits, and remediation activities.
  • Support Continuity of Operations (COOP) planning, tabletop exercises, incident response activities, and operational readiness events.
  • Assist mission teams in preparing for cybersecurity inspections, compliance reviews, and authorization activities.
  • Coordinate with government cybersecurity organizations to ensure documentation remains current and audit-ready.

Stakeholder Collaboration
  • Interface directly with government cybersecurity personnel, ISSMs, ISSOs, Authorizing Officials, mission owners, and engineering teams.
  • Communicate cybersecurity risks, mitigation options, and deployment recommendations to leadership and operational stakeholders.
  • Support Agile ceremonies, release planning events, architecture reviews, and technical working groups.
  • Provide cybersecurity guidance to software teams on secure coding, vulnerability remediation, and release readiness.

Required:
  • Able to obtain and maintain a DoD Secret clearance
  • Bachelor's degree in engineering, computer science, information systems, cybersecurity or related technical field
  • 7+ years of cybersecurity, information assurance, DevSecOps, system security engineering, or related defense experience
  • Extensive experience implementing and supporting the Risk Management Framework (RMF)
  • Strong understanding of NIST 800-53 security controls and DoD cybersecurity policies
  • Demonstrated experience evaluating, explaining, mitigating, and remediating Common Vulnerabilities and Exposures (CVEs)
  • Experience supporting software deployments within accredited government production environments
  • Strong understanding of IL5 and IL6 cloud environments and associated cybersecurity requirements
  • Experience supporting ATO and continuous monitoring activities
  • Experience working directly with government cybersecurity organizations and mission stakeholders
  • Ability to communicate technical cybersecurity issues to both technical and executive audiences
  • Strong written communication skills supporting cybersecurity documentation, risk acceptance packages, and authorization artifacts

Preferred:
  • Active DoD Secret clearance or higher
  • Master's degree in engineering, computer science, information systems, cybersecurity or related technical field
  • Experience supporting Space Systems Command (SSC), Space Operations Command (SpOC), U.S. Space Force, or other DoD space organizations.
  • Experience supporting operational systems accredited under RMF within classified environments.
  • Familiarity with Platform One, Cloud One, Kubernetes, Iron Bank, Big Bang, and related DoD DevSecOps ecosystems.
  • Experience supporting Authority to Operate (ATO) and Continuous Authorization to Operate (cATO) initiatives.
  • Knowledge of Secure Software Development Framework (SSDF) and modern DevSecOps pipelines.
  • Experience supporting Cybersecurity Strategies (CSS), Cyber Vulnerability Identification (CVI) events, cybersecurity inspections, and COOP tabletop exercises.
  • Experience with STIG implementation, SCAP compliance, ACAS, Nessus, Fortify, SonarQube, Snyk, Prisma Cloud, Twistlock, or similar security tooling.
  • Security certifications such as CISSP, CASP+, Security+, CISM, CCSP, or GIAC certifications.
  • Experience supporting mission-critical systems deployed in classified cloud environments.
  • Experience supporting software modernization efforts within U.S. Space Force programs.
  • Familiarity with SATCOM, space operations, command and control systems, mission planning systems, or enterprise management platforms.
  • Experience implementing Zero Trust architectures within DoD environments.
  • Experience balancing mission delivery timelines with cybersecurity compliance requirements in operational production systems.
  • Experience supporting large-scale software factories or government-managed production environments.
  • Certifications such as CISSP, CompTIA Security+
  • Certifications such as INCOSE CSEP or ESEP

Basic Compensation: $149,000-$186,000 in El Segundo, CA and $136,000-$170,000 in Colorado Springs, CO
The offered rate will be based on the selected candidate's knowledge, skills, abilities and/or experience and in consideration of internal parity.
Ready to Make a Difference? If you're excited about making a significant impact in the field of space defense and working on projects that matter, we encourage you to apply and join our team.
KBR Benefits
KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.
Belong, Connect and Grow at KBR
At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team's philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together.
KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

What KBR employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


KBR logo

About KBR

Sourced by ZipRecruiter

At KBR, we partner with government and industry clients to provide purposeful and comprehensive solutions with an emphasis on efficiency and safety. With a full portfolio of services, proprietary technologies and expertise, our employees are ready to handle projects and missions from planning and design to sustainability and maintenance. Whether at the bottom of the ocean or in outer space, our clients trust us to deliver the impossible on a daily basis.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Houston, TX, US

Year founded

1998