1

Infosec Jobs (NOW HIRING)

Staff Embedded InfoSec Engineer Primary: Bay Area (San Francisco/Peninsula) | Secondary: NYC About Us Beast Industries is a multifaceted media and entertainment company founded by Jimmy Donaldson ...

Responsibilities The Systems Engineer will support the Sponsor's organization as a critical member of the team in an INFOSEC engineering role. The candidate will be responsible for a wide range of ...

Showing results 41-60

Infosec information

See salary details

$43

$74

$110

How much do infosec jobs pay per hour?

As of Aug 20, 2026, the average hourly pay for infosec in the United States is $74.30, according to ZipRecruiter salary data. Most workers in this role earn between $50.24 and $93.27 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an information security (infosec) professional, and why are they important?

Infosec, short for information security, refers to the practices, policies, and technologies used to protect digital and physical information from unauthorized access, disclosure, alteration, and destruction. Professionals in infosec work to secure computer systems, networks, and data from threats such as hackers, malware, and data breaches. Their responsibilities include risk assessment, implementing security measures, monitoring for suspicious activity, and ensuring compliance with relevant laws and regulations. Infosec is a critical field in today's digital world, as organizations increasingly rely on secure information to operate effectively.

What are the key skills and qualifications needed to thrive as an information security (infosec) professional, and why are they important?

InfoSec, a shortening of information security, is a set of practices carried out by information and cybersecurity specialists designed to prevent hacking or unauthorized access to private information and data, databases, or services. Your responsibilities are to design or improve systems built to protect sensitive information, such as electronic health records, industry or trade secrets like proprietary code or industrial designs, or national security information. Although much contemporary InfoSec revolves around protecting digital information, there are still large amounts of physical information that must be protected from unauthorized access.

What are some common challenges faced by infosec professionals when working with cross-functional teams?

Infosec professionals often collaborate with various departments, such as IT, legal, and business units, to ensure the organization’s security policies are followed. One common challenge is communicating technical risks in a way that non-technical colleagues can understand and act upon. Additionally, balancing security requirements with operational needs can lead to difficult compromises, as different teams may have conflicting priorities. Building strong relationships and fostering a culture of security awareness are key strategies for overcoming these challenges.

What is the difference between Infosec vs Cybersecurity Analyst?

AspectInfosecCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentOrganizations' security teams, IT departmentsSecurity operations centers, IT security teams
Industry UsageBroad, including government, finance, healthcarePrimarily tech, finance, and government sectors
Job FocusOverall security policies, risk managementMonitoring, incident response, vulnerability assessment

Infosec (Information Security) is a broad field encompassing policies, risk management, and overall security strategy. A Cybersecurity Analyst typically focuses on monitoring systems, responding to threats, and vulnerability management within the broader Infosec framework. While both roles require similar certifications and work in security teams, Infosec professionals often handle strategic planning, whereas Cybersecurity Analysts are more operational.

What cities are hiring for Infosec jobs?

Cities with the most Infosec job openings:

What states have the most Infosec jobs?

States with the most job openings for Infosec jobs include:

Infographic showing various Infosec job openings in the United States as of August 2026, with employment types broken down into 84% Full Time, 13% Part Time, and 3% Contract. Highlights an 67% Physical, 24% Hybrid, and 9% Remote job distribution, with an average salary of $154,554 per year, or $74.3 per hour.

IT Cybersecurity Specialist (INFOSEC) - Arlington, VA

MSCCN

Arlington, VA • On-site

Full-time

Posted 9 days ago


Job description


ATTENTION MILITARY AFFILIATED JOB SEEKERS - Our organization works with partner companies to source qualified talent for their open roles. The following position is available to Veterans, Transitioning Military, National Guard and Reserve Members, Military Spouses, Wounded Warriors, and their Caregivers. If you have the required skill set, education requirements, and experience, please click the submit button and follow the next steps. All positions are onsite, unless otherwise stated.
IT Cybersecurity Specialist (INFOSEC) (Cyber Exercise Planner)
Series/Grade: GS-2210-13
Cybersecurity and Infrastructure Security Agency Infrastructure Security Division
Location: Arlington, VA
Clearance: Must be able to attain/maintain a Top Secret / Sensitive Compartmented Information
Who May Apply:
  • Veterans with a 30% or more service-connected disability rating
  • Individuals eligible under Schedule A (5 CFR 213.3102(u))

Travel: Up to 25%
Summary:
This position is located in the Cybersecurity and Infrastructure Security Agency (CISA), Infrastructure Security Division (ISD). CISA is the Nation's risk advisor, working with partners across government and industry to defend against today's threats and build more secure and resilient infrastructure.
The incumbent serves as an IT Cybersecurity Specialist (INFOSEC) supporting national cybersecurity exercise programs. The position contributes to CISA's efforts to build national capacity and capabilities to enhance the security and resilience of critical infrastructure through the planning, design, development, conduct, and evaluation of cybersecurity exercises.
The position requires advanced cybersecurity knowledge, experience applying Homeland Security Exercise and Evaluation Program (HSEEP) principles, and the ability to work with federal, state, local, tribal, territorial, private sector, and international partners.
Major Duties:
As an IT Cybersecurity Specialist (INFOSEC), GS-2210-13, you will:
  • Design, develop, and conduct cybersecurity exercises in accordance with the Homeland Security Exercise and Evaluation Program (HSEEP).
  • Plan and execute discussion-based and operations-based exercises, including seminars, workshops, games, drills, tabletop exercises, functional exercises, and full-scale exercises.
  • Lead diverse, multidisciplinary intra-agency and interagency groups to design, develop, deliver, and evaluate cybersecurity exercises.
  • Provide subject-matter expertise to guide exercise design and delivery, including control, facilitation, and evaluation of exercises.
  • Develop and maintain exercise support products and services, including CISA Tabletop Exercise Packages and related cybersecurity exercise tools.
  • Develop cybersecurity scenarios based on current and emerging technology, adversary tactics, techniques, and procedures, and stakeholder exercise objectives.
  • Conduct interactive training and exercise events to create effective learning environments for technical and non-technical audiences.
  • Collaborate with critical infrastructure owners and operators, IT security experts, emergency management officials, and government partners to support cybersecurity objectives.
  • Raise awareness and improve coordination with federal, SLTT, private sector, and international partners on gaps in cyber management practices and recommended process improvements.
  • Promote collaborative efforts to reduce risk and threats to critical information, enterprise, communications, and control systems.
  • Build and support regional and local cybersecurity partnerships, coalitions, and information-sharing efforts.
  • Promote awareness of cyber policy, strategy, and CISA cybersecurity capabilities among government and private sector partners.
  • Assess stakeholder needs, conduct gap analyses, and assist in defining requirements for cybersecurity exercise programs and products.
  • Publish after-action reviews and present technical findings, observations, and recommendations to technical and non-technical audiences.
  • Communicate key exercise findings to senior leadership.
  • Prepare decision papers, reports, analyses, memos, speeches, talking points, briefings, and correspondence for senior federal, departmental, and agency leadership.
  • Respond to inquiries and requests for information from higher headquarters, other federal agencies, Congress, the media, state and local governments, and the private sector, coordinating responses as appropriate.
  • Serve as a technical advisor on program effectiveness, efficiency, policy, direction, and cybersecurity exercise implementation.
  • Resolve complex issues involving organizations and stakeholders with differing or competing interests.

How You Will Be Evaluated:
  • Applicants should ensure their resumes clearly address:
  • Cybersecurity exercise planning, design, conduct, facilitation, or evaluation.
  • HSEEP principles and exercise methodology.
  • Cybersecurity or critical infrastructure risk and resilience.
  • Stakeholder coordination across government and private sector partners.
  • Development of after-action reports, briefings, decision papers, or technical materials.
  • Ability to present technical cybersecurity information to non-technical audiences.
  • Experience leading or coordinating multidisciplinary teams or working groups.
  • Experience identifying gaps and recommending process, policy, or program improvements.

Additional Information
Resume MUST Include:
  • Hours worked per week for each role (i.e. 40hrs/week)
  • Month and year start/end date for every role.
  • Do NOT include photographs or social media links (e.g., LinkedIn)

Required Experience
Qualifications:
  • Applicants must meet the GS-2210 Information Technology Management qualification requirements and specialized experience requirements for the GS-13 grade level.
GS-2210 Competency Requirements:
Applicants must demonstrate proficiency in the following competencies at the level required for GS-13 positions:
  • Attention to Detail
  • Customer Service
  • Decision Making
  • Information Management
  • Interpersonal Skills
  • Oral Communication
  • Problem Solving
  • Teamwork
  • Technical Competence
Competencies:
Applicants may be evaluated on the following competencies:
  • **Technical Competence:** Applies cybersecurity, infrastructure security, and exercise-planning knowledge to design, deliver, and evaluate cybersecurity exercises.
  • **Information Management:** Gathers, organizes, analyzes, and presents cybersecurity exercise information, stakeholder input, after-action findings, and program data.
  • **Problem Solving:** Identifies cybersecurity capability gaps, exercise design challenges, stakeholder coordination issues, and process improvement opportunities.
  • **Oral Communication:** Presents cybersecurity exercise content, findings, and recommendations to technical and non-technical audiences, including senior leaders and external partners.
  • **Attention to Detail:** Prepares accurate exercise products, after-action reviews, reports, briefings, and technical materials.
  • **Interpersonal Skills:** Builds and maintains effective working relationships with federal, SLTT, private sector, international, and internal CISA stakeholders.
  • **Customer Service:** Works with partners and stakeholders to assess needs, provide guidance, resolve issues, and support cybersecurity exercise objectives.
  • **Decision Making:** Makes sound recommendations on exercise design, stakeholder engagement, resource needs, program priorities, and corrective actions.
  • **Teamwork:** Leads or contributes to multidisciplinary groups supporting cybersecurity exercise planning, delivery, and evaluation.

Preferred Experience
For GS-13 and above, Information Management, Problem Solving, and Technical Competence generally require advanced proficiency.
Specialized Experience:
To qualify for the GS-13 grade level, applicants must demonstrate at least one year of specialized experience equivalent to the GS-12 grade level in the federal service, or equivalent public or private sector experience, performing work directly related to cybersecurity exercise planning, cybersecurity training, critical infrastructure security, or cybersecurity program coordination.
Specialized experience must include experience performing duties such as:
  • Contributing to efforts to build national, regional, or organizational cybersecurity capacity and resilience through the planning and conduct of cybersecurity exercise programs in accordance with HSEEP principles.
  • Leading or coordinating diverse, multidisciplinary groups to design, develop, deliver, or evaluate cybersecurity exercises.
  • Providing subject-matter expertise to guide exercise design, control, facilitation, execution, or evaluation.
  • Raising awareness and improving coordination with federal, state, local, tribal, territorial, private sector, or international partners on cybersecurity risk, cyber management practices, exercise findings, or recommended process improvements.
  • Developing, conducting, or supporting discussion-based or operations-based cybersecurity exercises, such as seminars, workshops, games, drills, tabletop exercises, functional exercises, or full-scale exercises.
  • Preparing after-action reviews, technical reports, decision papers, briefings, talking points, or senior-leader communications related to cybersecurity exercises, cyber risk, or infrastructure resilience.
  • Collaborating with critical infrastructure owners and operators, cybersecurity professionals, emergency management officials, or government partners to support organizational cybersecurity objectives.
  • Identifying capability gaps and recommending improvements to cybersecurity plans, policies, procedures, exercise products, or stakeholder coordination processes.
Experience should demonstrate advanced knowledge of cybersecurity and infrastructure security concepts, principles, and operations; the ability to solve complex cybersecurity or infrastructure security challenges; and the ability to communicate technical information to technical and non-technical audiences.