Infrastructure Security Engineer at JBG SMITH
Bethesda, MD
$130,000–$160,000from the description
Jul 20, 2026
Bethesda, MD
Jul 22, 2026
What this job asks for AI summary
A hands-on engineering role responsible for designing, deploying, and operating cloud, network, and identity infrastructure — spanning Azure and AWS environments, on-premises systems, and enterprise security tooling — for a real estate company. The position covers everything from network architecture and identity management to incident response, scripting, and security hardening, and suits an engineer with broad full-stack infrastructure experience who also brings meaningful security depth.
Senior level · Washington-Arlington-Alexandria, DC-VA-MD-WV · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 35 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 7–65
Applicant volume Light — Few people clear these requirements, so an application that does clear them gets looked at. Worth applying to even if you miss a nice-to-have.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $152,225 (middle half $125,286–$177,673). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
This role sits at the intersection of infrastructure engineering and security — it builds and operates cloud, network, and identity infrastructure (pointing toward 15-1244) while also owning the security posture end-to-end (pointing toward 15-1212). The posting explicitly frames it as a security engineering role and emphasizes security depth, so 15-1212 is the primary classification, with 15-1244 as a close runner-up.
A Bachelor's degree in Computer Science, IT, or a related field is listed as required, but the posting immediately adds 'or equivalent experience' and repeats that caveat at the end ('any equivalent combination of education, training, and/or experience'), so no formal degree is treated as a hard gate.
Python, PowerShell, and Bash are listed together as scripting/automation tools in the responsibilities section rather than a formal requirements block. They are captured as a single skill (Python as primary, PowerShell and Bash as alternatives) reflecting the 'such as' framing — any one of the three would satisfy the requirement.
Splunk and CrowdStrike are listed together as SIEM examples ('SIEM (Splunk, CrowdStrike)') in the requirements block; they are treated as alternatives for the same SIEM requirement rather than two independent hard gates.
Palo Alto, Meraki, Cisco, and Ruckus are listed together as firewall/network examples. Palo Alto is used as the primary name with the others as alternatives, reflecting that the requirement is for firewall/network security platform experience generally.
PKI, NDES, PIM, Kerberos, VoIP, Ruckus, and WVD appear in the identity/infrastructure technology list within the responsibilities narrative rather than a distinct requirements section, so they are marked as preferred.
No total years of experience are explicitly stated in the posting.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.