The standard advice I've heard is: Work for defense companies to learn the technology, and then leave to transfer this technology toward peaceful (and often lucrative) applications. Swords into Ploughshares.
Speaking for the U.S. context only: once you have a security clearance, which will become necessary at some point for defence work, it becomes difficult to move out to non-classified work. On one hand, the pool of people with clearances is smaller than the general labor pool, so you can have a higher salary & benefits, therefore it's more attractive to stay at that kind of work. On the other hand, prospective employe…
Doing secure work means you can't take any confidential information with you when you leave, and it might slightly limit what you can talk about, but it doesn't mean you can't say anything about the work you did. You can still talk about your role and skillset, usually about the languages and technologies (and COTS products) used.
Many government IT projects mandate security-cleared developers because the systems touch classified information, but that doesn't mean that the systems themselves (their existence, basic design, etc.) are classified. There's really no difference between having a project like that on your resume, and any other commercial-sector project that's internal use only.
If you're working or considering working on a clearance-required project, it's not unreasonable to ask to talk with the security officer beforehand to clear up exactly what you'll be able to put on your resume and discuss after the fact ... and price yourself accordingly.