Cybersecurity Assessment Engineer at Second Front Systems
Washington, DC
$125,000–$140,000
Jul 16, 2026
Washington, DC
Jul 21, 2026
What this job asks for AI summary
This role sits within a cloud security team, focused on maintaining the security posture of a government-facing software platform. Day-to-day work involves conducting vulnerability scans and assessments of cloud and containerized environments, managing authorization documentation (SSPs, SAPs, SARs), supporting continuous monitoring, and advising development teams on remediation. It suits candidates with hands-on experience in FedRAMP/RMF frameworks and cloud security across AWS, Azure, or GCP.
Mid level · 3+ years · Remote · Full-time
Pay in the description: $125,000–$140,000
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 4,200 people nationally plausibly meet what this posting asks for (information security analysts). range 2,500–7,500
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The posting lists specific hiring hubs (DC/MD/VA, NC, CO, TX), but the caller has declared this a fully-remote role, so remote=true and no metro is set.
The title carries no seniority level; the 3–5 years requirement and scope (individual contributor, cross-functional collaboration) support a Mid classification.
Secret clearance is explicitly listed as 'preferred', not a hard gate, so the clearance requirement is set to None.
DOD 8570 IAT II certification (e.g., CySA+) is required but must be obtained within 6 months of hire — it is not a pre-hire gate, so it is not listed as a skill.
Anchore, Trivy, and Tenable are listed together as examples of 'automated scanning suites' in the required section; Anchore is used as the primary name with the others as alternatives.
Docker, GitLab, Kubernetes (container scanning context), and scripting (Python/Bash) appear under the 'Preferred' section.
DISA SRGs and CIS Benchmarks are mentioned alongside STIGs in the required section; DISA STIGs is used as the canonical name covering that family of compliance standards.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, NIST SP 800-37.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.