Washington, DCremote

Salary
$125,000–$140,000
Posted
Jul 16, 2026
Location
Washington, DC
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

This role sits within a cloud security team, focused on maintaining the security posture of a government-facing software platform. Day-to-day work involves conducting vulnerability scans and assessments of cloud and containerized environments, managing authorization documentation (SSPs, SAPs, SARs), supporting continuous monitoring, and advising development teams on remediation. It suits candidates with hands-on experience in FedRAMP/RMF frameworks and cloud security across AWS, Azure, or GCP.

Mid level · 3+ years · Remote · Full-time

Pay in the description: $125,000–$140,000

Must have (5)
AWS, Azure or GCPKubernetesFedRAMPDISA STIGsAnchore, Trivy or Nessus
Nice to have (3)
DockerGitLabPython or Shell Scripting

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 4,200 people nationally plausibly meet what this posting asks for (information security analysts). range 2,500–7,500

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The posting lists specific hiring hubs (DC/MD/VA, NC, CO, TX), but the caller has declared this a fully-remote role, so remote=true and no metro is set.

The title carries no seniority level; the 3–5 years requirement and scope (individual contributor, cross-functional collaboration) support a Mid classification.

Secret clearance is explicitly listed as 'preferred', not a hard gate, so the clearance requirement is set to None.

DOD 8570 IAT II certification (e.g., CySA+) is required but must be obtained within 6 months of hire — it is not a pre-hire gate, so it is not listed as a skill.

Anchore, Trivy, and Tenable are listed together as examples of 'automated scanning suites' in the required section; Anchore is used as the primary name with the others as alternatives.

Docker, GitLab, Kubernetes (container scanning context), and scripting (Python/Bash) appear under the 'Preferred' section.

DISA SRGs and CIS Benchmarks are mentioned alongside STIGs in the required section; DISA STIGs is used as the canonical name covering that family of compliance standards.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, NIST SP 800-37.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗