Senior Cybersecurity Engineer - RMF/ISSE Lead at CACI International
Sterling, VA
$103,800–$218,100from the description
Jul 6, 2026
Sterling, VA
Jul 21, 2026
What this job asks for AI summary
A senior-level role leading cybersecurity for a portfolio of Electronic Warfare systems, with responsibility for executing all six steps of the Risk Management Framework (RMF) and guiding systems to Authorization to Operate (ATO). Day-to-day work spans security architecture, vulnerability management, continuous monitoring, incident response, and A&A documentation. The position also involves directly managing a small team of three to five security engineers.
Senior level · 10+ years · National · TS/SCI clearance · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
No specific work location or metro area is stated in the posting; CBSA is left blank. The role involves up to 10% local travel, suggesting a physical office exists but the location is not disclosed.
The degree requirement lists a Bachelor's in a relevant field but explicitly accepts 'equivalent experience' as a substitute, so no minimum degree is flagged as a hard gate.
The role carries meaningful people-management duties (leading a team of 3–5 Security Engineers, performance evaluations, professional development), which creates some ambiguity between an IC-level individual contributor and a people manager (11-3021). However, the posting's primary emphasis is on hands-on technical security engineering and RMF execution, so 15-1212 is the primary classification, with 15-1299 noted as a secondary option given the ISSE/ISSO specialization.
DoD 8570/8140 IASAE Level III is listed as a hard requirement; CISSP is given as the canonical example and is captured as the skill. Other certifications at that level (e.g., CSSLP, ISSEP) would also satisfy this requirement.
Nessus and ACAS are listed together in the posting as interchangeable scanning tools and are captured as a single skill with alternatives.
eMASS and Xacta are listed as interchangeable A&A tracking tools; eMASS is the primary name with Xacta in alternatives.
The posting was truncated mid-sentence in the qualifications section ('Nessus, ACAS, Tenab -'), suggesting additional vulnerability tools (likely Tenable) may have been listed but were cut off.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.
Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.