Sterling, VA

Salary
$103,800–$218,100from the description
Posted
Jul 6, 2026
Location
Sterling, VA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior-level role leading cybersecurity for a portfolio of Electronic Warfare systems, with responsibility for executing all six steps of the Risk Management Framework (RMF) and guiding systems to Authorization to Operate (ATO). Day-to-day work spans security architecture, vulnerability management, continuous monitoring, incident response, and A&A documentation. The position also involves directly managing a small team of three to five security engineers.

Senior level · 10+ years · National · TS/SCI clearance · Full-time

Must have (17)
RMFNIST 800-64ISSO/ISSE · 10+ yrseMASS or XactaSCAP/SCCNessus or AcasSTIG ViewerNmapIDS/IPSLinuxTCP/IPDNSVPNWAFCISSPICD 503CNSSI 1253

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
Nmap6%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Linux65%RMF40%TCP/IP40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

No specific work location or metro area is stated in the posting; CBSA is left blank. The role involves up to 10% local travel, suggesting a physical office exists but the location is not disclosed.

The degree requirement lists a Bachelor's in a relevant field but explicitly accepts 'equivalent experience' as a substitute, so no minimum degree is flagged as a hard gate.

The role carries meaningful people-management duties (leading a team of 3–5 Security Engineers, performance evaluations, professional development), which creates some ambiguity between an IC-level individual contributor and a people manager (11-3021). However, the posting's primary emphasis is on hands-on technical security engineering and RMF execution, so 15-1212 is the primary classification, with 15-1299 noted as a secondary option given the ISSE/ISSO specialization.

DoD 8570/8140 IASAE Level III is listed as a hard requirement; CISSP is given as the canonical example and is captured as the skill. Other certifications at that level (e.g., CSSLP, ISSEP) would also satisfy this requirement.

Nessus and ACAS are listed together in the posting as interchangeable scanning tools and are captured as a single skill with alternatives.

eMASS and Xacta are listed as interchangeable A&A tracking tools; eMASS is the primary name with Xacta in alternatives.

The posting was truncated mid-sentence in the qualifications section ('Nessus, ACAS, Tenab -'), suggesting additional vulnerability tools (likely Tenable) may have been listed but were cut off.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.

Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗