Cyber Security Engineer at Bowman
Reston, VA
$96,000–$123,000from the description
Jul 13, 2026
Reston, VA
Jul 21, 2026
What this job asks for AI summary
A hands-on security engineering role focused on protecting an organization's networks, cloud environments, and information systems. Day-to-day work spans designing and managing enterprise security controls, monitoring and responding to threats, conducting vulnerability assessments, and supporting cloud security in Microsoft Azure and M365. Suits an experienced security professional comfortable with tools like SIEM platforms, endpoint protection, and IAM, who can also automate processes and guide less senior colleagues.
Senior level · 5+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 530 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 390–680
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $152,225 (middle half $125,286–$177,673). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The posting is located in Virginia but does not specify a city; the Washington-Arlington-Alexandria DC-VA-MD-WV CBSA is the most likely match given Bowman's Virginia headquarters, but the exact metro is unconfirmed.
A Bachelor's degree is listed as a requirement but explicitly accepts 'equivalent experience' as a substitute, so no minimum degree is flagged as a hard gate.
PowerShell and Python are listed together as scripting language examples ('such as PowerShell or Python') under the qualifications section; PowerShell is named as the primary with Python as an alternative.
Microsoft Defender, Microsoft Sentinel, CrowdStrike, and Splunk are listed together under a 'tools such as… or similar platforms' framing in the qualifications section — treated as a single preferred skill group with Sentinel, CrowdStrike, and Splunk as alternatives.
Security automation and orchestration is explicitly called 'a plus' in the posting, so it is flagged as preferred.
Certifications (CISSP, Security+, CySA+, GSEC, GIAC, Microsoft Security) and security frameworks (NIST, CIS Controls, ISO 27001) are listed under 'Preferred certifications' and 'Familiarity with' respectively, so both are flagged as preferred.
Microsoft Azure is listed under preferred/supporting experience ('particularly Microsoft Azure') rather than as a hard gate, despite cloud security being required generally.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): SOC operations, security automation.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.