Washington, DC

Salary
$127,500–$251,100from the description
Posted
Jul 3, 2026
Location
Washington, DC
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior-level role focused on building and maintaining secure software across enterprise environments, primarily for US Treasury systems. Day-to-day work involves integrating security testing tools into CI/CD pipelines, developing APIs and automation frameworks, conducting secure code reviews, and extending secure development practices into AI/ML contexts. Suited to experienced software developers with a strong background in DevSecOps and application security.

Senior level · 9+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Full-time

Must have (4)
SAST or DastCI/CDvulnerability remediationSecurity+
Nice to have (3)
AWS API GatewayAI/ML securityDevSecOps

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 320 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 130–470

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
CI/CD45%Security+45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

This role sits at the intersection of security and software engineering — the primary day-to-day work is secure application development and security tooling integration (SAST/DAST/SCA, CI/CD hardening, API builds), which leans toward 15-1252 Software Developers; however, the explicit cybersecurity framing, vulnerability remediation, and secure coding standards focus make 15-1212 Information Security Analysts a reasonable primary classification. Both codes are plausible.

The job title is 'Lead Security Developer' / 'IS Security Developer III' with no standard seniority modifier, so advertised seniority is Unspecified. The 9+ years requirement and enterprise-level scope support a Senior classification.

SAST, DAST, and SCA are listed together as a single integrated application security testing requirement; DAST and SCA are captured as alternatives since the JD treats them as a combined capability.

AWS API Gateway appears in the 'Skills' tag block at the bottom of the posting (a CGI system-generated tag section), not in the formal requirements or desired qualifications sections — treated as preferred/context rather than a hard gate.

AI/ML security patterns and DevSecOps automation appear under 'Desired qualifications/non essential skills required' — explicitly non-essential, so marked preferred.

The posting lists Fairfax VA, Lafayette LA, and Knoxville TN as office locations with a hybrid model acceptable; it is not fully remote. The primary CBSA is Washington-Arlington-Alexandria (Fairfax VA) as the first-listed location. The position ID lists Washington DC as the main location.

Background investigation is mentioned as a condition of employment, but no specific US security clearance level is required or gated on.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secure software development, API development.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗