McLean, VA

Salary
$104,800–$192,200from the description
Posted
Jul 13, 2026
Location
McLean, VA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior cybersecurity consulting role focused on guiding federal government clients through the full NIST Risk Management Framework lifecycle — from system categorization and control selection through assessment, authorization, and continuous monitoring. Day-to-day work involves conducting security assessments, developing system security plans, supporting supply chain and third-party risk management, and mentoring junior staff. Suits candidates with hands-on federal RMF experience who can operate across both technical and advisory capacities.

Senior level · 3+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Secret clearance · Full-time

Must have (6)
NIST RMFFIPS 199FIPS 200NIST CSFCMMCFISMA
Nice to have (2)
eMASS, Csam or XactaArcher GRC, Snow Irm, Risklens or Azure Security Center

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
CMMC2%

Rare in this occupation — lead with these, and say what you built with them.

What the occupation pays Median $152,225 (middle half $125,286–$177,673). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The role is explicitly titled 'Senior' and the JD confirms this framing ('The Senior provides cybersecurity troubleshooting…'), so advertised seniority is Senior. The 3+ years minimum experience requirement is lower than typical for a Senior, but the scope — overseeing junior staff, co-leading engagements, client-facing delivery — supports the Senior band.

Location is not pinned to a single city; EY GPS roles of this type are predominantly DC-area/federal market. The posting notes travel 20–30%+ and work at client/EY/contractor sites. The New York and California salary ranges are listed as secondary alternatives, so DC metro is used as the primary CBSA.

The clearance requirement is stated as 'must be able to obtain and maintain a Secret-level clearance or higher' — this is a hard gate on clearance eligibility, classified as Secret (the minimum stated).

The Federal RMF tool options (eMASS, CSAM, Xacta) and GRC platform options (SNOW IRM, Archer GRC, RiskLens, Azure Security Center) appear under the 'experience in one or more of the following areas' block, which is a menu of qualifying experience paths rather than a requirement for all listed tools. They are marked as preferred accordingly.

Consulting experience is listed under the 'Ideally, you'll also have' section and is therefore preferred.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, NIST SP 800-37, NIST SP 800-161.

Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗