Arlo Solutions LLC · Arlington, VA

Salary
Posted
Jul 13, 2026
Location
Arlington, VA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior cybersecurity role embedded with a DoD acquisition office at the Pentagon and Alexandria, Virginia, managing the full Risk Management Framework lifecycle across multiple classified and CUI information systems. Day-to-day work centers on maintaining authorization packages, overseeing continuous monitoring and vulnerability management, coordinating assessments with government stakeholders, and advising senior leadership on cybersecurity risk. Suits a seasoned DoD cybersecurity professional with deep RMF and A&A experience.

Senior level · 8+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Top Secret clearance

Must have (4)
DoD Risk Management Framework (RMF) · 5+ yrsAssessment & Authorization (A&A) · 5+ yrsContinuous Monitoring (ConMon)System Security Plans (SSPs)
Nice to have (9)
CISSP, Cism, Casp+ or CcspeMASS or XactaACASSTIG complianceVulnerability managementFedRAMPWindowsLinuxCloud security

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
DoD Risk Management Framework (RMF)40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The clearance requirement is 'Active Top Secret' as a hard gate; SCI eligibility is listed as preferred, not required — the clearance is mapped to TopSecret accordingly.

The degree requirement is listed as 'Bachelor's degree … or equivalent experience', so no formal degree is hard-gated.

Total years minimum is set to 8 (the overall DoD cybersecurity experience gate); the 5-year RMF/A&A requirement is captured on those specific skills.

Certifications (CISSP, CISM, CASP+, CCSP) appear under a 'Preferred certifications' heading and are not hard gates; CISSP is listed as the primary with the others as alternatives since they are presented as a peer group.

All technical tools and platforms (eMASS/Xacta, ACAS, STIG, ZTA, FedRAMP, Windows, Linux, cloud) appear under the 'Desired Qualifications' section and are therefore preferred, not required.

The title uses 'ISSO' (Information System Security Officer) but the responsibilities describe ISSM-level duties (managing multiple systems, briefing senior leadership, leading full RMF lifecycle) — the role is squarely within the Information Security Analysts occupation regardless of the title distinction.

No compensation figures are provided in the posting.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): POA&M management, Zero Trust Architecture.

Requires a Top Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗