Senior Information Security Analyst
Data Systems Analysts, Inc. · Fairfax, VA
$105,000–$115,000
Jul 14, 2026
Fairfax, VA
Jul 21, 2026
What this job asks for AI summary
A senior-level role embedded within a team supporting the EPA's agency-wide information security program. Day-to-day work centers on RMF/ATO package reviews, FISMA reporting, POA&M management, and advising agency officials on compliance and risk using GRC tools such as Telos Xacta. Suited to an experienced information security professional with deep knowledge of NIST 800-53 and 800-37 who has held leadership responsibilities.
Senior level · 8+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Full-time
Pay in the description: $105,000–$115,000
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 920 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 270–1,400
Applicant volume Heavy — This req sits in a large pool with little in its requirements to thin it, and auto-apply tools fire at everything in the occupation. Applying early and leading with the rare skills below is what gets read.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $152,225 (middle half $125,286–$177,673). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The JD requires a Bachelor's degree in IT or a related field AND 8 years of IA experience, but allows substituting a security certification (e.g., CISSP) for up to 2 of those years — the degree itself is still a hard requirement.
Clearance: the role requires the ability to obtain a Public Trust (not a classified clearance), so the clearance requirement is set to None. The posting notes that many DSA positions require a clearance, but this specific role only gates on Public Trust eligibility.
The GRC tool requirement names Xacta as the primary tool in use, with CSAM, RSA Archer, and eMASS listed as acceptable equivalents — all captured as alternatives.
Microsoft Copilot is stated as a company-wide expectation for all hires ('All hired employees are expected to have experience with…'), making it a hard gate despite appearing outside the formal qualifications section.
POA&M management appears as a named, specific responsibility with direct ownership language ('Managing InfoSec Program POA&Ms') in the required responsibilities — retained as a concrete, named InfoSec artifact/process rather than a generic soft skill.
CISSP and CISM appear under Desired Qualifications and are therefore preferred. Note that CISSP is also referenced in Required Qualifications as a possible experience substitute, but only as an optional trade-off, not a standalone gate.
NIST 800-53 Rev 5 knowledge is listed under Desired Qualifications; Rev 4 is the hard-required version.
Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST 800-37 RMF, POA&M management, NIST 800-53 Rev 5.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.