Data Systems Analysts, Inc. · Fairfax, VA

Salary
$105,000–$115,000
Posted
Jul 14, 2026
Location
Fairfax, VA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior-level role embedded within a team supporting the EPA's agency-wide information security program. Day-to-day work centers on RMF/ATO package reviews, FISMA reporting, POA&M management, and advising agency officials on compliance and risk using GRC tools such as Telos Xacta. Suited to an experienced information security professional with deep knowledge of NIST 800-53 and 800-37 who has held leadership responsibilities.

Senior level · 8+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Full-time

Pay in the description: $105,000–$115,000

Must have (4)
NIST 800-53Xacta, Csam, Rsa Archer or EmassMicrosoft CopilotFISMA
Nice to have (1)
CISSP or Cism

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 920 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 270–1,400

Applicant volume Heavy — This req sits in a large pool with little in its requirements to thin it, and auto-apply tools fire at everything in the occupation. Applying early and leading with the rare skills below is what gets read.

What won't set you apart
NIST 800-5340%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The JD requires a Bachelor's degree in IT or a related field AND 8 years of IA experience, but allows substituting a security certification (e.g., CISSP) for up to 2 of those years — the degree itself is still a hard requirement.

Clearance: the role requires the ability to obtain a Public Trust (not a classified clearance), so the clearance requirement is set to None. The posting notes that many DSA positions require a clearance, but this specific role only gates on Public Trust eligibility.

The GRC tool requirement names Xacta as the primary tool in use, with CSAM, RSA Archer, and eMASS listed as acceptable equivalents — all captured as alternatives.

Microsoft Copilot is stated as a company-wide expectation for all hires ('All hired employees are expected to have experience with…'), making it a hard gate despite appearing outside the formal qualifications section.

POA&M management appears as a named, specific responsibility with direct ownership language ('Managing InfoSec Program POA&Ms') in the required responsibilities — retained as a concrete, named InfoSec artifact/process rather than a generic soft skill.

CISSP and CISM appear under Desired Qualifications and are therefore preferred. Note that CISSP is also referenced in Required Qualifications as a possible experience substitute, but only as an optional trade-off, not a standalone gate.

NIST 800-53 Rev 5 knowledge is listed under Desired Qualifications; Rev 4 is the hard-required version.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST 800-37 RMF, POA&M management, NIST 800-53 Rev 5.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗