Cybersecurity Engineer at D2 Technical Services
Springfield, VA
$130,000–$140,000from the description
Jul 16, 2026
Springfield, VA
Jul 21, 2026
What this job asks for AI summary
A hands-on cybersecurity engineering role supporting an intelligence community customer, focused on hardening and maintaining enterprise infrastructure spanning Windows, Linux, network, virtualization, and cloud environments. Day-to-day work centers on implementing STIGs, managing POA&Ms, executing RMF continuous monitoring, remediating vulnerabilities, and operating security tools such as ACAS, HBSS, Carbon Black, and Tanium. An active TS/SCI clearance is required, and the role suits experienced security engineers with a strong RMF and NIST SP 800-53 background.
Senior level · 5+ years · St. Louis, MO · TS/SCI clearance · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 3 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $108,760 (middle half $84,815–$135,424). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role is dual-located in Springfield, VA and Arnold, MO. Springfield, VA falls within the Washington-Arlington-Alexandria, DC-VA-MD-WV CBSA (47900); Arnold, MO falls within the St. Louis, MO-IL CBSA (41180). Both are listed as valid work sites; the St. Louis metro is reported here as the less common of the two — hiring managers should note the DC-metro location (Springfield, VA) may be the primary site.
A Bachelor's degree is listed as required but the posting explicitly accepts 'the equivalent combination of education, professional training or work experience,' so the degree requirement is set to None.
ACAS, HBSS, Carbon Black, Tanium, and RedSeal are listed in the required section as 'such as … or equivalent,' meaning the capability is a hard gate but the specific tool is interchangeable; they are marked required accordingly.
The role has a significant O&S/infrastructure operations component (firewalls, IDS/IPS, network perimeter hardening), which creates genuine ambiguity with 15-1244 (Network and Computer Systems Administrators); however, the primary framing is cybersecurity compliance, RMF, and vulnerability management, making 15-1212 the better fit.
DoD 8570/8140 certifications (Security+, CISSP, CAP, CASP+) appear under the Desired/preferred section and are marked accordingly.
NGA TESR environment experience and IC A&A process experience are listed as desired/preferred but are too domain-specific to surface as named technology skills.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, DoD 8570/8140 certifications.
Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.