Information Systems Security Engineer (ISSE) at Peraton
Herndon, VA
$135,000–$216,000from the description
Jul 23, 2026
Herndon, VA
Jul 24, 2026
What this job asks for AI summary
A senior security engineering role on a defense intelligence contract, focused on designing and maintaining security architectures for complex networked systems under the Risk Management Framework. Day-to-day work spans SIEM log analysis, vulnerability scanning, STIG compliance, continuous monitoring, and supporting authorization processes. Suits an experienced cybersecurity engineer with a clearance, strong Linux background, and familiarity with DoD security tooling and DevSecOps practices.
Senior level · 10+ years · TS/SCI clearance · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (11)
The role title is 'Information System Security Engineer (ISSE)' with no seniority level in the title; the title states no level. The 10+ years of experience requirement (or 8+ with a Master's) supports a Senior classification.
The degree requirement accepts 4 additional years of relevant experience in lieu of a degree, so no minimum degree is hard-gated.
An active polygraph (or ability to obtain one) is explicitly required alongside TS/SCI, which is captured under TopSecretSci clearance.
ACAS is mentioned in the core functions section ('Review ACAS scan results') as a primary tool; it is treated as required given the role's explicit security engineering responsibilities.
DoD 8570 IAT/IAM Level II certification is listed as required; Security+ is given as an example certification that satisfies it and is placed in alternatives.
AWS and Google Cloud are listed together under Desired Qualifications as interchangeable cloud platform experience; AWS is the primary name with Google Cloud as an alternative.
CloudTrail, CloudWatch, OpenShift, and Ansible all appear under Desired Qualifications (note: 'Antible' in the posting is a clear misspelling of Ansible).
No work location (city/state) is specified in the posting beyond the requirement to work full-time in a SCIF; CBSA is left blank.
The role is classified as 15-1212 (Information Security Analysts) rather than a developer SOC because the primary day-to-day work is security analysis, RMF/A&A, SIEM monitoring, vulnerability assessment, STIG compliance, and risk assessment — not building software. 15-1299 is noted as a runner-up given the 'security engineer' framing and some design/architecture duties.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): DoD 8570 IAT/IAM Level II.
Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.