Falls Church, VA

Salary
Posted
Jul 12, 2026
Location
Falls Church, VA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior cybersecurity role embedded within a federal Department of Justice program, responsible for leading day-to-day security operations, incident response, vulnerability management, and insider threat monitoring. The position also carries team leadership duties — supervising contractors, advising government stakeholders, and maintaining compliance with federal frameworks such as NIST and FISMA. Best suited to an experienced federal cybersecurity practitioner comfortable operating at both a technical and strategic level.

Senior level · 5+ years · National

Must have (10)
SIEM, Splunk, Microsoft Sentinel, Qradar or ElasticSOAREDRIDS/IPSTenable or BigfixThreat intelligence platformsDigital forensicsThreat huntingNIST Cybersecurity FrameworkFISMA
Nice to have (2)
CISSP, Cism, Gcih, Cysa+, Security+, Ceh or Casp+Azure, AWS or Microsoft 365

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
SIEM55%EDR40%NIST Cybersecurity Framework40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (10)

Location is not specified in the posting — the role supports a federal DOJ customer, likely in the Washington, DC area, but no city or metro is stated. CBSA left blank.

The degree requirement states a Bachelor's in a relevant field but explicitly allows substitution with 'relevant professional experience' — treated as no hard degree gate.

The role carries significant team leadership and supervisory duties (supervising personnel, managing deliverables, executive briefings), which creates genuine ambiguity between an IC security analyst (15-1212) and a people-manager (11-3021). The primary day-to-day work described is hands-on cybersecurity operations and incident response, so 15-1212 is the primary code, with 11-3021 as the runner-up.

The 'Required Technical Experience' section lists skills as 'one or more of the following' — this is a broad list where any combination qualifies. SIEM, SOAR, EDR, IDS/IPS, vulnerability management tools, threat intelligence, malware analysis, digital forensics, and threat hunting are all listed under this required block and are marked as hard gates accordingly, consistent with the section's placement.

Certifications (CISSP, CISM, GCIH, CySA+, Security+, CEH, CASP+) appear under 'Preferred Qualifications' and are listed as 'highly desired' — not hard gates.

Cloud security experience (Azure, AWS, Microsoft 365) appears under 'Preferred Qualifications' only.

A DOJ Public Trust is required (ability to obtain and maintain), but this is not a national security clearance — it is a suitability/fitness determination. Clearance field is set to None accordingly.

U.S. Citizenship is a hard requirement per the posting.

The 5-year total experience minimum is at the role level (federal cybersecurity); the 3-year sub-requirement for SOC/incident response/vulnerability management/threat hunting is a domain-specific gate within that overall requirement.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Malware analysis.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗