Cybersecurity Lead Incident Response Coordinator at Nationwide IT Services
Alexandria, VA
—
Jul 23, 2026
Alexandria, VA
Jul 25, 2026
What this job asks for AI summary
A senior cybersecurity role embedded full-time at a federal immigration review office, split roughly 70/30 between hands-on technical work and program management. On the technical side, the position leads incident response through the full lifecycle, oversees enterprise vulnerability management, and performs threat and security event analysis. On the management side, it supervises the contractor team, liaises with government leadership, and ensures deliverables and compliance activities stay on track. Suits experienced federal cybersecurity practitioners comfortable operating at both a technical and supervisory level.
Senior level · 3+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Full-time
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 820 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 620–1,050
Applicant volume Heavy — This req sits in a large pool with little in its requirements to thin it, and auto-apply tools fire at everything in the occupation. Applying early and leading with the rare skills below is what gets read.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $152,225 (middle half $125,286–$177,673).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (5)
The role is explicitly described as ~70% technical cybersecurity / ~30% program management and on-site supervision, making it a genuine hybrid. It is classified as 15-1212 (Information Security Analysts) because the primary day-to-day work is security analysis, incident response, and vulnerability management; 11-3021 (Computer and Information Systems Managers) is the runner-up given the PM/supervisor framing.
The clearance requirement is a DOJ Public Trust — this is a suitability/background investigation, not a national-security clearance (Confidential/Secret/TS), so the clearance requirement is set to None. Candidates must be U.S. citizens and able to obtain and maintain the Public Trust.
Experience range is stated as '3–10 years of cyber incident-response experience'; the overall years minimum is set to 3 (the stated minimum). The wide range likely reflects flexibility in the level of candidate the client will accept.
Splunk appears in both the Required Qualifications section (as an enterprise SIEM/security monitoring tool, without being named explicitly) and the Preferred Qualifications section (named explicitly). It is marked preferred because the required section only calls for generic SIEM/monitoring experience, while Splunk is named only under Preferred.
No compensation figures are provided in the posting.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.