Bethesda, MD

Salary
Posted
Jul 22, 2026
Location
Bethesda, MD
Last confirmed open
Jul 23, 2026

What this job asks for AI summary

A cybersecurity engineering role embedded in a DoD intelligence-community program, focused on designing and securing on-premises systems through the full Risk Management Framework process. Day-to-day work spans maintaining vulnerability scanning infrastructure, authoring and updating RMF documentation, applying STIGs, and integrating security controls across the software development lifecycle. Suits an experienced security engineer holding an active TS/SCI and a qualifying IASAE Level II certification.

Senior level · 8+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · TS/SCI clearance · Full-time

Must have (17)
DoDI 8510.01SCAPSTIG ViewerACASCISSP, Cissp Issap, Cissp Issep, Csslp or Casp+ CeXACTA or EmassWindowsLinuxApache, Apache Tomcat or IisPostgreSQL, SQL Server, MySQL or ElasticsearchTCP/IPJenkins, Bamboo, Gitlab Ci or Azure DevOpsOWASPFortify, Sonarqube or NessusCMMCNIST SSDFCNSSI 1253
Nice to have (6)
Python, Java or ReactGitLab, Jira or ConfluenceKubernetes, Rancher, Strimzi or ClouderaActive DirectoryBash or PowerShellOIDC or OAuth

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
CMMC2%Apache12%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Linux65%PostgreSQL40%TCP/IP40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (11)

The role is hybrid (3 days on-site in Bethesda, MD); remote=false is set because it is not fully remote.

An active TS/SCI is required; the posting also states 'ability to obtain a Poly,' which implies a polygraph may be required later but is not a hard gate at hiring — the clearance gate is TS/SCI.

A BS degree is listed as the baseline, but the posting explicitly accepts 'additional relevant years of experience in lieu of degree,' so the degree requirement is set to None.

DoD 8570 IASAE Level II certification (CISSP or equivalent) is a hard gate; CISSP Associate is explicitly called out as NOT acceptable.

Developer/scripting experience is listed under Minimum Requirements but framed as 'preferred' — it has been captured as preferred skills (Python, Java, React, Bash, PowerShell).

OWASP, Fortify, SonarQube, and Tenable appear together as examples of vulnerability scanning solutions under Minimum Requirements; Fortify is used as the primary name with SonarQube and Tenable as alternatives.

XACTA and eMASS appear as alternatives for the same requirement ('XACTA, EMass, or similar tool').

Apache, Tomcat, and IIS are listed as interchangeable middleware/web technology examples; Apache is used as the primary with Tomcat and IIS as alternatives.

The alternative occupation code 15-1299 is noted because the role blends security analysis with significant systems/security engineering (design, implementation, automation) — a genuine occupational ambiguity.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): DoD Risk Management Framework, NIST SP 800-53, NIST SP 800-171.

Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗