AnaVation · Washington

Salary
Posted
Jul 5, 2026
Location
Washington
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A hybrid security engineering role supporting a federal client in Alexandria, VA, focused on administering and operating a suite of security tools — including vulnerability scanners, an EDR platform, and a SIEM — alongside incident response activities. The position involves advising client leadership on vulnerabilities, maintaining IR plans and playbooks, and presenting findings to technical and non-technical stakeholders. It suits an experienced security professional with at least six years in system security engineering and hands-on familiarity with tools such as Splunk, CrowdStrike, Tenable, and Qualys.

Senior level · 6+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Full-time

Must have (5)
SplunkCrowdStrikeTenable or QualysBurp SuiteMicrosoft Excel
Nice to have (8)
LinuxWindowsOracle or SQLAgileCSAMSecurity+AWS, Azure, GCP or Oracle CloudCISSP

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 260 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 75–460

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Splunk45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

The role blends security analysis/engineering (15-1212) with significant system administration duties (patching, account management, log management, configuration scheduling), which creates some ambiguity between 15-1212 and 15-1244; the security-analysis and incident-response focus tips the classification toward Information Security Analysts.

The posting requires a Public Trust suitability determination, not a formal DoD security clearance — the clearance requirement is set to None accordingly.

Security+, Linux/Windows/Oracle familiarity, Agile, and CSAM all appear under a 'Familiarity with' sub-heading within the Required Qualifications section; despite their placement in the broader required block, the explicit 'Familiarity with' framing signals these are contextual rather than hard gates, so they are marked preferred.

Security+ is listed under 'Familiarity with' in the required section (not as a hard certification gate), while CISSP appears under Preferred Qualifications — both are marked preferred.

Cloud provider knowledge (AWS, Azure, Oracle, GCP) and CISSP are explicitly listed under Preferred Qualifications.

The role is described as hybrid with periodic onsite in Alexandria, VA; it is not fully remote.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗