100%remote

Salary
—
Posted
Aug 18, 2026
Location
100%
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

A cybersecurity engineering role at a veteran-owned government contractor, focused on implementing and validating Zero Trust security capabilities for enterprise systems. Day-to-day work involves configuring and testing security controls across infrastructure, identity, network, and cloud environments, producing technical evidence for authorization activities, and supporting RMF/ATO processes. Suited to engineers with hands-on security control implementation experience in federal or enterprise settings.

Mid level · 3+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required

Quick apply — this platform usually takes a CV and a few fields.

Must have (2)
Zero TrustRMF
Nice to have (4)
FISMAATOSecurity+, Cysa+, CISSP, Gsec or CcspAPI integrations

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 95 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 55–140

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
Zero Trust3%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
RMF40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 20, 2026. It is a model, not a headcount.

Why we read it this way (6)

The role title is 'Cybersecurity Engineer' but the primary day-to-day work — control validation, RMF/ATO evidence production, security testing, and continuous monitoring — aligns most closely with Information Security Analysts (15-1212). 15-1299 is noted as a runner-up given the engineering/integration framing.

No specific security clearance is stated as required, though the federal/FISMA context makes one likely in practice; the posting does not gate on it.

The degree requirement is a hard gate per the qualifications section; however, the posting does not offer an 'or equivalent experience' escape clause.

Certifications (Security+, CySA+, CISSP, GSEC, CCSP) are listed under 'Preferred Certifications' — none are required. Security+ is listed as the primary with the others captured as alternatives since they are presented as interchangeable options.

Location is inferred from True Zero Technologies' known Mid-Atlantic base (DC/MD/VA region); no explicit city is stated in the posting.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗