Scott AFB

Salary
$120,000–$150,000
Posted
Jul 28, 2026
Location
Scott AFB
Last confirmed open
Jul 29, 2026

What this job asks for AI summary

This role leads all cybersecurity operations for a U.S. Army Transportation Command (ARTRANS) program, covering DoD networks at both classification levels. Day-to-day work centers on RMF/ATO sustainment via eMASS, vulnerability scanning and POA&M management, security tool administration across a government-furnished stack, and incident response. The position suits an experienced DoD cybersecurity professional holding an active Secret clearance and DoDM 8140.03 qualification.

Senior level · 6+ years · Scott Air Force Base area, IL · Secret clearance · Full-time

Pay in the description: $120,000–$150,000

Quick apply — this platform usually takes a CV and a few fields.

Must have (9)
RMFeMASSTenable/ACASSTIG/SCAPTrellix ePO or HbssCisco ISEPalo Alto NGFW or PanoramaSplunkSymantec ProxySG
Nice to have (2)
CySA+, Gcia or CehCISSP, Gcih or Casp+

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
Palo Alto NGFW1%Cisco ISE2%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Splunk45%RMF40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $98,346 (middle half $78,571–$125,286). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 29, 2026. It is a model, not a headcount.

Why we read it this way (6)

The posting does not name a specific installation or city; ARTRANS/U.S. Army Transportation Command is headquartered at Scott AFB, IL — the CBSA is estimated accordingly and should be confirmed with the employer.

DoDM 8140.03 foundational qualification and DCWF Work Role 621 (Cyber Defense Analyst, Intermediate) are hard-gated requirements stated in the qualifications section; these are credentialing/compliance requirements rather than named tools and are not represented in the skills list.

Certifications are listed as qualifying examples for the DCWF 621 work role: CySA+, GCIA, or CEH satisfy the baseline requirement; CISSP, GCIH, or CASP+ satisfy the advanced requirement. Both groups are marked preferred because the JD frames them as 'common qualifying' and 'advanced' options rather than naming a single required cert.

The alt SOC (15-1244) was considered because the role involves administering government-furnished security tools, but the primary day-to-day work — RMF/ATO, vulnerability management, incident response, and SIEM analysis — is squarely information security analysis.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): POA&M management.

Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗