Chantilly, VA

Salary
$140,000–$160,000
Posted
Aug 9, 2026
Location
Chantilly, VA
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

A Senior Information System Security Engineer (ISSE) role at Redhorse Corporation supporting government clients with critical national security missions. The position centers on information assurance engineering: designing and implementing security requirements, conducting risk and vulnerability assessments, preparing certification and accreditation documentation, and developing security architectures. Candidates must hold an active TS/SCI with Full Scope Polygraph clearance and bring deep experience with federal security frameworks such as NIST RMF and DIACAP.

Senior level · 8+ years · Bachelor's required · TS/SCI clearance · Full-time

Pay in the description: $140,000–$160,000

Quick apply — this platform usually takes a CV and a few fields.

Must have (4)
NIST SP 800-37 (RMF), Diacap, Niacap or Dcid 6 3System Security Plans (SSP)vulnerability scanningDITSCAP
Nice to have (7)
CISSPISSEP or CismAWS, Azure or GCPDevSecOpsDatabricksGitLabJira

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
vulnerability scanning55%NIST SP 800-37 (RMF)40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 11, 2026. It is a model, not a headcount.

Why we read it this way (8)

No work location or CBSA is specified in the posting. Given the TS/SCI with Full Scope Polygraph requirement, the role is almost certainly on-site at a cleared facility, but the specific location is not disclosed.

The SOC classification is a judgement call: the role blends security analysis (15-1212) with systems/security engineering. 15-1299 (Computer Occupations, All Other) is noted as a runner-up because 'Information System Security Engineer' is a distinct engineering discipline that doesn't map perfectly to the analyst SOC, but 15-1212 is the closest available code for the primary day-to-day work described.

NIST SP 800-37 (RMF), DIACAP, NIACAP, and DCID 6/3 are listed together as interchangeable framework options under the required qualifications; they are captured as a single skill with alternatives accordingly.

DITSCAP is listed in the responsibilities section (not the requirements block) as a documentation guideline, but given its specificity and centrality to the described duties it is included as a required skill.

Cloud platforms (AWS, Azure, GCP), DevSecOps, Databricks, GitLab, and Jira all appear under 'Desired Experience' and are marked preferred.

CISSP, ISSEP, and CISM are professional certifications listed under 'Desired Experience' and are marked preferred.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Security Test and Evaluation (ST&E).

Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗