Colorado Springs, CO

Salary
$155,000–$170,000
Posted
Jul 21, 2026
Location
Colorado Springs, CO
Last confirmed open
Jul 23, 2026

What this job asks for AI summary

A lead-level security engineering role supporting federal agency cybersecurity programs, primarily for TSA. Day-to-day work involves translating NIST and government security standards into actionable tasks, conducting security impact analyses, overseeing Assessment & Authorization documentation, and guiding junior staff. The role suits a deeply experienced security engineer comfortable bridging hands-on technical work with senior-level communication, requiring a CISSP or CISM and 15 years of relevant experience.

Senior level · 15+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Full-time

Pay in the description: $155,000–$170,000

Must have (6)
CISSP or CismNISTAssessment & Authorization (A&A)MS Office SuiteFISMAPOA&M
Nice to have (5)
Tenable Security CenterInvicti 360Trustwave DbProtectCyberArk Certificate ManagerBurp Suite Pro

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
NIST40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The role is titled 'security engineer lead' but the day-to-day work is overwhelmingly security analysis, policy translation, A&A documentation review, risk assessment, and compliance — squarely 15-1212. The 'engineering' framing reflects seniority and government nomenclature rather than a software-development primary function.

CISSP and CISM are listed as a hard gate ('Must have a CISSP or a CISM'); they are captured as a single required skill with CISM as the alternative.

The security scan tools (Tenable Security Center, Invicti 360, Trustwave DbProtect, CyberArk Certificate Manager, Burp Suite Pro) are introduced with 'Examples include' under a general 'experience with security scan tools' requirement — they are illustrative examples rather than individually gated tools, so they are marked preferred.

The posting states candidates must be able to obtain a Government suitability determination (background investigation), but does not gate on holding or obtaining a specific US security clearance level — clearance is set to None accordingly.

Work locations are Annapolis Junction, MD and Colorado Springs, CO; the CBSA reflects the primary/first-listed location (Annapolis Junction falls within the Washington-Arlington-Alexandria metro). Colorado Springs (CBSA 17820) is a secondary location.

The role is hybrid (4 days on-site per week), not fully remote.

15 years of related security engineering experience is stated as a hard requirement alongside a Bachelor's degree.

The title carries no explicit seniority level word; the title states no level. The actual scope and experience requirements (15 years, lead responsibilities, senior leadership interaction) support a Senior classification.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Security Impact Analysis.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗