AnaVation · Alexandria, VA

Salary
Posted
Jul 6, 2026
Location
Alexandria, VA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A hybrid security role focused on incident response and vulnerability management for a federal client in Alexandria, VA. Day-to-day work involves leading IR activities, maintaining and querying SIEM and EDR tools, conducting vulnerability scans, analyzing results, and reporting findings to leadership and system owners. Suits an experienced security professional with at least six years in the field and hands-on familiarity with tools such as Splunk, CrowdStrike, and Tenable.

Senior level · 6+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Full-time

Must have (7)
Incident ResponseCrowdStrikeSplunkTenable Security Center or QualysNessusWiresharkVulnerability Management
Nice to have (4)
IBM BigFix or SccmRemedyCSAMPower BI or Excel

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 350 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 150–630

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Incident Response62%Vulnerability Management55%Splunk45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The posting requires a Public Trust clearance (not a national security clearance), so the clearance requirement is set to None — the standard security clearance field does not cover Public Trust adjudications.

A Bachelor's degree 'or equivalent demonstrated experience and knowledge' is listed, so the degree requirement is set to None per the equivalency rule.

CrowdStrike, Tenable SC, and Splunk are listed as required with the parenthetical '(Experience with comparable tools may be considered)' — this is a substitution qualifier, not an opt-out; they remain hard gates with the understanding that direct equivalents may satisfy the requirement.

Nessus and Tenable SC are listed separately in the JD (under different functional contexts — vulnerability scanning vs. configuration management) and are treated as distinct skills; both are required.

IBM BigFix and SCCM appear only in a parenthetical examples list under configuration management tools, not in a dedicated requirements section, so they are marked preferred.

CSAM (GRC tool) and Remedy (ticketing) appear in the responsibilities narrative rather than the required qualifications section and are marked preferred.

Power BI and Microsoft Excel appear only under Preferred Qualifications and are marked preferred.

The role is described as hybrid with periodic onsite in Alexandria, VA; remote=false reflects that it is not fully remote.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-61.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗