Salary
Posted
Jul 6, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A senior role leading cybersecurity audits and assessments within federal government environments. Day-to-day work involves managing assessment teams, overseeing configuration reviews, vulnerability management, and findings development, as well as producing audit deliverables such as POA&Ms, SCSEMs, and Nessus results. Suited to experienced cybersecurity professionals with a background in federal IT compliance frameworks and personnel management, and who can meet IRS suitability requirements.

Senior level · National

Must have (2)
vulnerability managementCISSP, Casp+ Ce, Ccnp Security, Cisa, Gced, Gcih, Ccsp, Cism, Gslc, Cciso, Hcispp, Ceh, Cysa+, Gsna, Cfr or Pentest+
Nice to have (8)
NIST 800-53NIST RMFFISMACIS BenchmarksDISA STIGsNessusSCAPPOA&M

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
vulnerability management55%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

The role title is 'Senior Information Systems Manager' but the day-to-day work is leading federal cybersecurity audits and assessments, making 15-1212 (Information Security Analysts) the best primary fit; 11-3021 (Computer and Information Systems Managers) is a genuine runner-up given the explicit personnel management and team coordination responsibilities.

No work location or CBSA is specified in the posting; the federal government client context (IRS/Treasury references) suggests a Washington DC-area or remote-US position, but this cannot be confirmed from the text.

The certification requirement is an OR list — at least one of the 16 named certifications (or a two-year IT/cybersecurity program) satisfies the gate. CISSP is listed as the primary name with all alternatives captured.

Degree requirement is effectively None: the JD states 'high school diploma or higher,' which is not a college degree gate.

IRS suitability / staff-like access is required but does not constitute a formal US security clearance under standard definitions; it is not mapped to the clearance requirement.

All preferred qualifications (NIST frameworks, DISA STIGs, Nessus, SCAP, POA&M, multi-platform environment experience, technical writing) appear under an explicit 'Preferred Qualifications' heading.

Several deliverable acronyms in the JD (SCSEMs, PFRs, SRR Section H, CAP/POA&M, AARs) are IRS-specific audit artifacts, not standalone tools or skills, and are not emitted as discrete skill entries.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): federal cybersecurity audits and assessments, security controls implementation, IT/cybersecurity project management.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗