Application Cyber Security Engineer
Glint Tech Solutions LLC · Reston, VA
—
Jul 1, 2026
Reston, VA
Jul 20, 2026
What this job asks for AI summary
A hands-on security engineering role embedded within a healthcare payor's DevSecOps and cloud migration efforts. Day-to-day work spans securing AWS environments and Kubernetes/container workloads, integrating security tooling (SAST, DAST, CNAPP, CSPM) into CI/CD pipelines, implementing infrastructure- and policy-as-code, and mapping controls to frameworks such as NIST and MITRE ATT&CK. Suits an experienced application and cloud security engineer comfortable bridging development teams and security governance.
Senior level · Remote
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 1,700 people nationally plausibly meet what this posting asks for (information security analysts). range 350–3,050
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
The caller has instructed that this role be treated as fully remote with a national candidate pool; the posting itself describes a hybrid arrangement requiring monthly onsite visits to Reston, VA and restricts candidates to the DC/MD/VA area — this geographic gate is overridden per caller instruction.
SOC classification is a genuine judgment call: the role blends hands-on security engineering (writing IaC, policy-as-code, pipeline security tooling) with security analysis and advisory work. 15-1212 (Information Security Analysts) is the primary pick given the dominant focus on securing systems, compliance frameworks, and vulnerability management; 15-1252 (Software Developers) is a credible runner-up given the depth of engineering work (Terraform, Helm, OPA, CI/CD pipeline development).
CNAPP, CSPM, KSPM, and CWPP are listed in the Mandatory Skills section as platform categories; Wiz and CrowdStrike are the named exemplars and are captured as the skill with alternatives. The broader platform categories are represented through the Application Security and DevSecOps skills.
Compliance frameworks (NIST CSF, NIST 800-53, ISO 27001, SOC2, CIS Benchmarks, MITRE ATT&CK) appear in the responsibilities section rather than the Mandatory Skills block; NIST CSF and MITRE ATT&CK are surfaced as preferred to flag their presence without over-gating.
No total years of experience or compensation figures are stated in the posting.
One security certification (CISSP, CISM, CEH, or CISA) is explicitly required ('One or more certifications required'); CISSP is listed as the primary with the others as alternatives. AWS Certified Security Specialty is listed under Nice-to-Have.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.