Glint Tech Solutions LLC · Reston, VAremote

Salary
Posted
Jul 1, 2026
Location
Reston, VA
Last confirmed open
Jul 20, 2026

What this job asks for AI summary

A hands-on security engineering role embedded within a healthcare payor's DevSecOps and cloud migration efforts. Day-to-day work spans securing AWS environments and Kubernetes/container workloads, integrating security tooling (SAST, DAST, CNAPP, CSPM) into CI/CD pipelines, implementing infrastructure- and policy-as-code, and mapping controls to frameworks such as NIST and MITRE ATT&CK. Suits an experienced application and cloud security engineer comfortable bridging development teams and security governance.

Senior level · Remote

Must have (15)
Application SecurityDevSecOpsSASTDASTIASTAWSKubernetesAmazon EKSWiz or CrowdstrikeOWASP Top 10TerraformHelmRego/OPACI/CDCISSP, Cism, Ceh or Cisa
Nice to have (3)
AWS Certified Security SpecialtyNIST CSFMITRE ATT&CK

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 1,700 people nationally plausibly meet what this posting asks for (information security analysts). range 350–3,050

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
Terraform11%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
CI/CD45%Application Security40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The caller has instructed that this role be treated as fully remote with a national candidate pool; the posting itself describes a hybrid arrangement requiring monthly onsite visits to Reston, VA and restricts candidates to the DC/MD/VA area — this geographic gate is overridden per caller instruction.

SOC classification is a genuine judgment call: the role blends hands-on security engineering (writing IaC, policy-as-code, pipeline security tooling) with security analysis and advisory work. 15-1212 (Information Security Analysts) is the primary pick given the dominant focus on securing systems, compliance frameworks, and vulnerability management; 15-1252 (Software Developers) is a credible runner-up given the depth of engineering work (Terraform, Helm, OPA, CI/CD pipeline development).

CNAPP, CSPM, KSPM, and CWPP are listed in the Mandatory Skills section as platform categories; Wiz and CrowdStrike are the named exemplars and are captured as the skill with alternatives. The broader platform categories are represented through the Application Security and DevSecOps skills.

Compliance frameworks (NIST CSF, NIST 800-53, ISO 27001, SOC2, CIS Benchmarks, MITRE ATT&CK) appear in the responsibilities section rather than the Mandatory Skills block; NIST CSF and MITRE ATT&CK are surfaced as preferred to flag their presence without over-gating.

No total years of experience or compensation figures are stated in the posting.

One security certification (CISSP, CISM, CEH, or CISA) is explicitly required ('One or more certifications required'); CISSP is listed as the primary with the others as alternatives. AWS Certified Security Specialty is listed under Nice-to-Have.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗