SW Cyber Security Engineer (Mid-Level)
Glint Tech Solutions LLC · Reston, VA
—
Jul 1, 2026
Reston, VA
Jul 20, 2026
What this job asks for AI summary
A mid-level security engineering role focused on application security within a Java and AWS environment for a healthcare payor client. Day-to-day work involves running application security testing tools, embedding security into CI/CD pipelines and DevSecOps workflows, managing cloud and container vulnerabilities across AWS and Kubernetes-based infrastructure, and integrating security tooling with platforms like Jira and ServiceNow. Suits candidates with hands-on secure SDLC and AWS cloud security experience.
Mid level · Washington-Arlington-Alexandria, DC-VA-MD-WV
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $152,225 (middle half $125,286–$177,673).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role is titled 'SW Cyber Security Engineer' and is explicitly application-security focused (SAST/DAST tooling, secure SDLC, DevSecOps), which maps most closely to Information Security Analysts (15-1212). However, the emphasis on secure coding in Java/JavaScript/Python and CI/CD pipeline integration gives it a meaningful software-development dimension, so 15-1252 Software Developers is a credible runner-up.
Java, JavaScript, and Python are listed as a single interchangeable requirement ('Java, JavaScript, or Python') under Mandatory Skills; Java is used as the primary name with the others as alternatives.
The application security testing tools (Checkmarx, Contrast Security, TideLift, Burp Suite, OWASP Dependency Check, Fortify) are presented as interchangeable options for the same requirement; Checkmarx is used as the primary name.
Bitbucket, GitLab, and GitHub are listed as interchangeable SCM options; Jenkins is listed alongside them as a CI/CD platform and is kept as a separate skill since it serves a distinct function.
OSCP and CEH certifications appear under 'Nice-to-Have Skills' and are marked preferred accordingly.
Healthcare or regulated industry background also appears under 'Nice-to-Have Skills' and is marked preferred.
No compensation range, contract type, or degree requirement is stated in the posting.
The role is hybrid with monthly onsite in Reston, VA; candidates must reside in the DC/MD/VA area.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.