Consultant, Cybersecurity consultant at RSA Security
$140,000–$160,000from the description
Jul 21, 2026
—
Jul 23, 2026
What this job asks for AI summary
A senior individual-contributor role on an internal security and risk team, responsible for incident response, detection engineering, and operating tools such as SIEM, SOAR, EDR, WAF, and NGFW across cloud and on-premises environments. The position also involves applying Zero Trust and identity-centric controls, advising engineering teams on secure development practices, mentoring junior staff, and communicating security findings to both technical and non-technical stakeholders. Suits an experienced cybersecurity operations professional comfortable working across corporate and product/R&D environments.
Senior level · 6+ years · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
The posting requires US citizenship and work on US soil ('US Citizen / US Soil') but does not gate on a formal security clearance — clearance is not mentioned.
The degree requirement is flexible: 6–10 years of experience with a Bachelor's, or 4+ years with a Master's. Because equivalent experience pathways exist and the degree is not a standalone hard gate, the degree requirement is set to None.
Total years minimum is set to 6, reflecting the lower bound of the stated range for the Bachelor's path.
No specific work location or metro is stated in the posting; the role appears to be US-based but the city/CBSA is unspecified.
XDR and EDR are listed together in the JD as 'XDR/EDR'; they are treated as interchangeable alternatives for a single requirement.
Azure and AWS are listed as 'Azure and/or AWS'; treated as a single requirement with the other as an alternative.
Kubernetes, infrastructure-as-code scanning, secrets management, FedRAMP, SOC 2, NIST, AI/ML workload security, threat hunting, and certifications all appear under the 'Desirable Outcomes' section and are marked preferred.
Scripting and AI Agents are mentioned in the responsibilities narrative but not called out as a named technology requirement in the qualifications section; omitted per the generic-concept rule.
System hardening/STIG and network segmentation are mentioned in the required qualifications but name no specific product or tool, so they are omitted per the named-technology rule.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.