Hanover, MDremote

Salary
Posted
Jul 7, 2026
Location
Hanover, MD
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A hybrid security engineering role focused on DoD and Intelligence Community environments, centered on RMF Assessment and Authorization, vulnerability management, and system hardening. Day-to-day work involves implementing NIST and DISA STIG controls, automating remediation across Windows, Linux, and containerized platforms using Ansible and scripting, and supporting secure CI/CD integration. Suited to engineers with hands-on RMF experience and an active Top Secret/SCI clearance.

Senior level · 5+ years · Remote · Bachelor's required · TS/SCI clearance

Advertised as Junior, but the requirements read as Senior.

Must have (12)
RMFACASDISA STIGsCIS BenchmarksAnsiblePythonBashVMware/ESXiDockerRHEL or UbuntuWindowsCisco
Nice to have (3)
CI/CDCNSSI 1253CompTIA CASP, Cisco Ccsp or Sans Gsec

“or” means any one of them counts — you don't need all of them.

Posted 3 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
Ansible8%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
Docker53%Python51%RMF40%Cisco40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (10)

Significant seniority mismatch: the title says 'Junior Security Engineer' but the qualifications gate on 5+ years of ISSE/Security Engineer experience with RMF — requirements that firmly support a Senior-level classification.

RHEL and Ubuntu are listed together as target platforms; they are distinct OSes but serve the same hardening/STIG requirement here, so Ubuntu is captured as an alternative to RHEL rather than a separate skill.

Cisco and Juniper are listed as network device hardening targets; Juniper is captured as an alternative since either platform satisfies the same network-hardening requirement.

CI/CD integration is mentioned in the responsibilities narrative rather than the formal Qualifications section, so it is marked preferred.

CNSSI 1253 appears in the job description narrative/intro rather than the Qualifications block, so it is marked preferred.

Security Architect certifications (CompTIA CASP, Cisco CCSP, SANS GSEC) are listed in the Qualifications section but framed as examples ('e.g.'), suggesting they are preferred rather than a hard gate on any one specific cert.

The role is described as 'hybrid' in the posting; the caller has overridden this to fully remote.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53.

Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗