Virginia Beach, VA

Salary
$80,893–$102,677from the description
Posted
Jul 28, 2026
Location
Virginia Beach, VA
Last confirmed open
Jul 29, 2026

What this job asks for AI summary

This role at NEXCOM (Navy Exchange Command) is responsible for designing and maintaining the enterprise information security and BC/DR architecture across the organization. Day-to-day work spans DoD Information Assurance architecture, risk analysis, security design for systems and infrastructure, disaster recovery site configuration, and GRC toolset administration. The position suits an experienced security architect comfortable operating within DoD/federal compliance frameworks.

Senior level · 5+ years · Virginia Beach-Norfolk-Newport News, VA-NC · Top Secret clearance · Full-time

Must have (4)
CISSP, Cism or GslcDoD Information Assurance (IA)Disaster RecoveryIT Security Compliance
Nice to have (4)
DIACAPPCI DSSSOXGRC

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What gives you an edge
Disaster Recovery6%

Rare in this occupation — lead with these, and say what you built with them.

What the occupation pays Median $128,801 (middle half $91,632–$161,699). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 29, 2026. It is a model, not a headcount.

Why we read it this way (9)

The posting requires candidates to obtain a Top Secret clearance (via SSBI/Single Scope Background Investigation) within 6 months of appointment — it does not require an active clearance at time of hire, but the role is hard-gated on eligibility and eventual attainment.

The required certification is one of CISSP, CISM, or GSLC (GSLC is the NEXCOM-preferred cert); candidates without one may be hired but must obtain it within 6 months or face termination.

The specialized experience requirement is 5 years in at least two of the listed disciplines (infrastructure architecture, DR design, IT security compliance, technical risk analysis, enterprise architecture); the overall years minimum is set to 5 to reflect this specialized floor.

General experience of 3 years (or equivalent education) is also required, but the 5-year specialized requirement is the binding gate for a qualified candidate.

DIACAP, PCI, PII, and SOX appear in a 'familiar with' context in the duties narrative rather than a hard requirements section.

The alt SOC (15-1299) reflects that the role blends enterprise architecture with security analysis; the primary classification as 15-1212 is based on the dominant security analysis and IA design duties.

U.S. citizenship is explicitly required.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Enterprise Architecture, Risk Analysis.

Requires a Top Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗