CoStar Realty Information, Inc. · US-VA Arlington

Salary
$90,000–$154,000from the description
Posted
Jun 30, 2026
Location
US-VA Arlington
Last confirmed open
Jul 20, 2026

What this job asks for AI summary

This role sits within a global cyber threat center, handling security incidents end-to-end — from triage and investigation through to resolution and post-incident documentation. The engineer also owns the Incident Response Plan, conducts threat hunts, runs tabletop exercises, and works alongside threat intelligence and detection engineering teams. It suits someone with hands-on security engineering experience, familiarity with Microsoft/Azure security tooling, and comfort scripting for automation.

Senior level · 4+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Bachelor's required · Full-time

Must have (3)
AzurePython or Low Code AutomationMITRE ATT&CK
Nice to have (4)
Microsoft DefenderMicrosoft SentinelKubernetesthreat intelligence

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 340 people in the Washington-Arlington-Alexandria, DC-VA-MD-WV area plausibly meet what this posting asks for (information security analysts). range 250–530

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Python51%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $152,225 (middle half $125,286–$177,673). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (6)

The role is titled 'Threat Detection Security Engineer' but the responsibilities — owning incident response end-to-end, threat hunting, tabletop exercises, on-call rotation, and maintaining the Incident Response Plan — are squarely Information Security Analyst work (15-1212).

The posting lists two locations: Arlington, VA and Richmond, VA. Arlington falls within the Washington-Arlington-Alexandria CBSA (47900); Richmond is a separate metro. The Arlington/DC metro is listed first and is the larger market, so it is used here.

The degree requirement is explicitly stated as a Bachelor's from an accredited, not-for-profit, in-person university — equivalent experience is not offered as a substitute.

Microsoft/Azure security tooling is listed under Basic Qualifications as a hard gate; specific products (Defender, Sentinel, EOP) are called out again under Preferred Qualifications as 'a plus', so those named products are marked preferred while the broader Azure security tooling requirement is captured as a must-have.

Python is listed under Basic Qualifications with 'or a low-code automation solution' as an alternative, making it a hard gate on scripting capability; the alternative is captured accordingly.

Kubernetes and threat intelligence collaboration appear only under Preferred Qualifications and are marked preferred.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗