1

Senior Security Analyst Jobs in Reston, VA (NOW HIRING)

Senior Security

Washington, DC ยท On-site

$108K - $142K/yr

Senior Security Location: Washington DC Duration: 12 Months contract 5-8 Years Experience Principal ... Excellent written, communication, and analytical skills. * Experience in Windows and UNIX ...

New

Our security analysts will provide a thorough review of security clearance paperwork and personnel ... Senior (Level 4) requires minimum of 5 years of experience performing security or suitability ...

Security Analyst

Chantilly, VA ยท On-site

$85K - $100K/yr

Our security analysts will provide a thorough review of security clearance paperwork and personnel ... Senior (Level 4) requires minimum of 5 years of experience performing security or suitability ...

Showing results 21-40

Senior Security Analyst information

See Reston, VA salary details

$72.4K

$120.4K

$172.5K

How much do senior security analyst jobs pay per year?

As of Aug 6, 2026, the average yearly pay for senior security analyst in Reston, VA is $120,431.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,100.00 and $130,800.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a senior security analyst?

To thrive as a Senior Security Analyst, you need deep expertise in cybersecurity principles, risk assessment, and incident response, often supported by a degree in computer science or related field and relevant certifications such as CISSP or CISM. Familiarity with security information and event management (SIEM) tools, intrusion detection systems, and vulnerability assessment platforms is typically required. Strong analytical thinking, attention to detail, and effective communication skills help set top performers apart in this role. These skills and qualities are vital for identifying threats, protecting organizational assets, and ensuring robust incident handling in complex security environments.

What is a senior security analyst?

Senior Security Analysts are experienced professionals responsible for protecting an organization's digital assets from cyber threats. They monitor networks and systems for security breaches, investigate incidents, and develop strategies to prevent future attacks. In addition, Senior Security Analysts often lead teams, conduct risk assessments, and ensure compliance with security policies and regulations. Their role is critical in maintaining the overall security posture of an organization.

How does a senior security analyst typically collaborate with other departments to enhance an organization's security posture?

Senior Security Analysts work closely with IT, compliance, risk management, and executive teams to identify vulnerabilities, implement security policies, and respond to incidents. They often lead security awareness training, coordinate with system administrators to deploy security measures, and provide guidance during audits. Effective collaboration ensures that security protocols align with business objectives and that all departments are informed about best practices and emerging threats.

What is the difference between Senior Security Analyst vs Security Engineer?

AspectSenior Security AnalystSecurity Engineer
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentSecurity teams, incident response, threat analysisSystem design, implementation, security architecture
Employer & Industry UsageIT security departments across various industriesIT and cybersecurity teams, often in infrastructure projects
Common Search & ComparisonYesNo

The Senior Security Analyst primarily focuses on monitoring, analyzing, and responding to security threats, while the Security Engineer designs and implements security systems. Both roles require similar certifications and are integral to cybersecurity teams, but they differ in daily responsibilities and focus areas.

What are the most commonly searched types of Security Analyst jobs in Reston, VA? The most popular types of Security Analyst jobs in Reston, VA are:
What are popular job titles related to Senior Security Analyst jobs in Reston, VA? For Senior Security Analyst jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Senior Security Analyst jobs in Reston, VA look for? The top searched job categories for Senior Security Analyst jobs in Reston, VA are:
What cities near Reston, VA are hiring for Senior Security Analyst jobs? Cities near Reston, VA with the most Senior Security Analyst job openings:

Security Analyst/Sr. Security Analyst (Application Security)-ITDSGGR (Contractual)

International Monetary Fund

Washington, DC โ€ข On-site

Full-time

Posted 16 days ago


Job description

Work for the IMF. Work for the World.
The Security Analyst (Application Security) supports the integration of security throughout the Software Development Lifecycle (SDLC) by partnering with development, infrastructure, and application teams to embed secure development practices, implement security requirements, and strengthen the overall security posture of enterprise applications. The role is responsible for identifying, validating, prioritizing, tracking, and supporting the remediation of application security vulnerabilities, while driving risk-based vulnerability management activities and application security initiatives across on-premises and cloud environments. The successful candidate combines hands-on expertise in application security and vulnerability management with the ability to provide actionable guidance, support secure software development, and continuously improve security outcomes through governance, metrics, reporting, and security best practices.
Major Duties and Responsibilities
Vulnerability Management & Risk Management
  • Lead the identification, validation, prioritization, tracking, and remediation of application security vulnerabilities, ensuring risks are addressed in accordance with established timelines and organizational priorities.
  • Partner with application owners and engineering teams to manage vulnerability workflows, including intake, analysis, assignment, risk-based prioritization, exception handling, remediation tracking, and escalation of critical issues.
  • Provide risk-based remediation recommendations and guidance to application teams to support informed security decisions and risk reduction efforts.

Application Security & Secure SDLC
  • Support the integration of security throughout the Software Development Lifecycle (SDLC) by promoting secure coding practices, implementing security requirements, participating in threat modeling and design reviews, and helping implement security controls across on-premises and cloud environments.
  • Lead and support the adoption of application security testing capabilities, including SAST, DAST, and SCA solutions within CI/CD pipelines, while reviewing security findings, validating results, and providing remediation guidance.

Governance, Reporting & Security Enablement
  • Maintain visibility into application security posture through tracking, analysis, and reporting of vulnerability status, severity, aging, ownership, exceptions, remediation progress, and risk trends using enterprise platforms.
  • Stay current with emerging threats, vulnerabilities, and industry best practices while supporting security awareness, developer enablement, and continuous improvement of application security processes and standards.

Minimum Qualifications
  • Educational development, typically acquired by the completion of an advanced university degree, or equivalent, in Computer Science, Cybersecurity, or related field, supplemented by a minimum of four (4) years of relevant, professional work experience, is required. Alternatively, a university degree, or equivalent, and ten (10) years of relevant professional experience, is required.
  • Experience in Vulnerability Management, Application Security, Secure Development or related cybersecurity disciplines.
  • Strong knowledge of application security principles, secure software development practices, and industry frameworks such as OWASP Top 10, NIST SSDF, NIST CSF, and ISO 27001.
  • Experience with one or more programming or scripting languages (e.g., Java, Python, .NET, PowerShell) and the ability to analyze application security findings and support remediation efforts.
  • Understanding of secure architecture principles for web, cloud, and enterprise applications, including common attack vectors and mitigation techniques.
  • Hands-on experience with application security testing methodologies and tools, including SAST, DAST, SCA, vulnerability assessments, and penetration testing.
  • Strong understanding of vulnerability management processes, including vulnerability validation, risk-based prioritization, remediation tracking, exception management, compensating controls, and vulnerability lifecycle management.
  • Experience collaborating with development and engineering teams to integrate security requirements and controls throughout the Software Development Lifecycle (SDLC).
  • Ability to analyze security risks, communicate technical findings to diverse audiences, and provide actionable remediation guidance.
  • Strong communication, analytical, stakeholder management, and collaboration skills, with the ability to influence security outcomes across cross-functional teams.

Preferred Qualifications
  • Security certifications, such as OSCP, SSCP, CEH, Security+, GIAC, CISSP, or equivalent.
  • Experience using ServiceNow, including native AI capabilities, and vulnerability management, ticketing, or reporting platforms to support remediation tracking and risk reporting.
  • Knowledge, certifications, and experience in Microsoft Azure, Azure DevOps, and Power BI for cloud operations, reporting, and data visualization.
  • Experience with enterprise application security tools, such as Burp Suite, Sonatype Nexus Lifecycle, Checkmarx, Fortify, HCL AppScan, Veracode, or similar solutions.

This is a one-year contractual appointment. Contractual appointments at the IMF are renewable for up to four years of cumulative contractual service, pending incumbent's performance, budget availability, and continuous business need.
Department:
ITDSG Information Technology Department Information Security & Governance
Hiring For:
A11, A12
The IMF is guided by the principle that the employment, classification, promotion, and assignment of staff shall be made without discrimination against any person. We welcome requests for reasonable accommodations for disabilities during the selection process. Information on how to request accommodations will be provided during the application process.