Cybersecurity Engineer Principal

General Dynamics Information Technology

Bossier City (LA)

Hybrid

USD 140,000 - 190,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

General Dynamics Information Technology in the United States is seeking a Cybersecurity Engineer Principal to join a senior technical role in the SOC. You will own design, implementation, and automation of the SIEM ecosystem, serve as SME for Windows/Linux, EDR, and vulnerability management, and drive detection content, playbooks, and threat intelligence across a multi-customer federal environment.

The role requires deep expertise across SIEM, SOAR, EDR, and vulnerability management with strong

Qualifications

  • BA/BS or equivalent and 8+ years of progressive cybersecurity, SOC, or security engineering experience.
  • 5+ years administering and securing Windows and Linux systems including Active Directory, IAM, PKI, baseline hardening, patching, and automation.
  • Hands-on SIEM engineering experience including architecture design, data onboarding, parsing and normalization, detection development, dashboards, and performance optimization.
  • Strong experience with Splunk—including SPL development, Enterprise Security, and API integrations—with exposure to additional SIEM platforms such as Microsoft Sentinel or IBM QRadar.
  • SOAR engineering experience including API-driven automated workflows, enrichment, containment, response playbooks, and scripting for automation.
  • Enterprise EDR administration with direct experience in CrowdStrike Falcon, including sensor deployment, policy tuning, custom IOAs, behavioral detections, threat hunting, and incident response support; experience with Defender for Endpoint or SentinelOne also applicable.
  • Vulnerability and compliance management experience using Qualys or equivalent tools (Tenable, Rapid7), aligned to NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks.
  • Cloud security monitoring experience across AWS, Azure, or GCP including cloud log ingestion and detection engineering.
  • Identity and PAM telemetry correlation experience with Active Directory, Okta, or CyberArk integrated into SIEM and SOAR pipelines.
  • Network monitoring experience including IDS/IPS analysis, NetFlow analytics, and east-west traffic visibility.
  • Strong scripting proficiency in Python and PowerShell/Bash for automation and platform integration.
  • Experience developing detection content aligned to MITRE ATT&CK and performing coverage gap analysis.
  • Ability to integrate and automate security platforms using REST APIs, SDKs, and event-driven pipelines.
  • Strong communication skills and proven ability to interface effectively with technical teams, executives, and customer stakeholders.

Responsibilities

  • Administer, harden, and automate Windows Server and Linux systems; manage Active Directory, IAM, and PKI; apply secure configuration and patch baselines.
  • Design, implement, and operate distributed SIEM architectures and data onboarding pipelines.
  • Develop high-fidelity SIEM detection content, dashboards, and alarms; optimize retention and indexing strategies.
  • Build and maintain SOAR workflows including playbooks for triage, enrichment, and containment.
  • Administer and optimize enterprise EDR platforms; map detections to MITRE ATT&CK; support incident response.
  • Lead vulnerability and compliance programs aligned to NIST/DISA CIS benchmarks; automate remediation.
  • Lead detection engineering and threat intel operations; maintain version control and test pipelines.
  • Maintain platform operations, monitoring, upgrades, and runbooks; serve as Tier III escalation for SIEM/SOAR/EDR.
  • Collaborate across analysts, engineering, and customer stakeholders; mentor engineers; present findings to executives.

Skills

Windows administration
Linux administration
SIEM engineering
SOAR automation
EDR administration
Vulnerability management
Cloud security
Identity and PAM telemetry
Network monitoring
Scripting Python
PowerShell/Bash scripting
MITRE ATT&CK mapping
REST APIs integration

Education

Bachelor's degree or equivalent

Tools

Splunk
CrowdStrike Falcon
Defender for Endpoint
SentinelOne
Qualys
Tenable
Rapid7

Job description

Advance your career while impacting our national security in cyber as a Cybersecurity Engineer Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.

As a senior technical contributor within the SOC, the Cybersecurity Engineer Principal owns the design, implementation, optimization, and automation of the security information and event management ecosystem - while also serving as the technical subject matter expert for Windows and Linux systems, Endpoint Detection and Response (EDR), and vulnerability management platforms. This role operates at the intersection of systems engineering, security operations, data engineering, and platform architecture - building and sustaining the telemetry pipelines, detection logic, and tool integrations that power Tier I-III analyst workflows.

The ideal candidate brings deep, vendor-agnostic expertise across operating systems, SIEM, SOAR, EDR, and vulnerability/compliance management, with proven ability to translate that knowledge into operational outcomes in a complex, multi-customer federal environment.

KEY RESPONSIBILITIES:
  • Administer, harden, and automate Windows Server and Linux systems (Red Hat, Rocky, Ubuntu, Amazon Linux); manage Active Directory, IAM, and PKI; apply secure configuration and patch baselines; and develop automation tooling using PowerShell and Bash.
  • Design, implement, and operate distributed SIEM architectures including search head/indexer clustering, deployment infrastructure, data store management, and ingestion pipelines; onboard and normalize data sources across forwarders, event collectors, and syslog; develop parsing logic including timestamping, line-breaking, field extraction, and normalization.
  • Develop high-fidelity SIEM detection content including correlation searches, dashboards, alerts, and reporting; implement retention/index strategies balancing coverage, cost, and performance; integrate SIEM components via REST APIs, SDKs, and modular inputs with built-in observability and automation validation.
  • Build and maintain SOAR automation workflows including playbooks for triage, enrichment, containment, and response; script integrations and operational logic in Python and PowerShell/Bash; integrate ticketing systems, identity platforms, directory services, and threat intelligence feeds; monitor and report automation KPIs.
  • Administer and optimize enterprise EDR platforms including sensor deployment, policy management, and behavioral detection tuning; develop custom detections mapped to MITRE ATT&CK; integrate EDR telemetry into SIEM pipelines; conduct endpoint forensics and support containment activities during incident response.
  • Operate vulnerability and compliance management programs including scanner infrastructure, schedules, authentication records, baselines, exceptions, and remediation workflows; align assessments with NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks; integrate findings into SIEM/SOAR for automated remediation, SLA tracking, and trend reporting; produce executive-level reporting on vulnerability posture.
  • Lead detection engineering and threat intelligence operations including ATT&CK coverage mapping, proactive threat hunting, detection-as-code lifecycle management, version control, and test pipeline maintenance.
  • Maintain platform operations including monitoring pipeline reliability, tuning queries, optimizing summary indexing and data models, managing licensing and capacity, performing upgrades, and maintaining SOPs, runbooks, and architecture documentation; serve as Tier III escalation for SIEM, SOAR, EDR, and vulnerability platforms.
  • Provide leadership and collaboration across Tier I-III analysts, engineering teams, and customer stakeholders; mentor engineers; drive post-incident reviews into measurable improvements; and coordinate with architecture, infrastructure, network, and cloud teams while presenting technical information clearly to both executive and technical audiences.
REQUIRED SKILLS/EXPERIENCE:
  • BA/BS or equivalent and 8+ years of progressive cybersecurity, SOC, or security engineering experience.
  • 5+ years administering and securing Windows and Linux systems including Active Directory, IAM, PKI, baseline hardening, patching, and automation.
  • Hands-on SIEM engineering experience including architecture design, data onboarding, parsing and normalization, detection development, dashboards, and performance optimization.
  • Strong experience with Splunk—including SPL development, Enterprise Security, and API integrations—with exposure to additional SIEM platforms such as Microsoft Sentinel or IBM QRadar.
  • SOAR engineering experience including API-driven automated workflows, enrichment, containment, response playbooks, and scripting for automation.
  • Enterprise EDR administration with direct experience in CrowdStrike Falcon, including sensor deployment, policy tuning, custom IOAs, behavioral detections, threat hunting, and incident response support; experience with Defender for Endpoint or SentinelOne also applicable.
  • Vulnerability and compliance management experience using Qualys or equivalent tools (Tenable, Rapid7), aligned to NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks.
  • Cloud security monitoring experience across AWS, Azure, or GCP including cloud log ingestion and detection engineering.
  • Identity and PAM telemetry correlation experience with Active Directory, Okta, or CyberArk integrated into SIEM and SOAR pipelines.
  • Network monitoring experience including IDS/IPS analysis, NetFlow analytics, and east-west traffic visibility.
  • Strong scripting proficiency in Python and PowerShell/Bash for automation and platform integration.
  • Experience developing detection content aligned to MITRE ATT&CK and performing coverage gap analysis.
  • Ability to integrate and automate security platforms using REST APIs, SDKs, and event-driven pipelines.
  • Strong communication skills and proven ability to interface effectively with technical teams, executives, and customer stakeholders.
Required certifications:
  • Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk ES Certified Admin within 6 months of hire
  • Splunk SOAR or Palo Alto XSOAR certification within 6 months of hire
  • DoD 8140/DCWF CSSP Analyst within 6 months of hire
Security Clearance Level:

Ability to pass a background check to obtain and maintain suitability for multi-agency federal/state support.

US Citizenship is required.
Location: Hybrid in Bossier City, LA
GDIT IS YOUR PLACE
  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace

OWN YOUR OPPORTUNITY
Explore an enterprise IT career at GDIT and you'll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.

#GDITLA

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer Principal
Cybersecurity Engineer Principal

General Dynamics Corporation • Bossier City (LA)

Hybrid
USD 146,000 - 198,000
Growth opportunities
Internal mobility team
Competitive benefits
Secure Enclave System Engineering Lead
Secure Enclave System Engineering Lead

GDIT • McLean (VA)

On-site
USD 170,000 - 230,000
Principal Systems Engineer
Principal Systems Engineer

General Dynamics - IT • Bossier City (LA)

On-site
USD 120,000 - 160,000
401K with company match
Comprehensive health and wellness
Professional growth opportunities
+2
DevSecOps Engineer for Artificial Intelligence and Machine Learning (AI/ML)
DevSecOps Engineer for Artificial Intelligence and Machine Learning (AI/ML)

General Dynamics Information Technology • Maryland

On-site
USD 140,000 - 190,000
Senior Principal Azure Engineer
Senior Principal Azure Engineer

General Dynamics Information Technology • Washington

On-site
USD 157,250 - 212,750
SME Cyber Network Analyst
SME Cyber Network Analyst

General Dynamics Information Technology • Crystal City (TX)

On-site
USD 187,000 - 253,000
401K with company match
Paid time off
Senior Information System Security Engineer
Senior Information System Security Engineer

General Dynamics Information Technology • Reston (VA)

On-site
USD 162,000 - 219,000
401K with company match
Comprehensive health and wellness
Internal mobility team
+3
Cybersecurity Information Security Assessor
Cybersecurity Information Security Assessor

General Dynamics Information Technology • Chantilly (VA)

Hybrid
USD 128,000 - 173,000
Network & Security Operations Manager
Network & Security Operations Manager

General Dynamics - IT • Bossier City (LA)

On-site
USD 120,000 - 170,000
Growth opportunities
Internal mobility support
Competitive pay & benefits
+2
Sr. Cybersecurity Architect - Active Top Secret
Sr. Cybersecurity Architect - Active Top Secret

General Dynamics - IT • Washington

On-site
USD 140,000 - 200,000
Comprehensive benefits
401K with company match
Military-friendly workplace