Cybersecurity Engineer Principal

General Dynamics Corporation

Bossier City (LA)

Hybrid

USD 146,200 - 197,800

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Growth opportunities
Internal mobility team
Competitive benefits

Job summary

GDIT in Bossier City, LA is looking for a Cybersecurity Engineer Principal to own the design, implementation, and automation of the SIEM/EDR ecosystem within the SOC. You will serve as the technical SME for Windows and Linux systems, EDR, and vulnerability management platforms, building telemetry pipelines and analyst tooling.

You will lead detection engineering, SIEM/SOAR integration, and threat intelligence operations while coordinating with Tier I-III teams to deliver measurable improvements

Qualifications

  • BA/BS or equivalent and 8+ years of progressive cybersecurity, SOC, or security engineering experience.
  • 5+ years administering and securing Windows and Linux systems including Active Directory, IAM, PKI, baseline hardening, patching, and automation.
  • Hands-on SIEM engineering experience including architecture design, data onboarding, parsing and normalization, detection development, dashboards, and performance optimization.
  • Strong experience with Splunk-including SPL development, Enterprise Security, and API integrations-with exposure to additional SIEM platforms such as Microsoft Sentinel or IBM QRadar.
  • SOAR engineering experience including API-driven automated workflows, enrichment, containment, response playbooks, and scripting for automation.
  • Enterprise EDR administration with direct experience in CrowdStrike Falcon, including sensor deployment, policy tuning, custom IOAs, behavioral detections, threat hunting, and incident response support; experience with Defender for Endpoint or SentinelOne also applicable.
  • Vulnerability and compliance management experience using Qualys or equivalent tools (Tenable, Rapid7), aligned to NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks.
  • Cloud security monitoring experience across AWS, Azure, or GCP including cloud log ingestion and detection engineering.
  • Identity and PAM telemetry correlation experience with Active Directory, Okta, or CyberArk integrated into SIEM and SOAR pipelines.
  • Network monitoring experience including IDS/IPS analysis, NetFlow analytics, and east-west traffic visibility.
  • Strong scripting proficiency in Python and PowerShell/Bash for automation and platform integration.
  • Experience developing detection content aligned to MITRE ATT&CK and performing coverage gap analysis.
  • Ability to integrate and automate security platforms using REST APIs, SDKs, and event-driven pipelines.
  • Strong communication skills and proven ability to interface effectively with technical teams, executives, and customer stakeholders.

Responsibilities

  • Administer, harden, and automate Windows Server and Linux systems (Red Hat, Rocky, Ubuntu, Amazon Linux); manage Active Directory, IAM, and PKI; apply secure configuration and patch baselines; and develop automation tooling using PowerShell and Bash.
  • Design, implement, and operate distributed SIEM architectures including search head/indexer clustering, deployment infrastructure, data store management, and ingestion pipelines; onboard and normalize data sources across forwarders, event collectors, and syslog; develop parsing logic including timestamping, line-breaking, field extraction, and normalization.
  • Develop high-fidelity SIEM detection content including correlation searches, dashboards, alerts, and reporting; implement retention/index strategies balancing coverage, cost, and performance; integrate SIEM components via REST APIs, SDKs, and modular inputs with built-in observability and automation validation.
  • Build and maintain SOAR automation workflows including playbooks for triage, enrichment, containment, and response; script integrations and operational logic in Python and PowerShell/Bash; integrate ticketing systems, identity platforms, directory services, and threat intelligence feeds; monitor and report automation KPIs.
  • Administer and optimize enterprise EDR platforms including sensor deployment, policy management, and behavioral detection tuning; develop custom detections mapped to MITRE ATT&CK; integrate EDR telemetry into SIEM pipelines; conduct endpoint forensics and support containment activities during incident response.
  • Operate vulnerability and compliance management programs including scanner infrastructure, schedules, authentication records, baselines, exceptions, and remediation workflows; align assessments with NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks; integrate findings into SIEM/SOAR for automated remediation, SLA tracking, and trend reporting; produce executive-level reporting on vulnerability posture.
  • Lead detection engineering and threat intelligence operations including ATT&CK coverage mapping, proactive threat hunting, detection-as-code lifecycle management, version control, and test pipeline maintenance.
  • Maintain platform operations including monitoring pipeline reliability, tuning queries, optimizing summary indexing and data models, managing licensing and capacity, performing upgrades, and maintaining SOPs, runbooks, and architecture documentation; serve as Tier III escalation for SIEM, SOAR, EDR, and vulnerability platforms.
  • Provide leadership and collaboration across Tier I-III analysts, engineering teams, and customer stakeholders; mentor engineers; drive post-incident reviews into measurable improvements; and coordinate with architecture, infrastructure, network, and cloud teams while presenting technical information clearly to both executive and technical audiences.

Skills

Security Monitoring
Security Platforms
System Security

Education

BA/BS or equivalent

Tools

Splunk
CrowdStrike Falcon
Defender for Endpoint
Palo Alto XSOAR
Qualys

Job description

Responsibilities for this Position

Location: USA LA Bossier City

Full Part/Time: Full time

Job Req: RQ224804

Type of Requisition: Regular

Clearance Level Must Currently Possess: None

Clearance Level Must Be Able to Obtain: None

Public Trust/Other Required: None

Job Family: Cyber and IT Risk Management

Job Qualifications:

Skills: Security Monitoring, Security Platforms, System Security

Certifications: None

Experience: 8 + years of related experience

US Citizenship Required: Yes

Job Description: Advance your career while impacting our national security in cyber as a Cybersecurity Engineer Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.

As a senior technical contributor within the SOC, the Cybersecurity Engineer Principal owns the design, implementation, optimization, and automation of the security information and event management ecosystem - while also serving as the technical subject matter expert for Windows and Linux systems, Endpoint Detection and Response (EDR), and vulnerability management platforms. This role operates at the intersection of systems engineering, security operations, data engineering, and platform architecture - building and sustaining the telemetry pipelines, detection logic, and tool integrations that power Tier I-III analyst workflows.

  • Administer, harden, and automate Windows Server and Linux systems (Red Hat, Rocky, Ubuntu, Amazon Linux); manage Active Directory, IAM, and PKI; apply secure configuration and patch baselines; and develop automation tooling using PowerShell and Bash.
  • Design, implement, and operate distributed SIEM architectures including search head/indexer clustering, deployment infrastructure, data store management, and ingestion pipelines; onboard and normalize data sources across forwarders, event collectors, and syslog; develop parsing logic including timestamping, line-breaking, field extraction, and normalization.
  • Develop high-fidelity SIEM detection content including correlation searches, dashboards, alerts, and reporting; implement retention/index strategies balancing coverage, cost, and performance; integrate SIEM components via REST APIs, SDKs, and modular inputs with built-in observability and automation validation.
  • Build and maintain SOAR automation workflows including playbooks for triage, enrichment, containment, and response; script integrations and operational logic in Python and PowerShell/Bash; integrate ticketing systems, identity platforms, directory services, and threat intelligence feeds; monitor and report automation KPIs.
  • Administer and optimize enterprise EDR platforms including sensor deployment, policy management, and behavioral detection tuning; develop custom detections mapped to MITRE ATT&CK; integrate EDR telemetry into SIEM pipelines; conduct endpoint forensics and support containment activities during incident response.
  • Operate vulnerability and compliance management programs including scanner infrastructure, schedules, authentication records, baselines, exceptions, and remediation workflows; align assessments with NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks; integrate findings into SIEM/SOAR for automated remediation, SLA tracking, and trend reporting; produce executive-level reporting on vulnerability posture.
  • Lead detection engineering and threat intelligence operations including ATT&CK coverage mapping, proactive threat hunting, detection-as-code lifecycle management, version control, and test pipeline maintenance.
  • Maintain platform operations including monitoring pipeline reliability, tuning queries, optimizing summary indexing and data models, managing licensing and capacity, performing upgrades, and maintaining SOPs, runbooks, and architecture documentation; serve as Tier III escalation for SIEM, SOAR, EDR, and vulnerability platforms.
  • Provide leadership and collaboration across Tier I-III analysts, engineering teams, and customer stakeholders; mentor engineers; drive post-incident reviews into measurable improvements; and coordinate with architecture, infrastructure, network, and cloud teams while presenting technical information clearly to both executive and technical audiences.

REQUIRED SKILLS/EXPERIENCE:

  • BA/BS or equivalent and 8+ years of progressive cybersecurity, SOC, or security engineering experience.
  • 5+ years administering and securing Windows and Linux systems including Active Directory, IAM, PKI, baseline hardening, patching, and automation.
  • Hands-on SIEM engineering experience including architecture design, data onboarding, parsing and normalization, detection development, dashboards, and performance optimization.
  • Strong experience with Splunk-including SPL development, Enterprise Security, and API integrations-with exposure to additional SIEM platforms such as Microsoft Sentinel or IBM QRadar.
  • SOAR engineering experience including API-driven automated workflows, enrichment, containment, response playbooks, and scripting for automation.
  • Enterprise EDR administration with direct experience in CrowdStrike Falcon, including sensor deployment, policy tuning, custom IOAs, behavioral detections, threat hunting, and incident response support; experience with Defender for Endpoint or SentinelOne also applicable.
  • Vulnerability and compliance management experience using Qualys or equivalent tools (Tenable, Rapid7), aligned to NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks.
  • Cloud security monitoring experience across AWS, Azure, or GCP including cloud log ingestion and detection engineering.
  • Identity and PAM telemetry correlation experience with Active Directory, Okta, or CyberArk integrated into SIEM and SOAR pipelines.
  • Network monitoring experience including IDS/IPS analysis, NetFlow analytics, and east-west traffic visibility.
  • Strong scripting proficiency in Python and PowerShell/Bash for automation and platform integration.
  • Experience developing detection content aligned to MITRE ATT&CK and performing coverage gap analysis.
  • Ability to integrate and automate security platforms using REST APIs, SDKs, and event-driven pipelines.
  • Strong communication skills and proven ability to interface effectively with technical teams, executives, and customer stakeholders.

Required certifications:

  • Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk ES Certified Admin within 6 months of hire
  • Splunk SOAR or Palo Alto XSOAR certification within 6 months of hire
  • DoD 8140/DCWF CSSP Analyst within 6 months of hire

Security Clearance Level: Ability to pass a background check to obtain and maintain suitability for multi-agency federal/state support.

US Citizenship is required.

Location: Hybrid in Bossier City, LA

GDIT IS YOUR PLACE

At GDIT, the mission is our purpose, and our people are at the center of everything we do.

  • Growth: AI-powered career tool that identifies career steps and learning opportunities
  • Support: An internal mobility team focused on helping you achieve your career goals
  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off
  • Community: Award-winning culture of innovation and a military-friendly workplace

OWN YOUR OPPORTUNITY

Explore an enterprise IT career at GDIT and you'll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.

#GDITLA

The likely salary range for this position is $146,200 - $197,800. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours: 40

Travel Required: Less than 10%

Telecommuting Options: Hybrid

Work Location: USA LA Bossier City

Additional Work Locations:

Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process: As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work: We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

PI286082390

GDIT supports and secures some of the most complex government, defense, and intelligence projects across the country.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer Principal
Cybersecurity Engineer Principal

General Dynamics Information Technology • Bossier City (LA)

Hybrid
USD 140,000 - 210,000
Growth opportunities
Internal mobility support
Competitive benefits and 401K matching
+1
Cyber Security Analyst Sr - Remote Role
Cyber Security Analyst Sr - Remote Role

Socket.dev • Town of Florida (NY)

Hybrid
USD 119,000 - 161,000
Solutions Architect/Lead
Solutions Architect/Lead

General Dynamics Information Technology • Arlington (VA)

Hybrid
USD 153,000 - 207,000
Growth opportunities
Internal mobility
Benefits package
+1
SOC Cyber Security Manager
SOC Cyber Security Manager

General Dynamics Information Technology • Falls Church (VA)

On-site
USD 153,000 - 207,000
Project Manager with TS/SCI With Polygraph Required
Project Manager with TS/SCI With Polygraph Required

General Dynamics Information Technology • North Dakota

On-site
USD 168,000 - 227,000
401K with company match
Health and wellness packages
Internal mobility team dedicated to
Cyber Incident Response Team (CIRT) Lead
Cyber Incident Response Team (CIRT) Lead

General Dynamics Information Technology • Falls Church (VA)

On-site
USD 136,000 - 184,000
401(k) with company match
Flexible work weeks
Paid time off
Senior Principal Azure Engineer
Senior Principal Azure Engineer

General Dynamics Information Technology • Washington

On-site
USD 157,250 - 212,750
Cybersecurity Information Security Assessor
Cybersecurity Information Security Assessor

General Dynamics Information Technology • Chantilly (VA)

Hybrid
USD 128,000 - 173,000
Senior DevOps Engineer
Senior DevOps Engineer

General Dynamics Information Technology • St. Louis (MO)

On-site
USD 144,000 - 194,000
401K with company match
Paid time off
Health benefits
Senior Information System Security Engineer
Senior Information System Security Engineer

General Dynamics Information Technology • Reston (VA)

On-site
USD 162,000 - 219,000
401K with company match
Comprehensive health and wellness
Internal mobility team
+3