Cybersecurity Engineer Principal: SIEM, EDR & SOC Lead

General Dynamics Corporation

Bossier City (LA)

Hybrid

USD 146,200 - 197,800

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Growth opportunities
Internal mobility team
Competitive benefits

Job summary

GDIT in Bossier City, LA is looking for a Cybersecurity Engineer Principal to own the design, implementation, and automation of the SIEM/EDR ecosystem within the SOC. You will serve as the technical SME for Windows and Linux systems, EDR, and vulnerability management platforms, building telemetry pipelines and analyst tooling.

You will lead detection engineering, SIEM/SOAR integration, and threat intelligence operations while coordinating with Tier I-III teams to deliver measurable improvements

Qualifications

  • BA/BS or equivalent and 8+ years of progressive cybersecurity, SOC, or security engineering experience.
  • 5+ years administering and securing Windows and Linux systems including Active Directory, IAM, PKI, baseline hardening, patching, and automation.
  • Hands-on SIEM engineering experience including architecture design, data onboarding, parsing and normalization, detection development, dashboards, and performance optimization.
  • Strong experience with Splunk-including SPL development, Enterprise Security, and API integrations-with exposure to additional SIEM platforms such as Microsoft Sentinel or IBM QRadar.
  • SOAR engineering experience including API-driven automated workflows, enrichment, containment, response playbooks, and scripting for automation.
  • Enterprise EDR administration with direct experience in CrowdStrike Falcon, including sensor deployment, policy tuning, custom IOAs, behavioral detections, threat hunting, and incident response support; experience with Defender for Endpoint or SentinelOne also applicable.
  • Vulnerability and compliance management experience using Qualys or equivalent tools (Tenable, Rapid7), aligned to NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks.
  • Cloud security monitoring experience across AWS, Azure, or GCP including cloud log ingestion and detection engineering.
  • Identity and PAM telemetry correlation experience with Active Directory, Okta, or CyberArk integrated into SIEM and SOAR pipelines.
  • Network monitoring experience including IDS/IPS analysis, NetFlow analytics, and east-west traffic visibility.
  • Strong scripting proficiency in Python and PowerShell/Bash for automation and platform integration.
  • Experience developing detection content aligned to MITRE ATT&CK and performing coverage gap analysis.
  • Ability to integrate and automate security platforms using REST APIs, SDKs, and event-driven pipelines.
  • Strong communication skills and proven ability to interface effectively with technical teams, executives, and customer stakeholders.

Responsibilities

  • Administer, harden, and automate Windows Server and Linux systems (Red Hat, Rocky, Ubuntu, Amazon Linux); manage Active Directory, IAM, and PKI; apply secure configuration and patch baselines; and develop automation tooling using PowerShell and Bash.
  • Design, implement, and operate distributed SIEM architectures including search head/indexer clustering, deployment infrastructure, data store management, and ingestion pipelines; onboard and normalize data sources across forwarders, event collectors, and syslog; develop parsing logic including timestamping, line-breaking, field extraction, and normalization.
  • Develop high-fidelity SIEM detection content including correlation searches, dashboards, alerts, and reporting; implement retention/index strategies balancing coverage, cost, and performance; integrate SIEM components via REST APIs, SDKs, and modular inputs with built-in observability and automation validation.
  • Build and maintain SOAR automation workflows including playbooks for triage, enrichment, containment, and response; script integrations and operational logic in Python and PowerShell/Bash; integrate ticketing systems, identity platforms, directory services, and threat intelligence feeds; monitor and report automation KPIs.
  • Administer and optimize enterprise EDR platforms including sensor deployment, policy management, and behavioral detection tuning; develop custom detections mapped to MITRE ATT&CK; integrate EDR telemetry into SIEM pipelines; conduct endpoint forensics and support containment activities during incident response.
  • Operate vulnerability and compliance management programs including scanner infrastructure, schedules, authentication records, baselines, exceptions, and remediation workflows; align assessments with NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks; integrate findings into SIEM/SOAR for automated remediation, SLA tracking, and trend reporting; produce executive-level reporting on vulnerability posture.
  • Lead detection engineering and threat intelligence operations including ATT&CK coverage mapping, proactive threat hunting, detection-as-code lifecycle management, version control, and test pipeline maintenance.
  • Maintain platform operations including monitoring pipeline reliability, tuning queries, optimizing summary indexing and data models, managing licensing and capacity, performing upgrades, and maintaining SOPs, runbooks, and architecture documentation; serve as Tier III escalation for SIEM, SOAR, EDR, and vulnerability platforms.
  • Provide leadership and collaboration across Tier I-III analysts, engineering teams, and customer stakeholders; mentor engineers; drive post-incident reviews into measurable improvements; and coordinate with architecture, infrastructure, network, and cloud teams while presenting technical information clearly to both executive and technical audiences.

Skills

Security Monitoring
Security Platforms
System Security

Education

BA/BS or equivalent

Tools

Splunk
CrowdStrike Falcon
Defender for Endpoint
Palo Alto XSOAR
Qualys

Job description

GDIT in Bossier City, LA is looking for a Cybersecurity Engineer Principal to own the design, implementation, and automation of the SIEM/EDR ecosystem within the SOC. You will serve as the technical SME for Windows and Linux systems, EDR, and vulnerability management platforms, building telemetry pipelines and analyst tooling.

You will lead detection engineering, SIEM/SOAR integration, and threat intelligence operations while coordinating with Tier I-III teams to deliver measurable improvements

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer: SIEM, EDR & Threat Hunting
Senior Cybersecurity Engineer: SIEM, EDR & Threat Hunting

General Dynamics Information Technology • Bossier City (LA)

Hybrid
USD 146,000 - 198,000
Health benefits
401K with company match
Paid time off
Cybersecurity Engineer Principal
Cybersecurity Engineer Principal

General Dynamics Corporation • Bossier City (LA)

Hybrid
USD 146,000 - 198,000
Growth opportunities
Internal mobility team
Competitive benefits
Cybersecurity Engineer Principal
Cybersecurity Engineer Principal

General Dynamics Information Technology • Bossier City (LA)

Hybrid
USD 146,000 - 198,000
Health benefits
401K with company match
Paid time off
Cybersecurity Engineer Sr Principal
Cybersecurity Engineer Sr Principal

General Dynamics Information Technology • McLean (VA)

On-site
USD 170,000 - 230,000
Comprehensive benefits
401K with company match
Paid time off
Senior Security Operations Center (SOC) Engineer
Senior Security Operations Center (SOC) Engineer

IT Data Consulting, LLC • Reston (VA)

On-site
USD 110,000 - 140,000
Senior SOC Engineer - Detection, Threat Hunting & SIEM
Senior SOC Engineer - Detection, Threat Hunting & SIEM

IT Data Consulting, LLC • Reston (VA)

On-site
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
Cybersecurity Engineer – Security Infrastructure & Automation Lead
Cybersecurity Engineer – Security Infrastructure & Automation Lead

Charter Global • Atlanta (GA)

Hybrid
USD 100,000 - 130,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
Cybersecurity Detection Engineer — SIEM & Automation
Cybersecurity Detection Engineer — SIEM & Automation

Career Listings • Columbus (OH)

On-site
USD 130,000 - 170,000