Senior Cybersecurity Engineer - SIEM/EDR Lead

General Dynamics Information Technology

Bossier City (LA)

Hybrid

USD 140,000 - 190,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

General Dynamics Information Technology in the United States is seeking a Cybersecurity Engineer Principal to join a senior technical role in the SOC. You will own design, implementation, and automation of the SIEM ecosystem, serve as SME for Windows/Linux, EDR, and vulnerability management, and drive detection content, playbooks, and threat intelligence across a multi-customer federal environment.

The role requires deep expertise across SIEM, SOAR, EDR, and vulnerability management with strong

Qualifications

  • BA/BS or equivalent and 8+ years of progressive cybersecurity, SOC, or security engineering experience.
  • 5+ years administering and securing Windows and Linux systems including Active Directory, IAM, PKI, baseline hardening, patching, and automation.
  • Hands-on SIEM engineering experience including architecture design, data onboarding, parsing and normalization, detection development, dashboards, and performance optimization.
  • Strong experience with Splunk—including SPL development, Enterprise Security, and API integrations—with exposure to additional SIEM platforms such as Microsoft Sentinel or IBM QRadar.
  • SOAR engineering experience including API-driven automated workflows, enrichment, containment, response playbooks, and scripting for automation.
  • Enterprise EDR administration with direct experience in CrowdStrike Falcon, including sensor deployment, policy tuning, custom IOAs, behavioral detections, threat hunting, and incident response support; experience with Defender for Endpoint or SentinelOne also applicable.
  • Vulnerability and compliance management experience using Qualys or equivalent tools (Tenable, Rapid7), aligned to NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks.
  • Cloud security monitoring experience across AWS, Azure, or GCP including cloud log ingestion and detection engineering.
  • Identity and PAM telemetry correlation experience with Active Directory, Okta, or CyberArk integrated into SIEM and SOAR pipelines.
  • Network monitoring experience including IDS/IPS analysis, NetFlow analytics, and east-west traffic visibility.
  • Strong scripting proficiency in Python and PowerShell/Bash for automation and platform integration.
  • Experience developing detection content aligned to MITRE ATT&CK and performing coverage gap analysis.
  • Ability to integrate and automate security platforms using REST APIs, SDKs, and event-driven pipelines.
  • Strong communication skills and proven ability to interface effectively with technical teams, executives, and customer stakeholders.

Responsibilities

  • Administer, harden, and automate Windows Server and Linux systems; manage Active Directory, IAM, and PKI; apply secure configuration and patch baselines.
  • Design, implement, and operate distributed SIEM architectures and data onboarding pipelines.
  • Develop high-fidelity SIEM detection content, dashboards, and alarms; optimize retention and indexing strategies.
  • Build and maintain SOAR workflows including playbooks for triage, enrichment, and containment.
  • Administer and optimize enterprise EDR platforms; map detections to MITRE ATT&CK; support incident response.
  • Lead vulnerability and compliance programs aligned to NIST/DISA CIS benchmarks; automate remediation.
  • Lead detection engineering and threat intel operations; maintain version control and test pipelines.
  • Maintain platform operations, monitoring, upgrades, and runbooks; serve as Tier III escalation for SIEM/SOAR/EDR.
  • Collaborate across analysts, engineering, and customer stakeholders; mentor engineers; present findings to executives.

Skills

Windows administration
Linux administration
SIEM engineering
SOAR automation
EDR administration
Vulnerability management
Cloud security
Identity and PAM telemetry
Network monitoring
Scripting Python
PowerShell/Bash scripting
MITRE ATT&CK mapping
REST APIs integration

Education

Bachelor's degree or equivalent

Tools

Splunk
CrowdStrike Falcon
Defender for Endpoint
SentinelOne
Qualys
Tenable
Rapid7

Job description

General Dynamics Information Technology in the United States is seeking a Cybersecurity Engineer Principal to join a senior technical role in the SOC. You will own design, implementation, and automation of the SIEM ecosystem, serve as SME for Windows/Linux, EDR, and vulnerability management, and drive detection content, playbooks, and threat intelligence across a multi-customer federal environment.

The role requires deep expertise across SIEM, SOAR, EDR, and vulnerability management with strong

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer Principal: SIEM, EDR & SOC Lead
Cybersecurity Engineer Principal: SIEM, EDR & SOC Lead

General Dynamics Corporation • Bossier City (LA)

Hybrid
USD 146,000 - 198,000
Growth opportunities
Internal mobility team
Competitive benefits
Senior Security Operations Center (SOC) Engineer
Senior Security Operations Center (SOC) Engineer

IT Data Consulting, LLC • Reston (VA)

On-site
USD 110,000 - 140,000
Senior SOC Engineer - Detection, Threat Hunting & SIEM
Senior SOC Engineer - Detection, Threat Hunting & SIEM

IT Data Consulting, LLC • Reston (VA)

On-site
Senior Cyber Systems Administrator - Remote SIEM & Security Expert
Senior Cyber Systems Administrator - Remote SIEM & Security Expert

Digital Management Llc • United States

Remote
USD 102,000 - 128,000
Virtual health visits & wellness
Tuition assistance
401(k) matches
+2
Senior Cyber Defense Engineer — Incident Response & SIEM Lead
Senior Cyber Defense Engineer — Incident Response & SIEM Lead

Selective Insurance • Short Hills (NJ)

On-site
USD 130,000 - 176,000
Cybersecurity Engineer
Cybersecurity Engineer

Vortalsoft Inc • New Jersey

On-site
USD 90,000 - 130,000
Cybersecurity Detection Engineer — SIEM & Automation
Cybersecurity Detection Engineer — SIEM & Automation

Career Listings • Columbus (OH)

On-site
USD 130,000 - 170,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
Cyber Security Engineer—Technical Lead
Cyber Security Engineer—Technical Lead

Leidos • Bethesda (MD)

On-site
USD 150,000 - 180,000
Cybersecurity Detection Engineer: SIEM & Threat Intel
Cybersecurity Detection Engineer: SIEM & Threat Intel

Age Solutions • Columbus (OH)

On-site
USD 85,000 - 120,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+7