Senior Cybersecurity Engineer: SIEM, EDR & Threat Hunting

General Dynamics Information Technology

Bossier City (LA)

Hybrid

USD 146,000 - 198,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health benefits
401K with company match
Paid time off

Job summary

General Dynamics Information Technology in the United States (Hybrid in Bossier City, LA) is seeking a Cybersecurity Engineer Principal to own and optimize the SIEM/SOAR ecosystem while serving as the subject matter expert for Windows and Linux, EDR, and vulnerability management platforms.

You will design, implement, and automate security telemetry pipelines and detection logic to support Tier I–III analysts.

Qualifications

  • BA/BS or equivalent and 8+ years of progressive cybersecurity, SOC, or security engineering experience.
  • 5+ years administering and securing Windows and Linux systems including Active Directory, IAM, PKI, baseline hardening, patching, and automation.
  • Hands-on SIEM engineering including architecture design, data onboarding, parsing and normalization, detection development, dashboards, and performance optimization.
  • Strong experience with Splunk—including SPL development, Enterprise Security, and API integrations—with exposure to additional SIEM platforms such as Microsoft Sentinel or IBM QRadar.
  • SOAR engineering including API-driven automated workflows, enrichment, containment, response playbooks, and scripting for automation.
  • Enterprise EDR administration with direct experience in CrowdStrike Falcon, including sensor deployment, policy tuning, custom IOAs, behavioral detections, threat hunting, and incident response support; Defender for Endpoint or SentinelOne also applicable.
  • Vulnerability and compliance management experience using Qualys or equivalent tools (Tenable, Rapid7) aligned to NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks.
  • Cloud security monitoring experience across AWS, Azure, or GCP including cloud log ingestion and detection engineering.
  • Identity and PAM telemetry correlation experience with Active Directory, Okta, or CyberArk integrated into SIEM and SOAR pipelines.
  • Network monitoring experience including IDS/IPS analysis, NetFlow analytics, and east-west traffic visibility.
  • Strong scripting proficiency in Python and PowerShell/Bash for automation and platform integration.
  • Experience developing detection content aligned to MITRE ATT&CK and performing coverage gap analysis.
  • Ability to integrate and automate security platforms using REST APIs, SDKs, and event-driven pipelines.
  • Strong communication skills and proven ability to interface effectively with technical teams, executives, and customer stakeholders.

Responsibilities

  • Administer, harden, and automate Windows Server and Linux systems (Red Hat, Rocky, Ubuntu, Amazon Linux); manage Active Directory, IAM, and PKI; apply secure configuration and patch baselines; and develop automation tooling using PowerShell and Bash.
  • Design, implement, and operate distributed SIEM architectures including search head/indexer clustering, deployment infrastructure, data store management, and ingestion pipelines; onboard and normalize data sources across forwarders, event collectors, and syslog; develop parsing logic including timestamping, line-breaking, field extraction, and normalization.
  • Develop high-fidelity SIEM detection content including correlation searches, dashboards, alerts, and reporting; implement retention/index strategies balancing coverage, cost, and performance; integrate SIEM components via REST APIs, SDKs, and modular inputs with built-in observability and automation validation.
  • Build and maintain SOAR automation workflows including playbooks for triage, enrichment, containment, and response; script integrations and operational logic in Python and PowerShell/Bash; integrate ticketing systems, identity platforms, directory services, and threat intelligence feeds; monitor and report automation KPIs.
  • Administer and optimize enterprise EDR platforms including sensor deployment, policy management, and behavioral detection tuning; develop custom detections mapped to MITRE ATT&CK; integrate EDR telemetry into SIEM pipelines; conduct endpoint forensics and support containment activities during incident response.
  • Operate vulnerability and compliance management programs including scanner infrastructure, schedules, authentication records, baselines, exceptions, and remediation workflows; align assessments with NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks; integrate findings into SIEM/SOAR for automated remediation, SLA tracking, and trend reporting; produce executive-level reporting on vulnerability posture.
  • Lead detection engineering and threat intelligence operations including ATT&CK coverage mapping, proactive threat hunting, detection-as-code lifecycle management, version control, and test pipeline maintenance.
  • Maintain platform operations including monitoring pipeline reliability, tuning queries, optimizing summary indexing and data models, managing licensing and capacity, performing upgrades, and maintaining SOPs, runbooks, and architecture documentation; serve as Tier III escalation for SIEM, SOAR, EDR, and vulnerability platforms.
  • Provide leadership and collaboration across Tier I–III analysts, engineering teams, and customer stakeholders; mentor engineers; drive post-incident reviews into measurable improvements; and coordinate with architecture, infrastructure, network, and cloud teams while presenting technical information clearly to both executive and technical audiences.

Skills

Security Monitoring
Security Platforms
System Security

Tools

Splunk
EDR (CrowdStrike)
Defender for Endpoint / SentinelOne

Job description

General Dynamics Information Technology in the United States (Hybrid in Bossier City, LA) is seeking a Cybersecurity Engineer Principal to own and optimize the SIEM/SOAR ecosystem while serving as the subject matter expert for Windows and Linux, EDR, and vulnerability management platforms.

You will design, implement, and automate security telemetry pipelines and detection logic to support Tier I–III analysts.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer Principal: SIEM, EDR & SOC Lead
Cybersecurity Engineer Principal: SIEM, EDR & SOC Lead

General Dynamics Corporation • Bossier City (LA)

Hybrid
USD 146,000 - 198,000
Growth opportunities
Internal mobility team
Competitive benefits
Senior Information Security Analyst (TS/SCI) – Cyber Defense Lead
Senior Information Security Analyst (TS/SCI) – Cyber Defense Lead

General Dynamics Information Technology, Inc. • Fort Bragg (CA)

On-site
USD 94,000 - 127,000
Cybersecurity Analyst Principal: IDS/IPS & Splunk Lead
Cybersecurity Analyst Principal: IDS/IPS & Splunk Lead

General Dynamics Information Technology (GDIT) • Washington

On-site
USD 149,000 - 201,000
Health benefits
401K with company match
Paid time off
+2
Cybersecurity Systems Administrator: SIEM, EDR & SOAR Lead
Cybersecurity Systems Administrator: SIEM, EDR & SOAR Lead

General Dynamics Information Technology (GDIT) • Tampa (FL)

On-site
USD 90,000 - 120,000
401K with company match
Paid time off
Flexible work weeks where possible
Principal Cybersecurity Analyst, IDS/IPS Lead
Principal Cybersecurity Analyst, IDS/IPS Lead

General Dynamics Information Technology • Washington

On-site
USD 130,000 - 170,000
Comprehensive benefits
401K with company match
Paid time off
Cybersecurity Systems Admin - SIEM/EDR & SOAR Lead
Cybersecurity Systems Admin - SIEM/EDR & SOAR Lead

General Dynamics Information Technology • Tampa (FL)

Hybrid
USD 110,000 - 150,000
401K with company match
Paid time off
Wellness programs
Cyber Defense Principal: IDS/IPS & Data Analytics
Cyber Defense Principal: IDS/IPS & Data Analytics

General Dynamics Information Technology • Reston (VA)

On-site
USD 149,000 - 201,000
Medical, dental, vision plans
401(k) with company match
Paid time off
Cybersecurity Engineer Principal
Cybersecurity Engineer Principal

General Dynamics Corporation • Bossier City (LA)

Hybrid
USD 146,000 - 198,000
Growth opportunities
Internal mobility team
Competitive benefits
IDS/IPS Lead & Splunk Expert for Cyber Defense
IDS/IPS Lead & Splunk Expert for Cyber Defense

General Dynamics Information Technology (GDIT) • Reston (VA)

On-site
USD 149,000 - 201,000
Medical plan options
401(k) with company match
Paid time off
Cyber Defense IDS Lead - Splunk & Signatures Expert
Cyber Defense IDS Lead - Splunk & Signatures Expert

General Dynamics Information Technology, Inc. • Washington

On-site
USD 149,000 - 201,000
AI‑driven career tools
Internal mobility support
Total rewards & benefits