System Engineer Sr Principal

General Dynamics Information Technology

Fort Meade (MD)

Hybrid

USD 140,000 - 190,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

General Dynamics Information Technology (GDIT) is seeking a Systems Engineer Sr Principal with a strong cyber and vulnerability management background. This hybrid role focuses on end-to-end vulnerability management, patching, STIG implementation, and sustainment of VMs, network devices, and containers in highly secure environments.

You will apply deep expertise in security baselines, vulnerability tooling, and remediation strategies to reduce risk and improve the security posture of enterprise

Qualifications

  • Active DoW Security Clearance of SECRET or higher.
  • 8+ years of relevant systems engineering experience in secure or mission-critical environments.
  • DoW 8570/8140 requirements compliance (e.g., CCSP, Security+ CE, CISSP, CASP+ or equivalent).
  • Experience with vulnerability management and patching across multi-platform environments.
  • Experience with Microsoft Azure Cloud services (VMs, storage, ARM).
  • Experience with PKI/PIV, AD or LDAP, and Group Policy.

Responsibilities

  • Lead design, implement, and optimize vulnerability management and patching strategies for virtualized infrastructures, network devices, and container workloads.
  • Interpret and implement STIGs, CIS benchmarks, and baselines across OS, applications, networks, and container platforms.
  • Own patch management lifecycle from assessment to verification for timely remediation.
  • Harden and maintain virtual machine environments, ensuring availability, performance, and security.
  • Configure network devices per security policies, STIGs, and best practices.
  • Deploy and maintain container platforms (Docker, Kubernetes/OpenShift) with secure configuration and image scanning.
  • Integrate vulnerability scanning and compliance tools to identify, track, and remediate findings.
  • Collaborate across cybersecurity, network engineering, systems admin, and DevSecOps teams.
  • Participate in incident response and root cause analysis related to vulnerabilities and misconfigurations.
  • Ensure solutions meet DoW directives, RMF/ATO, and NIST SP 800-53.

Skills

Vulnerability management
Patching
STIGs implementation
Security baselines
Azure Cloud
PKI/PIV
Active Directory/LDAP
Group Policy
Docker/Kubernetes/OpenShift
Vulnerability scanning tools
Automation scripting
Networking fundamentals
RMF/NIST

Education

Bachelor’s degree in Computer Science, Information Systems, Engineering, Cybersecurity, or related field

Tools

Tenable/Nessus/ACAS
Ansible
PowerShell
Python
Bash
Docker
Kubernetes/OpenShift
Azure Cloud services

Job description

SYSTEMS ENGINEER PRINCIPAL

General Dynamics Information Technology (GDIT) is seeking a Systems Engineer Sr Principal with a strong cyber and vulnerability management background to support a mission-critical environment. This role will focus on end-to-end vulnerability management, including patching, STIG implementation, and sustainment of virtual machines, network devices, and containers in highly secure environments.

As a senior principal systems engineer, you will apply deep expertise in security configuration baselines, vulnerability assessment tooling, and remediation strategies to reduce risk and improve the security posture of enterprise systems.

This is hybrid position and requires regular on-site support and remote work.

Responsibilities
  • Lead the design, implementation, and optimization of vulnerability management and patching strategies for virtualized infrastructures, network devices, and containerized workloads.
  • Interpret and implement DoW/DISA STIGs, CIS benchmarks, and other security baselines across operating systems, applications, networks, and container platforms.
  • Own the lifecycle of patch management (assessment, planning, testing, deployment, and verification) to ensure timely and compliant remediation of vulnerabilities.
  • Maintain and harden virtual machine environments (e.g., cloud-native VMs), ensuring availability, performance, and security.
  • Configure and maintain network devices (e.g., routers, switches, firewalls) in accordance with security policies, STIGs, and best practices.
  • Deploy and maintain container platforms (e.g., Docker, Kubernetes/OpenShift) with a focus on secure configuration, image scanning, and vulnerability remediation.
  • Integrate and leverage vulnerability scanning tools (e.g., Tenable, Qualys, Rapid7, ACAS) and configuration/compliance tools to identify, track, and remediate findings.
  • Collaborate with cross-functional teams (cybersecurity, network engineering, systems administration, DevSecOps) to ensure cohesive and secure designs and operations.
  • Participate in incident response and root cause analysis related to vulnerabilities, misconfigurations, and system security issues, driving corrective and preventive actions.
  • Ensure solutions meet applicable contractual, regulatory, and compliance requirements (e.g., DoW directives, RMF/ATO, NIST SP 800-53).
Required Qualifications
  • Active DoW Security Clearance of SECRET, or higher
  • 8+ years of relevant systems engineering experience, including work in secure or mission-critical environments.
  • Compliance with DoW 8570/8140 requirements (e.g., CCSP, Security+ CE, CISSP, Security X/CASP+, or equivalent baseline certification).
  • Demonstrated experience leading vulnerability management and patching activities across complex, multi-platform environments.
  • Experience with Microsoft Azure Cloud services such as virtual machines, storage, resource manager, etc.
  • Experience with implementing PKI and PIV standards, Active Directory or LDAP
  • Experience with Group Policy Objects and management
  • Hands-on experience implementing STIGs and security baselines for:
    • Operating systems (e.g., Windows Server, RHEL Linux, Ubuntu)
    • Network devices (e.g., Cisco, Juniper, firewalls)
    • Virtualization platforms and/or container platforms
  • Experience maintaining and securing virtual machine infrastructures (e.g. cloud-based VMs).
  • Experience supporting network infrastructure including configuration, hardening, and troubleshooting of routers, switches, and firewalls.
  • Experience deploying and maintaining container-based environments (e.g., Docker, Kubernetes) with an emphasis on secure configuration and image management.
  • Expertise with vulnerability scanning and compliance tools (e.g., Tenable.sc/Nessus ACAS or similar), including interpreting results and driving remediation.
  • Proficiency with automation and scripting (e.g., Ansible, PowerShell, Python, Bash) for patching, configuration management, and reporting.
  • Strong understanding of networking fundamentals (TCP/IP, routing, witching, DNS, DHCP, VLANs, VPNs) and how they intersect with security best practices.
  • Solid understanding of cybersecurity principles, controls, and frameworks, such as NIST, RMF, and defense-in-depth strategies
  • Strong written and verbal communication skills, including the ability to translate technical risk and remediation plans into language stakeholders understand.
  • Demonstrated ability to work collaboratively across engineering, cybersecurity, operations, and customer teams.
Desired Qualifications
  • Bachelor’s degree in Computer Science, Information Systems, Engineering, Cybersecurity, or related field;
  • Experience in Microsoft Azure Cloud securityimplementations
  • FamiliaritywithNIST 800-207 Zero Trust Architecture
  • FamiliaritywithNIST 800-144 Guidelines on Security and Privacy in Public Cloud Computing
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Engineer Sr Principal
System Engineer Sr Principal

General Dynamics Corporation • Fort Meade (MD), Northern (KY)

Hybrid
USD 133,000 - 181,000
Senior Principal Systems Engineer, Cloud & Security
Senior Principal Systems Engineer, Cloud & Security

General Dynamics Corporation • Fort Meade (MD), Northern (KY)

Hybrid
USD 133,000 - 181,000
Senior Principal Systems Engineer - Cyber Vulnerability
Senior Principal Systems Engineer - Cyber Vulnerability

General Dynamics Information Technology • Fort Meade (MD)

Hybrid
USD 140,000 - 190,000
Cybersecurity Engineer Sr Principal
Cybersecurity Engineer Sr Principal

General Dynamics Information Technology • McLean (VA)

On-site
USD 170,000 - 230,000
Comprehensive benefits
401K with company match
Paid time off
Systems Engineer-Principal
Systems Engineer-Principal

NetSage • Maryland

On-site
USD 150,000 - 210,000
Systems Administrator Lead
Systems Administrator Lead

CACI • Maryland

On-site
USD 110,000 - 160,000
Cybersecurity Engineer Principal
Cybersecurity Engineer Principal

General Dynamics Corporation • Bossier City (LA)

Hybrid
USD 146,000 - 198,000
Growth opportunities
Internal mobility team
Competitive benefits
Senior Principal DevSecOps Engineer
Senior Principal DevSecOps Engineer

Technical Consulting Solutions, Inc. • Huntsville (AL)

On-site
USD 110,000 - 160,000
Health/Dental/Vision
401(k) match
Profit-Sharing
+7
Cyber Engineer (Digital Ecosystem) San Diego, California
Cyber Engineer (Digital Ecosystem) San Diego, California

Precise Systems Inc. • San Diego (CA)

Hybrid
USD 140,000 - 190,000
Principal Software Engineer
Principal Software Engineer

General Dynamics Information Technology • San Antonio (TX)

On-site
USD 119,000 - 161,000
Comprehensive medical, dental, vision, and 401(k) plan
Paid time off
Flexible work options