> Markdown version of [/jobs/ext/1497773-cybersecurity-engineer-principal](https://www.wearedevelopers.com/jobs/ext/1497773-cybersecurity-engineer-principal). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer Principal - **Company:** General Dynamics Information Technology - **Location:** Bossier City, LA, United States - **Experience:** Expert - **Salary:** $146,200.0 - $197,800.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Computing Platforms, Systems Engineering, User Authentication, Microsoft Azure, Baselining, Bash Shell, Ubuntu (Operating System), Cloud Computing Security, Cluster Analysis, Cyber Security, Information Engineering, Data Stores, Linux, Identity and Access Management, Issue Tracking Systems, Intrusion Detection and Prevention, Intrusion Detection Systems, Python (Programming Language), Windows Servers, NetFlow, Network Monitoring, Parsing, Performance Tuning, Public Key Infrastructure, Windows PowerShell, Red Hat Enterprise Linux, Security Information and Event Management, Systems Integration, Software Vulnerability Management, EndPointSecurity, Scripting, Okta, Data Ingestion, Cyberark, Mitre Att&ck, QRadar, Cyber Threat Analysis, Infrastructure Automation Frameworks, Cybercrime, Microsoft Sentinel, Cortex XSOAR Platform, CIS Benchmarks, Api Design, Restful APIs, Splunk, SentinelOne Expertise, Software Version Control, Api Management, Qualys, Security Orchestration, Automation & Response - **Published:** July 30, 2026 - **Apply:** https://dejobs.org/x/x/69C53A5FF14448479EBF8644F3563E65/job/ ## About the Role Security Monitoring,Security Platforms,System Security Experience: 8 + years of related experience, The ideal candidate brings deep, vendor-agnostic expertise across operating systems, SIEM, SOAR, EDR, and vulnerability/compliance management, with proven ability to translate that knowledge into operational outcomes in a complex, multi-customer federal environment., * BA/BS or equivalent and 8+ years of progressive cybersecurity, SOC, or security engineering experience. * 5+ years administering and securing Windows and Linux systems including Active Directory, IAM, PKI, baseline hardening, patching, and automation. * Hands-on SIEM engineering experience including architecture design, data onboarding, parsing and normalization, detection development, dashboards, and performance optimization. * Strong experience with Splunk-including SPL development, Enterprise Security, and API integrations-with exposure to additional SIEM platforms such as Microsoft Sentinel or IBM QRadar. * SOAR engineering experience including API-driven automated workflows, enrichment, containment, response playbooks, and scripting for automation. * Enterprise EDR administration with direct experience in CrowdStrike Falcon, including sensor deployment, policy tuning, custom IOAs, behavioral detections, threat hunting, and incident response support; experience with Defender for Endpoint or SentinelOne also applicable. * Vulnerability and compliance management experience using Qualys or equivalent tools (Tenable, Rapid7), aligned to NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks. * Cloud security monitoring experience across AWS, Azure, or GCP including cloud log ingestion and detection engineering. * Identity and PAM telemetry correlation experience with Active Directory, Okta, or CyberArk integrated into SIEM and SOAR pipelines. * Network monitoring experience including IDS/IPS analysis, NetFlow analytics, and east-west traffic visibility. * Strong scripting proficiency in Python and PowerShell/Bash for automation and platform integration. * Experience developing detection content aligned to MITRE ATT&CK and performing coverage gap analysis. * Ability to integrate and automate security platforms using REST APIs, SDKs, and event-driven pipelines. * Strong communication skills and proven ability to interface effectively with technical teams, executives, and customer stakeholders. Required certifications: * Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk ES Certified Admin within 6 months of hire * Splunk SOAR or Palo Alto XSOAR certification within 6 months of hire * DoD 8140/DCWF CSSP Analyst within 6 months of hire Security Clearance Level: Ability to pass a background check to obtain and maintain suitability for multi-agency federal/state support. ## Description Advance your career while impacting our national security in cyber as a Cybersecurity Engineer Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government., As a senior technical contributor within the SOC, the Cybersecurity Engineer Principal owns the design, implementation, optimization, and automation of the security information and event management ecosystem - while also serving as the technical subject matter expert for Windows and Linux systems, Endpoint Detection and Response (EDR), and vulnerability management platforms. This role operates at the intersection of systems engineering, security operations, data engineering, and platform architecture - building and sustaining the telemetry pipelines, detection logic, and tool integrations that power Tier I-III analyst workflows., * Administer, harden, and automate Windows Server and Linux systems (Red Hat, Rocky, Ubuntu, Amazon Linux); manage Active Directory, IAM, and PKI; apply secure configuration and patch baselines; and develop automation tooling using PowerShell and Bash. * Design, implement, and operate distributed SIEM architectures including search head/indexer clustering, deployment infrastructure, data store management, and ingestion pipelines; onboard and normalize data sources across forwarders, event collectors, and syslog; develop parsing logic including timestamping, line-breaking, field extraction, and normalization. * Develop high-fidelity SIEM detection content including correlation searches, dashboards, alerts, and reporting; implement retention/index strategies balancing coverage, cost, and performance; integrate SIEM components via REST APIs, SDKs, and modular inputs with built-in observability and automation validation. * Build and maintain SOAR automation workflows including playbooks for triage, enrichment, containment, and response; script integrations and operational logic in Python and PowerShell/Bash; integrate ticketing systems, identity platforms, directory services, and threat intelligence feeds; monitor and report automation KPIs. * Administer and optimize enterprise EDR platforms including sensor deployment, policy management, and behavioral detection tuning; develop custom detections mapped to MITRE ATT&CK; integrate EDR telemetry into SIEM pipelines; conduct endpoint forensics and support containment activities during incident response. * Operate vulnerability and compliance management programs including scanner infrastructure, schedules, authentication records, baselines, exceptions, and remediation workflows; align assessments with NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks; integrate findings into SIEM/SOAR for automated remediation, SLA tracking, and trend reporting; produce executive-level reporting on vulnerability posture. * Lead detection engineering and threat intelligence operations including ATT&CK coverage mapping, proactive threat hunting, detection-as-code lifecycle management, version control, and test pipeline maintenance. * Maintain platform operations including monitoring pipeline reliability, tuning queries, optimizing summary indexing and data models, managing licensing and capacity, performing upgrades, and maintaining SOPs, runbooks, and architecture documentation; serve as Tier III escalation for SIEM, SOAR, EDR, and vulnerability platforms. * Provide leadership and collaboration across Tier I-III analysts, engineering teams, and customer stakeholders; mentor engineers; drive post-incident reviews into measurable improvements; and coordinate with architecture, infrastructure, network, and cloud teams while presenting technical information clearly to both executive and technical audiences. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [The best of two worlds - Bringing enterprise-grade Linux to the vehicle](https://www.wearedevelopers.com/videos/67-the-best-of-two-worlds-bringing-enterprise-grade-linux-to-the-vehicle) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)