Hiring.Camp

Cybersecurity Engineer Principal

GDIT

·

Today

Salary
$146k – $198k
Location
USA LA Bossier City - 6310 E Texas St (LAS004), United States of America
Type
Full-time
Department
Engineering
Seniority
Lead
Source
Workday

Description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

None

Clearance Level Must Be Able to Obtain:

None

Public Trust/Other Required:

None

Job Family:

Cyber and IT Risk Management

Job Qualifications:

Skills:

Security Monitoring, Security Platforms, System Security

Certifications:

None

Experience:

8 + years of related experience

US Citizenship Required:

Yes

Job Description:

Advance your career while impacting our national security in cyber as a Cybersecurity Engineer Principal at GDIT. Here, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.

As a senior technical contributor within the SOC, the Cybersecurity Engineer Principal owns the design, implementation, optimization, and automation of the security information and event management ecosystem — while also serving as the technical subject matter expert for Windows and Linux systems, Endpoint Detection and Response (EDR), and vulnerability management platforms. This role operates at the intersection of systems engineering, security operations, data engineering, and platform architecture — building and sustaining the telemetry pipelines, detection logic, and tool integrations that power Tier I–III analyst workflows.

The ideal candidate brings deep, vendor-agnostic expertise across operating systems, SIEM, SOAR, EDR, and vulnerability/compliance management, with proven ability to translate that knowledge into operational outcomes in a complex, multi-customer federal environment.

KEY RESPONSIBILITIES:

  • Administer, harden, and automate Windows Server and Linux systems (Red Hat, Rocky, Ubuntu, Amazon Linux); manage Active Directory, IAM, and PKI; apply secure configuration and patch baselines; and develop automation tooling using PowerShell and Bash.
  • Design, implement, and operate distributed SIEM architectures including search head/indexer clustering, deployment infrastructure, data store management, and ingestion pipelines; onboard and normalize data sources across forwarders, event collectors, and syslog; develop parsing logic including timestamping, line‑breaking, field extraction, and normalization.
  • Develop high‑fidelity SIEM detection content including correlation searches, dashboards, alerts, and reporting; implement retention/index strategies balancing coverage, cost, and performance; integrate SIEM components via REST APIs, SDKs, and modular inputs with built‑in observability and automation validation.
  • Build and maintain SOAR automation workflows including playbooks for triage, enrichment, containment, and response; script integrations and operational logic in Python and PowerShell/Bash; integrate ticketing systems, identity platforms, directory services, and threat intelligence feeds; monitor and report automation KPIs.
  • Administer and optimize enterprise EDR platforms including sensor deployment, policy management, and behavioral detection tuning; develop custom detections mapped to MITRE ATT&CK; integrate EDR telemetry into SIEM pipelines; conduct endpoint forensics and support containment activities during incident response.
  • Operate vulnerability and compliance management programs including scanner infrastructure, schedules, authentication records, baselines, exceptions, and remediation workflows; align assessments with NIST 800‑53, FISMA, DISA STIGs, and CIS Benchmarks; integrate findings into SIEM/SOAR for automated remediation, SLA tracking, and trend reporting; produce executive‑level reporting on vulnerability posture.
  • Lead detection engineering and threat intelligence operations including ATT&CK coverage mapping, proactive threat hunting, detection‑as‑code lifecycle management, version control, and test pipeline maintenance.
  • Maintain platform operations including monitoring pipeline reliability, tuning queries, optimizing summary indexing and data models, managing licensing and capacity, performing upgrades, and maintaining SOPs, runbooks, and architecture documentation; serve as Tier III escalation for SIEM, SOAR, EDR, and vulnerability platforms.
  • Provide leadership and collaboration across Tier I–III analysts, engineering teams, and customer stakeholders; mentor engineers; drive post‑incident reviews into measurable improvements; and coordinate with architecture, infrastructure, network, and cloud teams while presenting technical information clearly to both executive and technical audiences.

REQUIRED SKILLS/EXPERIENCE:

  • BA/BS or equivalent and 8+ years of progressive cybersecurity, SOC, or security engineering experience.
  • 5+ years administering and securing Windows and Linux systems including Active Directory, IAM, PKI, baseline hardening, patching, and automation.
  • Hands‑on SIEM engineering experience including architecture design, data onboarding, parsing and normalization, detection development, dashboards, and performance optimization.
  • Strong experience with Splunk—including SPL development, Enterprise Security, and API integrations—with exposure to additional SIEM platforms such as Microsoft Sentinel or IBM QRadar.
  • SOAR engineering experience including API‑driven automated workflows, enrichment, containment, response playbooks, and scripting for automation.
  • Enterprise EDR administration with direct experience in CrowdStrike Falcon, including sensor deployment, policy tuning, custom IOAs, behavioral detections, threat hunting, and incident response support; experience with Defender for Endpoint or SentinelOne also applicable.
  • Vulnerability and compliance management experience using Qualys or equivalent tools (Tenable, Rapid7), aligned to NIST 800‑53, FISMA, DISA STIGs, and CIS Benchmarks.
  • Cloud security monitoring experience across AWS, Azure, or GCP including cloud log ingestion and detection engineering.
  • Identity and PAM telemetry correlation experience with Active Directory, Okta, or CyberArk integrated into SIEM and SOAR pipelines.
  • Network monitoring experience including IDS/IPS analysis, NetFlow analytics, and east‑west traffic visibility.
  • Strong scripting proficiency in Python and PowerShell/Bash for automation and platform integration.
  • Experience developing detection content aligned to MITRE ATT&CK and performing coverage gap analysis.
  • Ability to integrate and automate security platforms using REST APIs, SDKs, and event‑driven pipelines.
  • Strong communication skills and proven ability to interface effectively with technical teams, executives, and customer stakeholders.

Required certifications:

  • Splunk Core Certified Power User, Splunk Enterprise Certified Admin, or Splunk ES Certified Admin within 6 months of hire
  • Splunk SOAR or Palo Alto XSOAR certification within 6 months of hire
  • DoD 8140/DCWF CSSP Analyst within 6 months of hire

Security Clearance Level: Ability to pass a background check to obtain and maintain suitability for multi‑agency federal/state support.

US Citizenship is required.

Location: Hybrid in Bossier City, LA

GDIT IS YOUR PLACE
At GDIT, the mission is our purpose, and our people are at the center of everything we do.

  • Growth: AI-powered career tool that identifies career steps and learning opportunities

  • Support: An internal mobility team focused on helping you achieve your career goals

  • Rewards: Comprehensive benefits and wellness packages, 401K with company match, and competitive pay and paid time off

  • Community: Award-winning culture of innovation and a military-friendly workplace


OWN YOUR OPPORTUNITY
Explore an enterprise IT career at GDIT and you’ll find endless opportunities to grow alongside colleagues who share your desire to drive operations forward.

#GDITLA

The likely salary range for this position is $146,200 - $197,800. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

Less than 10%

Telecommuting Options:

Hybrid

Work Location:

USA LA Bossier City

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

 

 


Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

 

 

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.

Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Skills

PythonAWSAzureGCPLinuxData EngineeringCybersecuritySIEMSOCSplunkRESTRisk ManagementCompliance

Similar Jobs

30

Principal Engineer, Cybersecurity

Baxter · NY0300 - Skaneateles Falls, NY, United States of America

6 days ago

Principal Cybersecurity Engineer

Forcepoint · Home Office - Texas, United States of America · Remote, Onsite

1 week ago

Principal Cybersecurity Engineer

Starfish · Hanscom AFB, United States of America

1 month ago

Cybersecurity Engineer Principal

GDIT · USA FL MacDill AFB - MacDill AFB (FLC007), United States of America · Remote, Hybrid

1 month ago

Cybersecurity Engineer Principal

Gdit · USA FL MacDill AFB - MacDill AFB (FLC007), United States of America · Remote, Hybrid

1 month ago

Principal Cybersecurity Engineer

Rocketlab · Long Beach, CA +1

1 month ago

Cybersecurity Engineer Principal

GDIT · USA FL MacDill AFB - MacDill AFB (FLC007), United States of America · Remote, Hybrid

1 month ago

Cybersecurity Engineer Principal

Gdit · USA FL MacDill AFB - MacDill AFB (FLC007), United States of America · Remote, Hybrid

1 month ago

Cybersecurity Engineer Principal

GDIT · USA VA Fort Belvoir - 8725 John J Kingman Rd (VAC375), United States of America

1 month ago

Cybersecurity Engineer Principal

Gdit · USA VA Fort Belvoir - 8725 John J Kingman Rd (VAC375), United States of America

1 month ago

Principal Cybersecurity Engineer

Twosixtechnologies · Arlington, Virginia +1 · Onsite

1 month ago

Principal Cybersecurity Engineer

Wabtec · Bengaluru, KA, India

1 month ago

Principal Cybersecurity Engineer

Fluenceenergy · India - Bangalore · Onsite

2 months ago

Principal Cybersecurity Engineer

Workday · USA.VA.Reston, United States of America

2 months ago

Principal Engineer - Cybersecurity

Harman · In_Bangalore_ Kalyani Platina_HII, India

2 months ago

Principal Cybersecurity Engineer

HiNext · (STS) Brisbane - Office, Australia · Onsite

3 months ago

Principal Cybersecurity Engineer

Huntington · Easton Ops Cols C Oh, United States of America +5 · Onsite

3 months ago

Principal Cybersecurity Engineer

Robert Bosch · bangalore, India

4 months ago

Principal Cybersecurity Engineer

Medtronic · IND-TS Hyderabad Nanakramguda, India

6 months ago

Principal Cybersecurity Engineer

Medtronic · IND-TS Hyderabad Nanakramguda, India

6 months ago

Principal Cybersecurity Engineer

RTX · AU-NSW-SYDNEY-012 ~ 12 Mars Rd ~ MARS BLDG 8, Lane Cove, Australia · Remote, Onsite

9 months ago

Principal Cybersecurity Engineer

Libertymutual · Portsmouth, NH, US · Remote, Hybrid, Onsite

1+ year ago

Cybersecurity Principal Engineer - HYBRID ROLE

vrtx · 5000 - Vertex US - Fan Pier, United States of America · Remote, Hybrid, Onsite

4 days ago

Principal Cybersecurity Engineer – Firewall Platforms: Firewall Policy with Operational Artificial Intelligence (AI)

Att · USA:NC:Charlotte / Ibm Dr - Adm:8505 Ibm Dr, United States of America +4 · Remote

4 days ago

Senior Principal Cybersecurity Engineer

Aptiv · USA Remote Worksite, United States of America · Remote

1 week ago

AI Cybersecurity Engineer Principal

Huntington · Ohio (Central Ohio Region), United States of America +7 · Remote

2 weeks ago

Principal Cybersecurity Engineer, Telco

Tmobile · WA-Headquarters, Building 1, United States of America +2

4 weeks ago

Principal Cybersecurity Engineer - US Federal

Workday · USA.VA.Reston, United States of America

1 month ago

R&D Principal Engineer Cybersecurity

Abb · Vaesteras, Sweden +2

2 months ago

Principal Cybersecurity Engineer - US Federal

Workday · USA.VA.Reston, United States of America

2 months ago