Cybersecurity Engineer Principal
Listed on 2026-07-31
-
IT/Tech
Cybersecurity
Job Qualifications
Security Monitoring, Security Platforms, System Security
Job DescriptionType of Requisition:
Regular
Clearance Level Must Currently Possess:
None
Clearance Level Must Be Able To Obtain:
None
Public Trust/Other
Required:
None
Job Family:
Cyber and IT Risk Management
Skills:
Job Qualifications:
Security Monitoring, Security Platforms, System Security
Certifications:
None
Experience:
8 + years of related experience
US Citizenship
Required:
Yes
Advance your career while impacting our national security in cyber as a Cybersecurity Engineer Principal e, technologists have many paths to grow a meaningful career supporting cyber missions and operations across the federal government.
As a senior technical contributor within the SOC, the Cybersecurity Engineer Principal owns the design, implementation, optimization, and automation of the security information and event management ecosystem - while also serving as the technical subject matter expert for Windows and Linux systems, Endpoint Detection and Response (EDR), and vulnerability management platforms. This role operates at the intersection of systems engineering, security operations, data engineering, and platform architecture - building and sustaining the telemetry pipelines, detection logic, and tool integrations that power Tier I-III analyst workflows.
The ideal candidate brings deep, vendor-agnostic expertise across operating systems, SIEM, SOAR, EDR, and vulnerability/compliance management, with proven ability to translate that knowledge into operational outcomes in a complex, multi-customer federal environment.
KEY RESPONSIBILITIES- Administer, harden, and automate Windows Server and Linux systems (Red Hat, Rocky, Ubuntu, Amazon Linux); manage Active Directory, IAM, and PKI; apply secure configuration and patch baselines; and develop automation tooling using Power Shell and Bash.
- Design, implement, and operate distributed SIEM architectures including search head/indexer clustering, deployment infrastructure, data store management, and ingestion pipelines; onboard and normalize data sources across forwarders, event collectors, and syslog; develop parsing logic including time stamping, line-breaking, field extraction, and normalization.
- Develop high-fidelity SIEM detection content including correlation searches, dashboards, alerts, and reporting; implement retention/index strategies balancing coverage, cost, and performance; integrate SIEM components via REST APIs, SDKs, and modular inputs with built-in observability and automation validation.
- Build and maintain SOAR automation workflows including playbooks for triage, enrichment, containment, and response; script integrations and operational logic in Python and Power Shell/Bash; integrate ticketing systems, identity platforms, directory services, and threat intelligence feeds; monitor and report automation KPIs.
- Administer and optimize enterprise EDR platforms including sensor deployment, policy management, and behavioral detection tuning; develop custom detections mapped to MITRE ATT&CK; integrate EDR telemetry into SIEM pipelines; conduct endpoint forensics and support containment activities during incident response.
- Operate vulnerability and compliance management programs including scanner infrastructure, schedules, authentication records, baselines, exceptions, and remediation workflows; align assessments with NIST 800-53, FISMA, DISA STIGs, and CIS Benchmarks; integrate findings into SIEM/SOAR for automated remediation, SLA tracking, and trend reporting; produce executive-level reporting on vulnerability posture.
- Lead detection engineering and threat intelligence operations including ATT&CK coverage mapping, proactive threat hunting, detection-as-code lifecycle management, version control, and test pipeline maintenance.
- Maintain platform operations including monitoring pipeline reliability, tuning queries, optimizing summary indexing and data models, managing licensing and capacity, performing upgrades, and maintaining SOPs, runbooks, and architecture documentation; serve as Tier III escalation for SIEM, SOAR, EDR, and vulnerability platforms.
- Provide leadership and collaboration across Tier I-III…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).