Role OverviewGeneral Dynamics Information Technology (GDIT) is seeking a Systems Engineer Sr Principal with a strong cyber and vulnerability management background to support a mission-critical environment. This role will focus on end-to-end vulnerability management, including patching, STIG implementation, and sustainment of virtual machines, network devices, and containers in highly secure environments. As a senior principal systems engineer, you will apply deep expertise in security configuration baselines, vulnerability assessment tooling, and remediation strategies to reduce risk and improve the security posture of enterprise systems. This is a hybrid position and requires regular on-site support and remote work.
What You Will Do
Lead the design, implementation, and optimization of vulnerability management and patching strategies for virtualized infrastructures, network devices, and containerized workloads. Interpret and implement DoD/DISA STIGs, CIS benchmarks, and other security baselines across operating systems, applications, networks, and container platforms. Own the lifecycle of patch management (assessment, planning, testing, deployment, and verification) to ensure timely and compliant remediation of vulnerabilities. Integrate and leverage vulnerability scanning tools (e.g., Tenable, Qualys, Rapid7, ACAS) and configuration/compliance tools to identify, track, and remediate findings.
Why It Might Be a Fit
You have 8+ years of relevant systems engineering experience, including work in secure or mission-critical environments, and an active DoD Security Clearance of SECRET or higher. You have demonstrated experience leading vulnerability management and patching activities across complex, multi-platform environments, with hands-on experience implementing STIGs and security baselines. You are proficient with automation and scripting (e.g., Ansible, PowerShell, Python, Bash) for patching, configuration management, and reporting. The likely salary range for this position is $133,450 - $180,550, and benefits include medical, dental, vision, 401(k) with company match, and paid time off.
Requirements
- Active DoD Security Clearance of SECRET, or higher
- 8+ years of relevant systems engineering experience, including work in secure or mission-critical environments
- Compliance with DoD 8570/8140 requirements (e.g., CCSP, Security+ CE, CISSP, Security X/CASP+, or equivalent baseline certification)
- Demonstrated experience leading vulnerability management and patching activities across complex, multi-platform environments
- Experience with Microsoft Azure Cloud services such as virtual machines, storage, resource manager, etc.
- Experience with implementing PKI and PIV standards, Active Directory or LDAP
- Experience with Group Policy Objects and management
- Hands-on experience implementing STIGs and security baselines for: Operating systems (e.g., Windows Server, RHEL Linux, Ubuntu), Network devices (e.g., Cisco, Juniper, firewalls), Virtualization platforms and/or container platforms
- Experience maintaining and securing virtual machine infrastructures (e.g. cloud-based VMs)
- Experience supporting network infrastructure including configuration, hardening, and troubleshooting of routers, switches, and firewalls
- Experience deploying and maintaining container-based environments (e.g., Docker, Kubernetes) with an emphasis on secure configuration and image management
- Expertise with vulnerability scanning and compliance tools (e.g., Tenable.sc/Nessus ACAS or similar), including interpreting results and driving remediation
- Proficiency with automation and scripting (e.g., Ansible, PowerShell, Python, Bash) for patching, configuration management, and reporting
- Strong understanding of networking fundamentals (TCP/IP, routing, switching, DNS, DHCP, VLANs, VPNs) and how they intersect with security best practices
- Solid understanding of cybersecurity principles, controls, and frameworks, such as NIST, RMF, and defense-in-depth strategies
- Strong written and verbal communication skills, including the ability to translate technical risk and remediation plans into language stakeholders understand
- Demonstrated ability to work collaboratively across engineering, cybersecurity, operations, and customer teams
Benefits
- Medical plan options, some with Health Savings Accounts
- Dental plan options
- Vision plan
- 401(k) plan with company match
- Full flex work weeks where possible
- Paid time off including vacation, sick and personal time, holidays
- Paid parental leave
- Paid military leave
- Paid bereavement leave
- Paid jury duty leave
- Short-term disability benefits
- Long-term disability benefits
- Life insurance
- Accidental death and dismemberment insurance
- Personal accident insurance
- Critical illness insurance
- Business travel and accident insurance
]]>