CybersecurityJobs.io
← Back to all jobs

Job Description

CGI Federal is hiring a Cybersecurity Officer (Entry to Senior Level) in the Intel sector to protect digital assets through continuous monitoring, alert triage, incident support, and security governance. This role is based in the Arlington office with a hybrid working model acceptable.

Key Responsibilities

  • Monitor security tools and dashboards for unusual network traffic or suspicious activity.
  • Review basic security alerts, determine whether they are false alarms, and escalate confirmed threats to senior team members.
  • Serve as first responder to basic security alerts by mitigating minor threats and collecting preliminary data.
  • Assist with granting, removing, and managing employee access to company software and sensitive files.
  • Follow established procedures for minor incidents (for example, locking a compromised account).
  • Continuously review security logs and network traffic to identify suspicious behavior, anomalies, and potential breaches.
  • Write simple reports that summarize diagnostic test results or security events.
  • Escalate complex or high-severity cyber attacks to Level 2 or Level 3 senior security teams.
  • Execute diagnostic tests and vulnerability scans to identify potential weaknesses in systems and networks.
  • Apply antivirus updates, firewall configurations, and security patches across enterprise environments.
  • Document known vulnerabilities and draft regular system status reports for management.
  • Enforce organizational security policies and ensure adherence to statutory or regulatory requirements related to information access and privacy.
  • Grant, review, and revoke user access credentials to maintain least-privilege practices.
  • Conduct periodic security audits to measure compliance and identify inefficiencies.
  • Lead or assist with employee cybersecurity awareness training and phishing simulations.
  • Provide technical consultation and security best-practice documentation to staff.
  • Lead investigation of complex security alerts escalated from Level 1, including root-cause determination, blast-radius scoping, and rapid containment actions.
  • Conduct proactive threat hunting using endpoint data, network telemetry, and actionable intelligence.
  • Analyze system logs to identify abnormalities and suspicious network signals.
  • Configure, fine-tune, and deploy security solutions such as SIEM, EDR, firewalls, and DLP.
  • Author custom detection rules and detection playbooks.
  • Perform enterprise-level risk assessments, enforce adherence to security legislation, and manage security documentation (including SSPs, ATO lifecycle, and security controls).
  • Guide junior SOC or Level 1 analysts and communicate complex technical risks to executive leadership and IT teams through detailed post-mortem reports.
  • Conduct deep-dive threat hunting missions using hypothesis-driven methodologies to uncover covert and deeply embedded threats, including zero-day threats within enterprise architecture.
  • Intercept, deconstruct, and analyze complex malware, ransomware, and malicious binaries to understand execution, C2 infrastructure, and exfiltration pathways.
  • Lead the technical command of catastrophic and nation-state-level security incidents.
  • Perform forensic analysis across endpoints, networks, and cloud infrastructures, then execute surgical eradication and recovery protocols.
  • Review complex system designs, microservices, and network topologies.
  • Provide architectural oversight on encryption protocols, data protection in transit and at rest, and secure hardware/software integrations.
  • Conduct authorized red-team-style exploitation testing to simulate real-world attacks.
  • Contribute to threat intelligence and secure coding hardening guides.
  • Translate complex technical findings and threat landscapes into actionable, high-level strategic directives for executive leadership and stakeholders.

Required Clearance

  • All levels require an active TS/SCI with Poly.

Level-Specific Education and Experience

  • Entry Level: High School Diploma/GED with 4 years of relevant experience, or Associate’s Degree with 2 years of relevant experience, or Bachelor’s Degree with 0 years of relevant experience.
  • Junior Level/Moderate: High School Diploma/GED with 6 years of relevant experience, or Associate’s Degree with 4 years of relevant experience, or Bachelor’s Degree with 2 years of relevant experience, or Master’s Degree with 0 years of relevant experience.
  • Mid-Level/Complex: High School Diploma/GED with 8 years of relevant experience, or Associate’s Degree with 6 years of relevant experience, or Bachelor’s Degree with 4 years of relevant experience, or Master’s Degree with 2 years of relevant experience, or PhD with 0 years of relevant experience.
  • Senior Level/Exceptionally Complex: High School Diploma/GED with 10 years of relevant experience, or Associate’s Degree with 8 years of relevant experience, or Bachelor’s Degree with 6 years of relevant experience, or Master’s Degree with 4 years of relevant experience, or PhD with 2 years of relevant experience.

Skills and Qualifications

  • Basic IT Knowledge: Computer networks (for example, IP addresses and routers) and operating systems such as Windows, macOS, or Linux.
  • Problem-Solving: Strong critical thinking and the ability to research unfamiliar issues.
  • Communication: Ability to explain technical issues to non-technical coworkers or management.
  • Technical Skills: Working knowledge of TCP/IP, firewalls, endpoint security, and intrusion detection systems.
  • Technical Proficiencies (Mid/Senior): Strong working knowledge of Linux, Windows, macOS, networking protocols (TCP/IP), and cloud architecture (AWS, Azure), plus basic scripting knowledge (Python, PowerShell) where applicable.
  • Advanced Technical Proficiencies (Senior): Mastery of SIEM, SOAR, and EDR platforms; deep understanding of network protocols, cloud-native architecture security; and scripting/programming languages including Python, C, C++, or Assembly.

Certifications

  • Foundational certifications such as CompTIA Security+, Network+, or ISC2 CC are highly recommended for beginners.
  • Junior Level/Moderate: foundational certifications such as CompTIA Security+, [ISC] CCSP, or [CodeHS] are highly valued.
  • Mid-Level/Complex: industry-recognized certifications such as CompTIA Security+, GIAC Certified Incident Handler (GCIH), or CISSP.
  • Senior Level/Exceptionally Complex: elite credentials such as CISSP, GIAC Security Expert (GSE), OSCP, or CCIE Security.

Technologies

  • Windows, macOS, Linux
  • IP addresses, routers, TCP/IP
  • Firewalls, endpoint security, intrusion detection systems
  • SIEM, EDR, DLP, SOAR
  • AWS, Azure
  • Python, PowerShell, C, C++, Assembly

Location and Compensation

  • Location: Arlington, VA (hybrid)
  • Salary: USD 89,600 to 204,000 per year

Benefits

  • Competitive compensation
  • Comprehensive insurance options
  • Matching contributions through the 401(k) plan and the share purchase plan
  • Paid time off for vacation, holidays, and sick time
  • Paid parental leave
  • Learning opportunities and tuition assistance
  • Wellness and Well-being programs

Similar Jobs