Cybersecurity Systems Engineer (Entry Level to SME)
Job Description
CGI Federal is seeking Cybersecurity Systems Engineers (Entry Level to SME) to support national security efforts within the Intel sector. The role focuses on maintaining and securing IT infrastructure while delivering cyber defense capabilities in a hybrid environment based in Arlington, Virginia.
Responsibilities
As part of the cybersecurity engineering team, you will support day-to-day operations and contribute to incident readiness and risk reduction activities.
- Assist in maintaining and upgrading basic security software such as antivirus, firewalls, and endpoint protection.
- Monitor networks and servers for unusual activity and policy violations.
- Run routine vulnerability scans and help patch outdated software.
- Write and organize technical reports, standard operating procedures, and security system documentation.
- Support senior engineers during security investigations by gathering logs and basic data.
- Assist with the operation, configuration, and maintenance of host-based, network-based, and cloud-based security systems.
- Help implement and maintain hardware and software configuration management processes aligned to industry best practices (for example, DISA STIGs if applicable).
- Monitor security logs, analyze event alerts, and manage ticket queues for system and security issues.
- Conduct vulnerability assessments and risk analyses to identify weaknesses and prioritize patching or remediation.
- Assist with technical security documentation, support Assessment and Authorization (A&A) activities, and help track compliance.
- Participate in tactical Cyber Incident Response Team (CIRT) execution by investigating suspicious activity and securing system boundaries.
- Design, implement, and maintain COTS and custom security products, including firewalls, SIEM tools, and identity management systems.
- Deploy and secure software applications within virtualized infrastructures and highly distributed cloud computing environments.
- Manage and secure endpoint baselines across operating systems such as Linux (Red Hat, Ubuntu) and Windows.
- Contribute to Agile/DevSecOps teams by automating security testing and integrating controls into CI/CD pipelines.
- Perform static and dynamic source code analysis (SAST/DAST) and manage application vulnerabilities as technical debt within backlogs.
- Support root cause analysis for security incidents and recommend mitigations to improve the security posture.
- Coordinate vulnerability scanning, patch management, and threat hunting across enterprise and operational environments.
- Implement and audit technical controls against compliance frameworks including NIST SP 800-53, NIST 800-171, or CMMC Level 2.
- Prepare and execute testing procedures to assess conformance with DoD, Federal Civilian, or Intelligence Community requirements.
- Draft and maintain systems engineering documentation such as System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and Interface Control Documents (ICDs).
- Architect, implement, and validate integrated hardware, software, and firmware security solutions for complex environments.
- Perform attack surface analyses and decompose system-level security controls into technical performance requirements (including Anti-Tamper and cryptography as applicable).
- Design zero-trust environments and implement Infrastructure as Code (IaC) with Terraform for securely deploying Mission Unique Software (MUS) in highly virtualized clouds.
- Lead the RMF process from system categorization through continuous monitoring (ConMon), ensuring compliance with strict federal or commercial controls.
- Triage findings from Static Code Analysis (SCA) and help establish technical debt in the software backlog.
- Use tools such as ACAS for vulnerability scanning, patch management, and deviation mitigation assessment.
- Design and deploy security systems such as SIEM, EDR, and XDR, including support during critical incidents or cyber test and evaluation.
- Automate repetitive security tasks and identity workflows, with experience scripting in Python or PowerShell strongly required.
- Architect enterprise-wide cyber systems by embedding security into design across hardware, software, and network components at OSI layers.
- Manage RMF activities including Attack Surface Analyses (ASA), Security Control Traceability Matrices (SCTM), and POA&Ms.
- Conduct advanced risk assessments, threat modeling, SCA triaging, and flaw remediation.
- Lead tactical CIRT operations, perform forensic preservation, and resolve non-standard vulnerabilities.
- Serve as a technical point of contact, lead design reviews with stakeholders, and mentor junior or mid-level engineering staff.
Requirements
- All levels require an active TS/SCI with Poly.
- Entry Level: High School Diploma/GED with 4 years of relevant experience, or Associates Degree with 2 years of relevant experience, or Bachelors Degree with 0 years of relevant experience.
- Entry Level: Foundational certifications such as CompTIA Security+, Network+, or similar vendor-specific badges.
- Entry Level: Basic understanding of networking protocols, operating systems (Windows/Linux), and fundamental security concepts.
- Junior Level/Moderate: High School Diploma/GED with 6 years of relevant experience, or Associates Degree with 4 years of relevant experience, or Bachelors Degree with 2 years of relevant experience, or Masters Degree with 0 years of relevant experience.
- Junior Level/Moderate: Understanding of operating systems (Windows/Linux), network protocols (TCP/IP), and security platforms such as SIEM, EDR, or firewalls.
- Junior Level/Moderate: Foundational certifications such as CompTIA Security+, Network+, or similar vendor-specific credentials are highly valued (for example, Cisco CCNA, AWS/Azure certifications).
- Mid-Level/Complex: High School Diploma/GED with 8 years of relevant experience, or Associates Degree with 6 years of relevant experience, or Bachelors Degree with 4 years of relevant experience, or Masters Degree with 2 years of relevant experience, or PhD with 0 years of relevant experience.
- Mid-Level/Complex: Hands-on experience with configuration management tools, scripting or automation (for example, Python, Bash, PowerShell), and cloud ecosystems (AWS, Azure).
- Mid-Level/Complex: Working knowledge of risk management frameworks including NIST, RMF, or ISO 27001.
- Mid-Level/Complex: Strong technical writing, effective communication with non-technical stakeholders, and the ability to balance operational support with long-term architectural initiatives.
- Senior Level/Exceptionally Complex: High School Diploma/GED with 10 years of relevant experience, or Associates Degree with 8 years of relevant experience, or Bachelors Degree with 6 years of relevant experience, or Masters Degree with 4 years of relevant experience, or PhD with 2 years of relevant experience.
- Senior Level/Exceptionally Complex: DoD 8570.01-M compliance (IAM/IASAE Level III) or a CISSP.
- SME Level/Exceptionally Complex: High School Diploma/GED with 12 years of relevant experience, or Associates Degree with 10 years of relevant experience, or Bachelors Degree with 8 years of relevant experience, or Masters Degree with 6 years of relevant experience, or PhD with 4 years of relevant experience.
- SME Level/Exceptionally Complex: Advanced DoD 8570/8140 baseline certifications (for example, CISSP, CISM, CASP+ CE).
- SME Level/Exceptionally Complex: Deep, practical command of regulatory frameworks including NIST SP 800-53, JSIG, CNSSI 1253, and NERC CIP.
- SME Level/Exceptionally Complex: Proficiency in COTS/GOTS security products, OS hardening (Linux/Windows), hypervisors/cloud deployment, and industrial protocols (if applied to OT/ICS).
Location and Work Model
- Location: Arlington, VA
- Work model: Hybrid (acceptable)
Salary
- Estimated annual range: USD 89,600 - 204,000
Benefits
- Competitive compensation
- Comprehensive insurance options
- Matching contributions through the 401(k) plan and the share purchase plan
- Paid time off for vacation, holidays, and sick time
- Paid parental leave
- Learning opportunities and tuition assistance
- Wellness and Well-being programs
Additional Information
- CGI Federal offers benefits to eligible professionals on their first day of employment.
- Employment in the U.S. is contingent upon successfully completing a background investigation; components can vary by assignment and/or level of U.S. government security clearance, and some investigations may include a credit check depending on role and clearance requirements.
- CGI will consider qualified applicants with arrests and conviction records in accordance with local regulations and ordinances.