Position Description: CGI Federal has an exciting opportunity for Cybersecurity Systems Engineers within our Intel sector advancing the national security mission through cutting edge technology. You must have a passion for keeping pace with rapidly evolving technology advancements and leveraging your knowledge on a highly collaborative team to deliver state-of-the-art capabilities.
The Cybersecurity Systems
Engineer supports senior staff in maintaining and securing an organization's IT infrastructure. They assist in configuring security controls, monitoring for threats, and documenting system policies, acting as a foundational builder of daily cyber defenses. CGI Federal is growing its high-performance team whose members share a passion for building high-quality, scalable, advanced IT solutions in a collaborative, fast-paced, outcome-driven mission. This position is located in our Arlington office; however, a hybrid working model is acceptable.
Your future duties and responsibilities: Key Responsibilities (Entry Level)
- System Maintenance: Assist in maintaining and upgrading basic security software (e.g., antivirus, firewalls, endpoint protection).
- Monitoring: Help monitor networks and servers for unusual activity or policy violations.
- Vulnerability Management: Run routine vulnerability scans and help patch outdated software.
- Documentation: Write and organize technical reports, standard operating procedures, and security system documentation.
- Incident Support: Assist senior engineers during security investigations by gathering logs and basic data. Key Responsibilities (Junior Level)
- Security Administration: Assist in the operation, configuration, and maintenance of host-based, network-based, and cloud-based security systems.
- System Hardening: Implement and maintain hardware and software configuration management processes to ensure systems are secured per industry best practices (e.g., DISA STIGs if applicable).
- Monitoring & Triage: Monitor security logs, analyze event alerts, and manage ticket queues for system and security issues.
- Vulnerability Management: Perform vulnerability assessments and risk analyses to identify weaknesses and prioritize patches or remediation.
- Documentation & Compliance: Help maintain technical security documentation, support Assessment and Authorization (A&A) activities, and track compliance.
- Incident Response: Participate in the tactical execution of the Cyber Incident Response Team (CIRT) by investigating suspicious activity on servers and securing system boundaries. Key Responsibilities (Mid-Level)
Systems Engineering & Secure Architecture
- Design, implement, and maintain Commercial-off-the-Shelf (COTS) and custom security products, including firewalls, SIEM tools, and identity management systems.
- Deploy and secure software applications within virtualized infrastructures and highly distributed cloud computing environments.
- Manage and secure endpoint baselines across operating systems like Linux (Red Hat, Ubuntu) and Windows.
- Participate in Agile/DevSecOps teams to automate security testing and integrate security controls into CI/CD pipelines.
Security Operations & Threat Management
- Conduct static and dynamic source code analysis (SAST/DAST) and manage application vulnerabilities as technical debt within backlogs.
- Perform root cause analysis on security incidents and proactively recommend mitigations to strengthen the overall security posture.
- Coordinate vulnerability scanning, patch management, and threat hunting across enterprise and operational environments.
Governance, Risk, and Compliance (GRC) • Implement and audit technical controls against rigorous compliance frameworks such as NIST SP 800-53, NIST 800-171, or CMMC Level 2.
- Prepare and execute testing procedures for assessing conformance with DoD, Federal Civilian, or Intelligence Community requirements.
- Draft and maintain essential systems engineering documentation, including System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and Interface Control Documents (ICDs). Key Responsibilities (Senior Level)
- Advanced Architecture: Architect, implement, and validate integrated hardware/software/firmware security solutions for highly complex environments (e.g., aerospace, cloud, or enterprise).
- Attack Surface Analysis (ASA): Perform attack surface analyses and decompose system-level security controls into technical performance requirements across disciplines like Anti-Tamper and cryptography.
- Cloud & DevOps Security: Design zero-trust environments, implement Infrastructure as Code (IaC) via Terraform, and securely deploy Mission Unique Software (MUS) in highly virtualized clouds.
- Risk Management Framework (RMF): Le