CGI
Posted 4w ago

Cybersecurity Systems Engineer (Entry Level to SME) TS/SCI with Poly REQUIRED

CGI
Arlington, Virginia, United States
$90k-$204k/yrHybridFull Time
Responsibilities
  • securing infrastructure
  • monitoring threats
  • documenting policies
Requirements
  • Active TS/SCI with Poly required. Education and experience vary by level
  • Qualifications include cybersecurity knowledge
  • Windows/Linux
  • Networking
  • Security tools, cloud
  • Automation, and relevant certifications
Technical tools mentioned
antivirusfirewallsendpoint protectionSIEMEDRXDRLinuxRed HatUbuntuWindowsAgileDevSecOpsCI/CDSASTDASTPythonPowerShellTerraformACASCOTSGOTSAWSAzureNIST SP 800-53NIST 800-171CMMC Level 2RMFISO 27001DoD 8570.01-MCISSPCISMCASP+ CEJSIGCNSSI 1253NERC CIPTCP/IPBash

Job description

Position Description:

CGI Federal has an exciting opportunity for Cybersecurity Systems Engineers within our Intel sector advancing the national security mission through cutting edge technology. You must have a passion for keeping pace with rapidly evolving technology advancements and leveraging your knowledge on a highly collaborative team to deliver state-of-the-art capabilities.

The Cybersecurity Systems Engineer supports senior staff in maintaining and securing an organization's IT infrastructure. They assist in configuring security controls, monitoring for threats, and documenting system policies, acting as a foundational builder of daily cyber defenses.

CGI Federal is growing its high-performance team whose members share a passion for building high-quality, scalable, advanced IT solutions in a collaborative, fast-paced, outcome-driven mission.

This position is located in our Arlington office; however, a hybrid working model is acceptable.






Your future duties and responsibilities:

Key Responsibilities (Entry Level)
• System Maintenance: Assist in maintaining and upgrading basic security software (e.g., antivirus, firewalls, endpoint protection).
• Monitoring: Help monitor networks and servers for unusual activity or policy violations.
• Vulnerability Management: Run routine vulnerability scans and help patch outdated software.
• Documentation: Write and organize technical reports, standard operating procedures, and security system documentation.
• Incident Support: Assist senior engineers during security investigations by gathering logs and basic data.

Key Responsibilities (Junior Level)
• Security Administration: Assist in the operation, configuration, and maintenance of host-based, network-based, and cloud-based security systems.
• System Hardening: Implement and maintain hardware and software configuration management processes to ensure systems are secured per industry best practices (e.g., DISA STIGs if applicable).
• Monitoring & Triage: Monitor security logs, analyze event alerts, and manage ticket queues for system and security issues.
• Vulnerability Management: Perform vulnerability assessments and risk analyses to identify weaknesses and prioritize patches or remediation.
• Documentation & Compliance: Help maintain technical security documentation, support Assessment and Authorization (A&A) activities, and track compliance.
• Incident Response: Participate in the tactical execution of the Cyber Incident Response Team (CIRT) by investigating suspicious activity on servers and securing system boundaries.

Key Responsibilities (Mid-Level)
Systems Engineering & Secure Architecture
• Design, implement, and maintain Commercial-off-the-Shelf (COTS) and custom security products, including firewalls, SIEM tools, and identity management systems.
• Deploy and secure software applications within virtualized infrastructures and highly distributed cloud computing environments.
• Manage and secure endpoint baselines across operating systems like Linux (Red Hat, Ubuntu) and Windows.
• Participate in Agile/DevSecOps teams to automate security testing and integrate security controls into CI/CD pipelines.
Security Operations & Threat Management
• Conduct static and dynamic source code analysis (SAST/DAST) and manage application vulnerabilities as technical debt within backlogs.
• Perform root cause analysis on security incidents and proactively recommend mitigations to strengthen the overall security posture.
• Coordinate vulnerability scanning, patch management, and threat hunting across enterprise and operational environments.
Governance, Risk, and Compliance (GRC)
• Implement and audit technical controls against rigorous compliance frameworks such as NIST SP 800-53, NIST 800-171, or CMMC Level 2.
• Prepare and execute testing procedures for assessing conformance with DoD, Federal Civilian, or Intelligence Community requirements.
• Draft and maintain essential systems engineering documentation, including System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and Interface Control Documents (ICDs).

Key Responsibilities (Senior Level)
• Advanced Architecture: Architect, implement, and validate integrated hardware/software/firmware security solutions for highly complex environments (e.g., aerospace, cloud, or enterprise).
• Attack Surface Analysis (ASA): Perform attack surface analyses and decompose system-level security controls into technical performance requirements across disciplines like Anti-Tamper and cryptography.
• Cloud & DevOps Security: Design zero-trust environments, implement Infrastructure as Code (IaC) via Terraform, and securely deploy Mission Unique Software (MUS) in highly virtualized clouds.
• Risk Management Framework (RMF): Lead the RMF process from system categorization to continuous monitoring (ConMon), ensuring compliance with strict federal or commercial controls.
• Vulnerability & Flaw Remediation: Triage findings from Static Code Analysis (SCA) and establish technical debt in the software backlog.
• Continuous Monitoring: Utilize tools like ACAS to conduct comprehensive vulnerability scanning, patch management, and assess deviation mitigations.
• Incident Response & Ethical Hacking: Design and deploy security systems like SIEM, EDR, and XDR. Support tactical execution during critical incidents or cyber test & evaluation.
• Automation: Automate repetitive security tasks and identity workflows. Experience with scripting in Python or PowerShell is strongly required.

Key Responsibilities (SME Level)
• Security Architecture & Design: Architect enterprise-wide cyber systems and embed security into the design of hardware, software, and network components across OSI layers.
• Risk & Compliance: Manage Risk Management Framework (RMF) activities, including Attack Surface Analyses (ASA), Security Control Traceability Matrices (SCTM), and Plans of Action & Milestones (POA&Ms).
• Vulnerability & Threat Management: Conduct advanced risk assessments, threat modeling, static code analysis (SCA) triaging, and flaw remediation.
• Incident Response & Forensics: Lead tactical Cyber Incident Response Team (CIRT) operations, perform forensic preservation, and resolve non-standard vulnerabilities.
• Leadership & Mentorship: Act as the technical point of contact, lead design reviews with stakeholders, and mentor junior or mid-level engineering staff.







Required qualifications to be successful in this role:

All levels require an active TS/SCI with Poly

Entry Level:
• Education:
o High School Diploma/GED with 4 years of relevant experience,
o Associates Degree with 2 years of relevant experience,
o or Bachelor’s Degree with 0 years of relevant experience
• Certifications: Foundational certifications such as CompTIA Security+, Network+, or similar vendor-specific badges.
• Skills: Basic understanding of networking protocols, operating systems (Windows/Linux), and fundamental security concepts.

Junior Level/Moderate:
• Education:
o High School Diploma/GED with 6 years of relevant experience,
o Associates Degree with 4 years of relevant experience,
o Bachelor’s Degree with 2 years of relevant experience,
o or Masters Degree with 0 years of relevant experience
• Technical Knowledge: Understanding of operating systems (Windows/Linux), network protocols (TCP/IP), and security platforms like SIEM, EDR, or firewalls.
• Certifications: Foundational certifications such as CompTIA Security+, Network+, or similar vendor-specific credentials (e.g., Cisco CCNA, AWS/Azure certifications) are highly valued.

Mid-Level/Complex:
• Education:
o High School Diploma/GED with 8 years of relevant experience,
o Associates Degree with 6 years of relevant experience,
o Bachelor’s Degree with 4 years of relevant experience,
o or Masters Degree with 2 years of relevant experience,
o or PhD with 0 years of relevant experience
• Technical Skills: Hands-on experience with configuration management tools, scripting or automation (e.g., Python, Bash, PowerShell), and cloud ecosystems (AWS, Azure).
• Compliance: Working knowledge of risk management frameworks (e.g., NIST, RMF, ISO 27001).
• Soft Skills: Strong technical writing, effective communication with non-technical stakeholders, and the ability to balance operational support with long-term architectural initiatives.

Senior Level/Exceptionally Complex:
• Education:
o High School Diploma/GED with 10 years of relevant experience,
o Associates Degree with 8 years of relevant experience,
o Bachelor’s Degree with 6 years of relevant experience,
o or Masters Degree with 4 years of relevant experience,
o or PhD with 2 years of relevant experience
• Certifications: DoD 8570.01-M compliance (IAM/IASAE Level III) or a CISSP.

SME Level/Exceptionally Complex:
• Education:
o High School Diploma/GED with 12 years of relevant experience,
o Associates Degree with 10 years of relevant experience,
o Bachelor’s Degree with 8 years of relevant experience,
o or Masters Degree with 6 years of relevant experience,
o or PhD with 4 years of relevant experience
• Certifications: Advanced DoD 8570/8140 baseline certifications (e.g., CISSP, CISM, CASP+ CE).
• Frameworks: Deep, practical command of regulatory frameworks like NIST SP 800-53, JSIG, CNSSI 1253, and NERC CIP.
• Technical Skills: Proficiency in COTS/GOTS security products, OS hardening (Linux/Windows), hypervisors/cloud deployment, and industrial protocols (if applied to OT/ICS).

CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit-based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $89,600.00 - $204,000.00.

CGI Federal's benefits are offered to eligible professionals on their first day of employment to include:
. Competitive compensation
. Comprehensive insurance options
. Matching contributions through the 401(k) plan and the share purchase plan
. Paid time off for vacation, holidays, and sick time
. Paid parental leave
. Learning opportunities and tuition assistance
. Wellness and Well-being programs

#CGIFederalJob
#LI-LB1
#ClearanceJobs
#CGIInternationalSecurity



















What you can expect from us:

Together, as owners, let’s turn meaningful insights into action.

Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you’ll reach your full potential because…

You are invited to be an owner from day 1 as we work together to bring our Dream to life. That’s why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company’s strategy and direction.

Your work creates value. You’ll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise.

You’ll shape your career by joining a company built to grow and last. You’ll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons.

Come join our team—one of the largest IT and business consulting services firms in the world.

Qualified applicants will receive consideration for employment without regard to their race, ethnicity, ancestry, color, sex, religion, creed, age, national origin, citizenship status, disability, pregnancy, medical condition, military and veteran status, marital status, sexual orientation or perceived sexual orientation, gender, gender identity, and gender expression, familial status or responsibilities, reproductive health decisions, political affiliation, genetic information, height, weight, or any other legally protected status or characteristics to the extent required by applicable federal, state, and/or local laws where we do business.

CGI provides reasonable accommodations to qualified individuals with disabilities. If you need an accommodation to apply for a job in the U.S., please email the CGI U.S. Employment Compliance mailbox at [email protected]. You will need to reference the Position ID of the position in which you are interested. Your message will be routed to the appropriate recruiter who will assist you. Please note, this email address is only to be used for those individuals who need an accommodation to apply for a job. Emails for any other reason or those that do not include a Position ID will not be returned.

We make it easy to translate military experience and skills! Click here to be directed to our site that is dedicated to veterans and transitioning service members.

All CGI offers of employment in the U.S. are contingent upon the ability to successfully complete a background investigation. Background investigation components can vary dependent upon specific assignment and/or level of US government security clearance held. Dependent upon role and/or federal government security clearance requirements, and in accordance with applicable laws, some background investigations may include a credit check. CGI will consider for employment qualified applicants with arrests and conviction records in accordance with all local regulations and ordinances.

CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with CGI’s legal duty to furnish information.

About CGI

Provides information technology and business consulting services.

Similar jobs

Cybersecurity Systems Engineer roles near Arlington, Virginia
1d
Save
Mark Applied
Hide
Cybersecurity Systems Engineer (ServiceNow/Cloud) w/Active TS
Chantilly, Virginia, United States
OnsiteFull Time
Sentinel Group
Sentinel Group: Provides logistics training and IT solutions to government agencies.
Requires active TS/SCI clearance with CI polygraph, enterprise IT experience, ServiceNow, Linux, AWS, APIs, systems integration, and troubleshooting across applications, infrastructure, databases, and cloud services.
ServiceNow, JavaScript, AWS, AWS Lambda, Amazon API Gateway, Linux, MariaDB, Amazon RDS, REST APIs, LDAP, CI/CD, Artificial Intelligence (AI)
2d
Save
Mark Applied
Hide
Senior Cybersecurity Systems Engineer
Dahlgren, Virginia, United States
$170k-$200k/yr OnsiteFull Time
Tharros
Tharros: Provides specialized cybersecurity defense and vulnerability research services.
8+ YOE5+ MgmtBachelor's degree in a technical discipline and 8+ years of relevant experience, or 10 years of expertise; active TS/SCI, CISSP, and DoD/Navy cybersecurity, RMF, systems engineering, and security authorization experience required.
RMF, DIACAP, GOTS, COTS, ECPs
6d
Save
Mark Applied
Hide
Cybersecurity Systems Engineer (NH3)
Annapolis Junction or Fort Meade or Columbia
$220k-$240k/yr OnsiteFull Time
Legato
Legato: Delivers IT engineering and cybersecurity services to defense agencies.
20+ YOERequires 20 years of systems or cybersecurity engineering, bachelor's degree or 5 additional years' experience, IAM Level II or III certification, MDE and Trellix HX expertise, and Windows, Linux, and macOS knowledge.
Microsoft Defender for Endpoint (MDE), MECM, SCCM, Microsoft Intune, Kusto Query Language (KQL), Trellix HX, OpenIOC, YARA, Windows, Linux, macOS, VDI
1w
Save
Mark Applied
Hide
Cybersecurity Systems Engineer (ServiceNow/Cloud) w/Active TS
Chantilly, Virginia, United States
OnsiteFull Time
HCI Integrated Solutions
HCI Integrated Solutions: Provides logistics and technical services for federal agencies.
Active TS/SCI clearance with current CI polygraph; enterprise IT, ServiceNow, Linux, AWS, systems integration, and API experience. Strong troubleshooting, written communication, and collaboration skills.
ServiceNow, JavaScript, AWS, Linux, AWS Lambda, Amazon API Gateway, MariaDB, Amazon RDS, REST APIs, LDAP, CI/CD, Artificial Intelligence (AI)
3w
Save
Mark Applied
Hide
Cybersecurity Systems Engineer / ISSM
Chantilly, Virginia, United States
OnsiteFull Time
AnaVation
AnaVation: Providing technical engineering and cybersecurity solutions for federal agencies.
7+ YOEBachelor's in a related field,7+ years cybersecurity/IA experience,experience as ISSM/ISSO,knowledge of NIST/CMMC/DFARS/RMF,ability to obtain U.S. government clearance,experience developing SSPs and supporting audits.
Microsoft 365 Government, Microsoft Defender, Microsoft Entra ID, Intune, Microsoft Purview, SIEM, EDR, vulnerability scanning
1mo
Save
Mark Applied
Hide
Senior Cybersecurity Systems Engineer
Chantilly, Virginia, United States
$160k-$210k/yr OnsiteFull Time
Modern Technology Solutions, Inc.
Modern Technology Solutions, Inc.: Provides engineering, technology, and cybersecurity services for national security.
20+ YOE20+ years technical experience, active TS/SCI clearance, expertise with DoD 8500.1-M, JSIG, NIST SP 800-53, ability to assess and articulate risk, and experience assessing software/hardware and guiding contractor work.
DoD 8500.1-M, Joint SAP Implementation Guide (JSIG), NIST SP 800-53
1mo
Save
Mark Applied
Hide
Senior Cybersecurity Systems Engineer
Chantilly, Virginia, United States
$160k-$210k/yr OnsiteFull Time
Modern Technology Solutions
Modern Technology Solutions: A technical services firm providing security engineering and support to defense and government acquisition programs.
20+ YOE20+ years cybersecurity experience, DoD/JSIG/NIST SP 800-53 knowledge, TS/SCI clearance, strong risk assessment, communications, and technical proficiency; travel ~30%.
NIST SP 800-53, DoD 8500.1-M, Joint SAP Implementation Guide (JSIG), AWS, Microsoft, Linux
2mo
Save
Mark Applied
Hide
Cybersecurity Systems Engineer Navy Mission
Arlington, Virginia, United States
$135k-$230k/yr OnsiteFull Time
Innovative Defense Technologies
Innovative Defense Technologies: Provides automated software and systems solutions to rapidly deliver mission-critical capabilities for the U.S. Department of Defense.
5+ YOEActive Secret clearance; bachelor\u0002s degree or equivalent; 5+ years systems administration experience; RMF/NIST 800-53, vulnerability management, Tenable/Nessus, VMWare, scripting (Bash/Python); Security+/CCNA or IAT Level II; POAM/STIG experience.
NIST 800-53, VMWare, Tenable Security Center, Nessus, Trellix, Bash, Python, ACAS, DISA STIG, Ansible, PowerShell, Chef, Salt, Puppet