
Principal Engineer – Detection and Response
Wells Fargo
full-time
Posted on:
Location Type: Hybrid
Location: Charlotte • North Carolina • Ohio • United States
Visit company websiteExplore more
Salary
💰 $159,000 - $305,000 per year
Tech Stack
About the role
- Act as an advisor to leadership to develop or influence applications, network, information security, database, operating systems, or web technologies for highly complex business and technical needs across multiple groups.
- Lead the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas or the enterprise, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, advanced analytical and inductive thinking.
- Translate advanced technology experience, an in-depth knowledge of the organization's tactical and strategic business objectives, the enterprise technological environment, the organization structure, and strategic technological opportunities and requirements into technical engineering solutions.
- Provide vision, direction and expertise to leadership on implementing innovative and significant business solutions.
- Maintain knowledge of industry best practices and new technologies and recommends innovations that enhance operations or provide a competitive advantage to the organization.
- Strategically engage with all levels of professionals and managers across the enterprise and serve as an expert advisor to leadership.
- Serve as the senior technical advisor for the CIDR ecosystem, including architecture, engineering, workflow orchestration, automation, and emerging AI-enabled capabilities.
- Define and maintain the long-term architectural vision, technical standards, and reference designs for detection and response platforms, ensuring cohesive integration across cloud, endpoint, identity, network, and third-party environments.
- Translate enterprise risk, threat intelligence, operational data, and regulatory expectations into actionable engineering direction, roadmaps, and platform investments.
- Lead evaluation of emerging tools and industry trends to drive continuous modernization of CIDR capabilities.
- Provide deep technical expertise and engineering leadership across detection architecture, SIEM design, log/telemetry pipelines, correlation logic, enrichment workflows, alert lifecycle management, and SOAR automation.
- Engineer reliable, scalable detection pipelines aligned with MITRE ATT&CK, NIST 800-61, and other frameworks.
- Lead design and engineering of playbooks, automated workflows, metrics, reporting, and escalation paths into Incident Management and CSIRT.
- Ensure telemetry coverage, detection fidelity, and tuning processes meet enterprise quality, performance, and risk requirements.
- Serve as the primary technical architect and decision authority for large-scale, multi-platform, cross-organizational CIDR engineering initiatives.
- Resolve complex design tradeoffs across scale, performance, data quality, automation reliability, and security risk.
- Partner with teams across CDM, infrastructure, cloud, identity, engineering, and application platforms to resolve dependencies and drive successful execution.
- Act as a senior escalation point and technical authority for detection and response issues surfaced through routine SOC operations or major investigations.
- Partner daily with SOC analysts, threat intelligence teams, CSIRT, engineering teams, and business stakeholders to ensure consistent operational readiness and high-quality detection outcomes.
- Drive continuous improvement across the detection and response lifecycle, including triage, investigation, containment, and handoff to Incident Management.
- Ensure CIDR capabilities align with enterprise risk posture, resiliency expectations, and regulatory scrutiny.
Requirements
- 7+ years of cybersecurity engineering and technology experience, designing and operating complex security systems at enterprise scale.
- 5+ years of hands-on SOC or incident response engineering experience, including alert pipelines, detection logic, response automation, and case management workflows.
- Deep technical expertise in SIEM architecture, data onboarding, normalization, correlation, large-scale tuning, and performance optimization.
- Strong experience in detection engineering, SOC workflow design, and playbook/runbook development.
- Demonstrated ability to translate threat intelligence into detection logic at scale.
- Strong knowledge of incident response and detection frameworks (NIST 800‑61, MITRE ATT&CK/DEFEND).
- Exceptional communication skills and proven experience engaging executive, technical, and operational audiences.
Benefits
- Health benefits
- 401(k) Plan
- Paid time off
- Disability benefits
- Life insurance, critical illness insurance, and accident insurance
- Parental leave
- Critical caregiving leave
- Discounts and savings
- Commuter benefits
- Tuition reimbursement
- Scholarships for dependent children
- Adoption reimbursement
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
cybersecurity engineeringSOC engineeringincident response engineeringSIEM architecturedetection engineeringalert pipelinesresponse automationcase management workflowsdata onboardingperformance optimization
Soft Skills
communication skillsleadershipstrategic thinkinganalytical thinkingproblem-solvingcollaborationinnovationcreativityadvisory skillsengagement with stakeholders
Certifications
NIST 800-61MITRE ATT&CKMITRE DEFEND