Wells Fargo

Principal Engineer – Detection and Response

Wells Fargo

full-time

Posted on:

Location Type: Hybrid

Location: CharlotteNorth CarolinaOhioUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $159,000 - $305,000 per year

Job Level

About the role

  • Act as an advisor to leadership to develop or influence applications, network, information security, database, operating systems, or web technologies for highly complex business and technical needs across multiple groups.
  • Lead the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas or the enterprise, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, advanced analytical and inductive thinking.
  • Translate advanced technology experience, an in-depth knowledge of the organization's tactical and strategic business objectives, the enterprise technological environment, the organization structure, and strategic technological opportunities and requirements into technical engineering solutions.
  • Provide vision, direction and expertise to leadership on implementing innovative and significant business solutions.
  • Maintain knowledge of industry best practices and new technologies and recommends innovations that enhance operations or provide a competitive advantage to the organization.
  • Strategically engage with all levels of professionals and managers across the enterprise and serve as an expert advisor to leadership.
  • Serve as the senior technical advisor for the CIDR ecosystem, including architecture, engineering, workflow orchestration, automation, and emerging AI-enabled capabilities.
  • Define and maintain the long-term architectural vision, technical standards, and reference designs for detection and response platforms, ensuring cohesive integration across cloud, endpoint, identity, network, and third-party environments.
  • Translate enterprise risk, threat intelligence, operational data, and regulatory expectations into actionable engineering direction, roadmaps, and platform investments.
  • Lead evaluation of emerging tools and industry trends to drive continuous modernization of CIDR capabilities.
  • Provide deep technical expertise and engineering leadership across detection architecture, SIEM design, log/telemetry pipelines, correlation logic, enrichment workflows, alert lifecycle management, and SOAR automation.
  • Engineer reliable, scalable detection pipelines aligned with MITRE ATT&CK, NIST 800-61, and other frameworks.
  • Lead design and engineering of playbooks, automated workflows, metrics, reporting, and escalation paths into Incident Management and CSIRT.
  • Ensure telemetry coverage, detection fidelity, and tuning processes meet enterprise quality, performance, and risk requirements.
  • Serve as the primary technical architect and decision authority for large-scale, multi-platform, cross-organizational CIDR engineering initiatives.
  • Resolve complex design tradeoffs across scale, performance, data quality, automation reliability, and security risk.
  • Partner with teams across CDM, infrastructure, cloud, identity, engineering, and application platforms to resolve dependencies and drive successful execution.
  • Act as a senior escalation point and technical authority for detection and response issues surfaced through routine SOC operations or major investigations.
  • Partner daily with SOC analysts, threat intelligence teams, CSIRT, engineering teams, and business stakeholders to ensure consistent operational readiness and high-quality detection outcomes.
  • Drive continuous improvement across the detection and response lifecycle, including triage, investigation, containment, and handoff to Incident Management.
  • Ensure CIDR capabilities align with enterprise risk posture, resiliency expectations, and regulatory scrutiny.

Requirements

  • 7+ years of cybersecurity engineering and technology experience, designing and operating complex security systems at enterprise scale.
  • 5+ years of hands-on SOC or incident response engineering experience, including alert pipelines, detection logic, response automation, and case management workflows.
  • Deep technical expertise in SIEM architecture, data onboarding, normalization, correlation, large-scale tuning, and performance optimization.
  • Strong experience in detection engineering, SOC workflow design, and playbook/runbook development.
  • Demonstrated ability to translate threat intelligence into detection logic at scale.
  • Strong knowledge of incident response and detection frameworks (NIST 800‑61, MITRE ATT&CK/DEFEND).
  • Exceptional communication skills and proven experience engaging executive, technical, and operational audiences.
Benefits
  • Health benefits
  • 401(k) Plan
  • Paid time off
  • Disability benefits
  • Life insurance, critical illness insurance, and accident insurance
  • Parental leave
  • Critical caregiving leave
  • Discounts and savings
  • Commuter benefits
  • Tuition reimbursement
  • Scholarships for dependent children
  • Adoption reimbursement
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
cybersecurity engineeringSOC engineeringincident response engineeringSIEM architecturedetection engineeringalert pipelinesresponse automationcase management workflowsdata onboardingperformance optimization
Soft Skills
communication skillsleadershipstrategic thinkinganalytical thinkingproblem-solvingcollaborationinnovationcreativityadvisory skillsengagement with stakeholders
Certifications
NIST 800-61MITRE ATT&CKMITRE DEFEND