Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Security Engineer

$104.9k - $174.7k

LexisNexis

This job is with LexisNexis Legal & Professional®, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.

Principal Incident Response Lead

J ob Profile Summary

The Principal Incident Response Lead position provides strategic and tactical leadership for enterprise incident response across a complex hybrid environment. This role serves as the senior incident commander and technical authority for high-severity security events, providing executive-ready decision support based on evolving threats, attack techniques, and advances in technology. The position supports the Information Security department's goals and objectives by leading escalations, guiding containment and recovery actions, and driving measurable improvements to response readiness and detection effectiveness. This role requires deep expertise in leading complex incident response efforts across hybrid environments and advancing cloud-native detection and monitoring capabilities, particularly within AWS. The role also owns the incident response program's readiness lifecycle-including tabletops, cyber range exercises, and after-action governance-to ensure continuous improvement and operational resilience.

Job Description

BASIC FUNCTIONS: This position will provide strategic and tactical incident response leadership, providing management with insight and input into overall security operations decisions based on advances in technology and the evolving threat landscape. The position supports the Information Security department's goals and objectives by leading escalations and coordinating response activities across multiple technical teams, ensuring consistent execution of triage, containment, eradication, and recovery. This position serves as the senior incident commander, establishes and maintains incident response readiness (playbooks, communications patterns, exercises), and drives detection and response improvements through lessons learned and measurable program outcomes.

QUALIFICATIONS:

• 10+ years of IT security experience, including significant incident response leadership in enterprise environments

• BS Engineering/Computer Science or equivalent experience required; advanced degree preferred

• Preferred: incident handling/forensics-focused certifications (e.g., GCIH, GCFA or equivalent) and cloud security certification(s) (AWS/Azure/GCP)

TECHNICAL SKILLS:

• Advanced knowledge of modern security operations environments, including hybrid enterprise architectures and common attack paths.

• Demonstrated experience leading incident response activities across complex hybrid environments, including on-premises infrastructure and multi-cloud platforms (AWS, Azure, GCP).

• Strong hands-on experience engineering detections, telemetry, and monitoring solutions within AWS (e.g., CloudTrail, GuardDuty, VPC Flow Logs, and related services).

• Expertise in incident command practices: severity assessment, stakeholder coordination, containment strategies, evidence handling, eradication and recovery planning, and post-incident review.

• Strong ability to monitor, triage, and investigate security events; apply structured analysis for anomalous activity and adversary behaviors.

• Experience with enterprise logging and telemetry pipelines, log onboarding strategies, and data quality expectations (coverage, fidelity, retention).

• Experience improving detection quality and signal-to-noise (e.g., tuning, suppression, enrichment, validation, and feedback loops).

• Working knowledge of identity and access security concepts (SSO/MFA, privileged access, conditional access) and identity-driven attack patterns and detections.

• Understanding of compliance and governance initiatives and the ability to translate requirements into operational controls, procedures, and evidence.

• Vulnerability and exposure understanding sufficient to prioritize response actions (active exploitation, blast radius, compensating controls) and guide remediation.

• Familiarity with automation/SOAR concepts and scripting for investigation and response workflows (e.g., Python/PowerShell or equivalent).

• Ability to develop and implement incident response programs with measurable outcomes (response readiness, containment speed, detection coverage, exercise cadence).

• Strong organization/project planning, time management, and change management skills across multiple functional groups and departments, including prioritizing work during incident conditions.

• Advanced problem-solving experience involving leading teams in identifying, researching, and coordinating resources necessary to troubleshoot/diagnose complex issues; success translating findings into options/solutions; identifying risks/impacts and schedule adjustments to facilitate management decision-making.

• Advanced communication (verbal and written) and customer service skills, including the ability to brief senior/executive leadership with clear, concise, decision-oriented updates.

ACCOUNTABILITIES:

• Serve as the senior incident commander and technical lead for high-severity incidents; drive structured triage, containment, eradication, and recovery across the enterprise.

• Lead and coordinate incident response efforts for high-severity events spanning hybrid and multi-cloud environments (on-prem, AWS, Azure, GCP), ensuring effective containment, eradication, and recovery.

• Own and continuously improve the incident response program: playbooks/runbooks, severity definitions, escalation paths, on-call expectations, evidence handling standards, and crisis communications patterns.

• Plan, run, and mature readiness activities including tabletop exercises and cyber range events; define objectives, measure outcomes, and ensure follow-through on remediation actions.

• Own after-action governance: facilitate post-incident reviews, establish root cause and contributing-factor analysis, drive corrective action plans, and track closure to completion (closed-loop improvement).

• Lead analysis and review of security events for anomalous activity; collaborate with peer groups to take appropriate action to safeguard company information assets against current and foreseen threats.

• Drive improvements to detection, investigation, and response processes through lessons learned, measurable corrective actions, and operational performance metrics.

• Drive the design, implementation, and continuous improvement of detection engineering and monitoring capabilities within AWS environments.

• Partner with infrastructure, cloud, endpoint, identity, and application teams to ensure response-ready logging, telemetry, and access to required investigative data sources.

• Provide guidance for threat-informed mitigation and hardening activities resulting from incidents (e.g., containment controls, identity protections, logging improvements, segmentation, credential hygiene).

• Communicate incident status, impact, and risk in executive-ready written and verbal updates; produce high-quality incident summaries and post-incident reports.

• Support compliance and governance efforts by operationalizing response procedures, documenting evidence, and ensuring repeatable execution aligned to policy and regulatory expectations.

• Assist with reviewing tools, applications, and processes to strengthen and optimize current incident response and detection capabilities, identify gaps, and recommend practical solutions to enhance effectiveness.

• Assess and measure incident response program effectiveness to ensure closed-loop operations (e.g., readiness/exercise cadence, time-to-contain, repeat incident reduction, detection coverage and quality).

• All other duties as assigned.

U.S. National Base Pay Range: $104,900 - $174,700. Geographic differentials may apply in some locations to better reflect local market rates. This job is eligible for an annual incentive bonus.

We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact View phone number on click.appcast.io.

Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here .

Please read our Candidate Privacy Policy.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

USA Job Seekers:

EEO Know Your Rights.

Vacancy posted 10 hours ago
Similar jobs that could be interesting for youBased on the Principal Security Engineer in Raleigh, NC vacancy
  • $104.9k - $174.7k

     ...not contact the recruiter directly. Principal Incident Response Lead J ob Profile...  ...technical authority for high-severity security events, providing executive-ready...  ...leadership in enterprise environments • BS Engineering/Computer Science or equivalent... 
    Suggested
    Local area

    LexisNexis

    Raleigh, NC
    2 days ago
  • $120.5k - $231k

     ...everywhere & always. Want in? Join the #VTeamLife. What you'll be doing... The Verizon Network Security team is looking for a highly motivated and experienced Principal Engineer to join the Net-Sec Defense Organization under the Broadband Access team. You will be... 
    Suggested
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Work from home
    Shift work
    3 days per week

    Verizon

    Cary, NC
    4 days ago
  • $95.3k - $158.8k

     ...contact the recruiter directly. This position is a Hybrid role on site in the Raleigh N.C. office 2-3 days a week. Senior Security Engineer II - Compliance Automation & Controls About Us LexisNexis, a part of RELX, is a leading global provider of legal,... 
    Suggested
    Work at office
    Local area
    Remote work
    Flexible hours
    2 days per week
    3 days per week

    LexisNexis

    Raleigh, NC
    3 days ago
  • $40 per hour

    A cybersecurity training company is seeking experienced professionals to evaluate AI-generated security content and solve technical problems within cybersecurity. Candidates should have a minimum of 2 years of hands-on experience in areas like penetration testing and incident... 
    Suggested
    Hourly pay
    Remote work

    DataAnnotation

    Raleigh, NC
    10 hours ago
  • $40 per hour

     ...company is seeking experienced cybersecurity professionals to join their team. This remote role focuses on evaluating AI-generated security content and solving technical cybersecurity challenges. Candidates should have 2+ years of experience in cybersecurity and strong... 
    Suggested
    Remote work
    Flexible hours

    DataAnnotation

    Raleigh, NC
    9 hours ago
  • $104.9k - $174.7k

     ...the Role : As a Consulting AWS Cloud Network Infrastructure Engineer, you will help define best practices, establish cloud vision,...  ...stakeholders to ensure our Cloud Network infrastructure is robust, secure, scalable, resilient, monitored and cost-efficient. This role... 
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    LexisNexis

    Raleigh, NC
    2 days ago
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) ~ Some... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Raleigh, NC
    1 day ago
  • $137.7k - $203.1k

    w/ Red Hat, LLC in U.S Remote. *Telecommuting role to be performd anywhere in the U.S. Deply pipelins & infrastructre in both proof of concpt (POC) & productn form to supprt the Customer Data Platform initiativs. Partnr w/ internl & externl stakehlders to supprt combins...
    Remote work

    Red Hat

    Raleigh, NC
    2 days ago
  •  ...Responsibilities ECSis hiringa Principal Geotechnical Engineer to join our transportation teamin the Southeast. This role provides technical leadership for major infrastructure projects. This person canbe located inany of our major hubs across the Southeast, including... 

    Ecs Southeast

    Raleigh, NC
    5 days ago
  •  ...Job Description Job Description At ANS, we’re not just a consulting engineering firm—we’re a team of trailblazers shaping the future of engineering. Recognized as one of the  Best Places to Work  and  Top 10 Hottest Engineering Firms in the US by Zweig Reports, and... 
    Internship
    Work at office
    Flexible hours

    ANS

    Raleigh, NC
    25 days ago
  • $320k

     ...NVIDIA is seeking a Distinguished Engineer to serve as the founding technical leader for our AI Safety & Security Engineering team. Rooted in the firm belief that open-weight models, transparency, and broad scientific scrutiny are foundational to American AI leadership... 
    Full time
    Part time
    Remote work

    Nvidia

    Raleigh, NC
    3 days ago
  • $40 per hour

    A leading AI cybersecurity firm is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical problems. The ideal candidate will possess over 2 years of hands-on experience in cybersecurity and strong analytical and writing... 
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Raleigh, NC
    10 hours ago
  • $116.03k - $140k

     ...Segra is searching for a qualified and experienced Staff Information Security Engineer to join us in a full-time capacity. Location Requirement: The work arrangement for this role is a hybrid position, requiring a minimum of three (3) days in the office, with... 
    Full time
    Work at office
    Immediate start
    Remote work
    Flexible hours
    2 days per week

    Segra

    Raleigh, NC
    4 days ago
  •  ...We are looking for a Principal Statistical Programmer to lead programming activities for one or more studies, ensuring high-quality development...  ...productivity and automation. Familiarity with modern software engineering practices, including Git-based workflows, reusable frameworks,... 
    Local area

    Dormont Manufacturing Company

    Raleigh, NC
    10 hours ago
  •  ...Location Requirement: Must currently reside in the greater Raleigh or Charlotte NC areas. What You Need BS in Civil or Environmental Engineering with NC PE registration. 7–15+ years of experience in land development design for residential, commercial, and/or industrial... 
    Contract work
    For contractors
    Work at office
    Local area

    McKim & Creed

    Raleigh, NC
    1 day ago
  • $124.5k - $239k

     ...if you have one or more of the following: Master’s degree in engineering, computer science or other technical discipline. Designed IT...  ...services (LAN, WAN, content delivery, WLAN, managed IP PBX), managed security solutions (firewall, proxy, VPN), managed mobility Solutions,... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Flexible hours
    Shift work

    Verizon

    Cary, NC
    2 hours ago
  •  ...Civil Engineering Project Manager Requisition Number: 2025-1350-21 Do you have a background in the Oil and Gas industry? Do you want to work on projects right here in North and South Carolina? S&ME is seeking a skilled Project Manager with design and permitting... 
    Full time

    S&ME

    Raleigh, NC
    2 days ago
  •  ...fieldwork, site visits (mostly in-state) and potential client meetings; capable of walking around outdoors Assist in preparing engineering deliverables, including sampling studies, condition assessments, process modeling, hydraulics, and design reports Work... 
    Full time
    Part time
    Internship
    Seasonal work
    Summer internship
    Work at office

    Hazen and Sawyer

    Raleigh, NC
    1 day ago
  •  ...Civil Engineering Project Manager Requisition Number: 2025-1350-21 Do you have a background in the Oil and Gas industry? Do you want to work on projects right here in North and South Carolina? S&ME is seeking a skilled Project Manager with design and permitting... 
    Full time

    S&ME

    Raleigh, NC
    4 days ago
  • $154k - $225k

     ...corporate Research Labs team is seeking a Chief Engineer to support Computational Methods (e.g....  ...the Energy Systems team. You will be a principal investigator on key projects responsible...  ...all candidates’ privacy rights and data security will be protected in accordance with... 
    H1b
    Local area
    Visa sponsorship
    Relocation package

    Eaton

    Raleigh, NC
    2 days ago
  •  ...facility. Comprehensive benefits program (health, dental, retirement savings, etc.). Opportunity to lead mission-critical engineering operations producing high-precision parts and to drive manufacturing excellence. Professional development opportunities and career... 
    Contract work

    PCI of North Carolina LLC

    Raleigh, NC
    5 days ago
  • $118.3k - $219.8k

     ...use case. About the Role : As a Senior Consulting Principal AWS Cloud Engineer, you will provide technical strategy, deep AWS expertise,...  ...AWS, Kubernetes, DevOps, Infrastructure as Code (IaC), and security architectures, with a strong ability to mentor and drive technical... 
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    LexisNexis

    Raleigh, NC
    3 days ago
  • $70.3k

     ...or update your information by visiting and logging into the careers section of the system. Job Description: At Regions, the Cyber Security Analyst is responsible for analyzing, identifying, and documenting cybersecurity information and risks. This role requires proactiveness... 
    Full time
    Work at office
    Relocation
    Visa sponsorship
    Work visa
    Relocation package
    Flexible hours
    Shift work
    3 days per week

    Regions Bank

    Raleigh, NC
    2 days ago
  • $102.17k - $178.78k

     ...Trinnex in Raleigh, NC, seeks a Senior Cyber Security Analyst to safeguard software systems essential for water utilities. You will...  ...lifecycle and manage vulnerabilities while collaborating with engineering teams. The ideal candidate has a Bachelor's Degree and 6+ years... 

    Trinnex

    Raleigh, NC
    3 days ago
  •  ...Garmin Ltd. in Cary, North Carolina is seeking a Senior Software Engineer to provide technical leadership and hands-on development for embedded software across products and systems. You will own security-critical components, review designs for vulnerabilities, and contribute... 

    Garmin

    Cary, NC
    2 days ago
  •  ...management and VulnOps. This role sits at the intersection of security risk, automation, and emerging AI‑driven capabilities. If you’...  ...custom reports, and perform special investigations Coordinate with Engineering platform team to tune scanning tools to improve visibility and... 
    Work experience placement

    Vanguard

    Raleigh, NC
    3 days ago
  • $128.1k - $239.6k

     ...EY Infosec is seeking a Cloud Security consultant with expertise in cloud security architecture, configuration, and governance across...  ...Work with cross‑functional teams, including security architects, engineers, developers and product owners to explore new ideas and... 
    Summer holiday
    Local area
    Flexible hours
    Shift work

    Ernst & Young Oman

    Raleigh, NC
    2 days ago
  •  ...Join to apply for the Cyber Security Analyst II role at SECU Join to apply for the Cyber Security Analyst II role at SECU If you are motivated...  ...highly valued. 2 – 4 Years previous experience as a SOC/SIEM Engineer or similar role, with a strong track record of successfully... 
    16 hours
    Full time
    Internship
    Work from home

    SECU

    Raleigh, NC
    3 days ago
  •  ...traffic, and implement defense measures using AI/ML to enhance detection and incident response. You will work with cloud and on‑prem security tools, tune policies, and coordinate with the Threat Management team to improve the organization’s security posture.... 

    Jobtailor

    Raleigh, NC
    10 hours ago
  •  ...Senior Incident Responder – Cyber Security (Regulated Environment) Channel Recruitment is working with a leading organization operating...  ...sources) to enrich investigations Contributing to detection engineering and improving alerting capability Producing clear post‑incident... 
    Permanent employment
    Full time
    Work at office
    3 days per week
    Weekday work

    Channel Recruitment Agency

    Raleigh, NC
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Security Engineer. Be the first to apply!