Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Consulting/Principal Security Engineer

$104.9k - $174.7k

RELX

Principal Incident Response Lead

Job Profile Summary

The Principal Incident Response Lead position provides strategic and tactical leadership for enterprise incident response across a complex hybrid environment. This role serves as the senior incident commander and technical authority for high-severity security events, providing executive-ready decision support based on evolving threats, attack techniques, and advances in technology. The position supports the Information Security department’s goals and objectives by leading escalations, guiding containment and recovery actions, and driving measurable improvements to response readiness and detection effectiveness. This role requires deep expertise in leading complex incident response efforts across hybrid environments and advancing cloud-native detection and monitoring capabilities, particularly within AWS. The role also owns the incident response program’s readiness lifecycle—including tabletops, cyber range exercises, and after-action governance—to ensure continuous improvement and operational resilience.

Job Description

BASIC FUNCTIONS: This position will provide strategic and tactical incident response leadership, providing management with insight and input into overall security operations decisions based on advances in technology and the evolving threat landscape. The position supports the Information Security department’s goals and objectives by leading escalations and coordinating response activities across multiple technical teams, ensuring consistent execution of triage, containment, eradication, and recovery. This position serves as the senior incident commander, establishes and maintains incident response readiness (playbooks, communications patterns, exercises), and drives detection and response improvements through lessons learned and measurable program outcomes.

QUALIFICATIONS:

• 10+ years of IT security experience, including significant incident response leadership in enterprise environments

• BS Engineering/Computer Science or equivalent experience required; advanced degree preferred

• Preferred: incident handling/forensics-focused certifications (e.g., GCIH, GCFA or equivalent) and cloud security certification(s) (AWS/Azure/GCP)

TECHNICAL SKILLS:

• Advanced knowledge of modern security operations environments, including hybrid enterprise architectures and common attack paths.

• Demonstrated experience leading incident response activities across complex hybrid environments, including on-premises infrastructure and multi-cloud platforms (AWS, Azure, GCP).

• Strong hands-on experience engineering detections, telemetry, and monitoring solutions within AWS (e.g., CloudTrail, GuardDuty, VPC Flow Logs, and related services).

• Expertise in incident command practices: severity assessment, stakeholder coordination, containment strategies, evidence handling, eradication and recovery planning, and post-incident review.

• Strong ability to monitor, triage, and investigate security events; apply structured analysis for anomalous activity and adversary behaviors.

• Experience with enterprise logging and telemetry pipelines, log onboarding strategies, and data quality expectations (coverage, fidelity, retention).

• Experience improving detection quality and signal-to-noise (e.g., tuning, suppression, enrichment, validation, and feedback loops).

• Working knowledge of identity and access security concepts (SSO/MFA, privileged access, conditional access) and identity-driven attack patterns and detections.

• Understanding of compliance and governance initiatives and the ability to translate requirements into operational controls, procedures, and evidence.

• Vulnerability and exposure understanding sufficient to prioritize response actions (active exploitation, blast radius, compensating controls) and guide remediation.

• Familiarity with automation/SOAR concepts and scripting for investigation and response workflows (e.g., Python/PowerShell or equivalent).

• Ability to develop and implement incident response programs with measurable outcomes (response readiness, containment speed, detection coverage, exercise cadence).

• Strong organization/project planning, time management, and change management skills across multiple functional groups and departments, including prioritizing work during incident conditions.

• Advanced problem-solving experience involving leading teams in identifying, researching, and coordinating resources necessary to troubleshoot/diagnose complex issues; success translating findings into options/solutions; identifying risks/impacts and schedule adjustments to facilitate management decision-making.

• Advanced communication (verbal and written) and customer service skills, including the ability to brief senior/executive leadership with clear, concise, decision-oriented updates.

ACCOUNTABILITIES:

• Serve as the senior incident commander and technical lead for high-severity incidents; drive structured triage, containment, eradication, and recovery across the enterprise.

• Lead and coordinate incident response efforts for high-severity events spanning hybrid and multi-cloud environments (on-prem, AWS, Azure, GCP), ensuring effective containment, eradication, and recovery.

• Own and continuously improve the incident response program: playbooks/runbooks, severity definitions, escalation paths, on-call expectations, evidence handling standards, and crisis communications patterns.

• Plan, run, and mature readiness activities including tabletop exercises and cyber range events; define objectives, measure outcomes, and ensure follow-through on remediation actions.

• Own after-action governance: facilitate post-incident reviews, establish root cause and contributing-factor analysis, drive corrective action plans, and track closure to completion (closed-loop improvement).

• Lead analysis and review of security events for anomalous activity; collaborate with peer groups to take appropriate action to safeguard company information assets against current and foreseen threats.

• Drive improvements to detection, investigation, and response processes through lessons learned, measurable corrective actions, and operational performance metrics.

• Drive the design, implementation, and continuous improvement of detection engineering and monitoring capabilities within AWS environments.

• Partner with infrastructure, cloud, endpoint, identity, and application teams to ensure response-ready logging, telemetry, and access to required investigative data sources.

• Provide guidance for threat-informed mitigation and hardening activities resulting from incidents (e.g., containment controls, identity protections, logging improvements, segmentation, credential hygiene).

• Communicate incident status, impact, and risk in executive-ready written and verbal updates; produce high-quality incident summaries and post-incident reports.

• Support compliance and governance efforts by operationalizing response procedures, documenting evidence, and ensuring repeatable execution aligned to policy and regulatory expectations.

• Assist with reviewing tools, applications, and processes to strengthen and optimize current incident response and detection capabilities, identify gaps, and recommend practical solutions to enhance effectiveness.

• Assess and measure incident response program effectiveness to ensure closed-loop operations (e.g., readiness/exercise cadence, time-to-contain, repeat incident reduction, detection coverage and quality).

• All other duties as assigned.

U.S. National Base Pay Range: $104,900 - $174,700. Geographic differentials may apply in some locations to better reflect local market rates.

This job is eligible for an annual incentive bonus.

We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here ( to access benefits specific to your location.

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Form or please contact View phone number on click.appcast.io.

Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.

Please read our Candidate Privacy Policy.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

USA Job Seekers:

EEO Know Your Rights.

RELX is a global provider of information-based analytics and decision tools for professional and business customers, enabling them to make better decisions, get better results and be more productive.

Our purpose is to benefit society by developing products that help researchers advance scientific knowledge; doctors and nurses improve the lives of patients; lawyers promote the rule of law and achieve justice and fair results for their clients; businesses and governments prevent fraud; consumers access financial services and get fair prices on insurance; and customers learn about markets and complete transactions.

Our purpose guides our actions beyond the products that we develop. It defines us as a company. Every day across RELX our employees are inspired to undertake initiatives that make unique contributions to society and the communities in which we operate.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Consulting/Principal Security Engineer in Raleigh, NC vacancy
  • $104.9k - $174.7k

     ...technical guidance that shapes how we approach security across the organization — with real...  ...detection) into CI/CD pipelines in ways engineers actually embrace rather than route...  ...without slowing everything to a crawl At the Principal Level, additionally: Shape multi-year... 
    Suggested
    Full time
    Local area

    Remitly

    Raleigh, NC
    6 hours ago
  •  ...QualificationsIf you like high profile and challenging cloud system security work supporting the readiness of America's Navy ships...  ...forces – Serco has a great opportunity for you! This Principal Information Security Systems Engineer (ISSE) will be working with a dynamic team supporting... 
    Suggested
    Full time
    Contract work
    Part time
    For contractors
    Local area
    Remote work
    Flexible hours

    Serco

    Raleigh, NC
    1 day ago
  • $100k - $172.5k

     ...more at Job Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job...  ...Description: We are searching for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote... 
    Suggested
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    Johnson & Johnson

    Raleigh, NC
    2 days ago
  • A leading cybersecurity firm is seeking a Network Security Engineer to provide implementation and consulting services for clients. The role requires 3 to 5 years of experience in network security engineering and must hold ZDTA or ZDTE certification. Responsibilities include... 
    Suggested
    Remote work
    Flexible hours

    GuidePoint Security

    Raleigh, NC
    4 days ago
  •  ...be sure to visit our tech blog at ally.tech The Cloud Security Principal Engineer position at Ally is a member of the Information Protection...  ...capabilities, including AI security and promoting AI adoption. Consult with project teams to ensure that platform and application... 
    Suggested
    Work experience placement
    Remote work
    Flexible hours

    Ally

    Raleigh, NC
    13 hours ago
  • A leading digital financial services company is looking for a Cloud Security Principal Engineer to manage and improve security across cloud platforms. The engineer will support security infrastructure, troubleshoot security controls, and implement security policies while... 

    Ally Financial Inc.

    Raleigh, NC
    4 days ago
  • $110k - $180k

     ...discretion and/or business need.### The OpportunityThe Cloud Security Principal Engineer position at Ally is a member of the Information Protection...  ...and maturing our application security capabilities* Consult with project teams to ensure that platform architecture has... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Remote work
    Relocation package
    Flexible hours

    Ally Financial Inc.

    Raleigh, NC
    4 days ago
  • A leading digital financial services company is looking for a Cloud Security Principal Engineer to enhance their security posture and automate processes. The role requires over 7 years of relevant experience and a strong background in cloud security technologies, information... 

    Ally Financial Inc.

    Raleigh, NC
    4 days ago
  • $104.9k - $174.7k

     ...for each legal use case. About the Role : As a Consulting AWS Cloud Network Infrastructure Engineer, you will help define best practices, establish...  ...ensure our Cloud Network infrastructure is robust, secure, scalable, resilient, monitored and cost-efficient.... 
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    LexisNexis

    Raleigh, NC
    4 days ago
  •  ...Design Group is a fully integrated architecture, engineering, construction, system integration, and consulting firm committed to helping our clients realize their...  ...and fulfillment.When you join Design Group as a Principal Process Engineer, you are joining a team that... 
    Work at office

    Barry-Wehmiller Companies Inc.

    Raleigh, NC
    4 days ago
  •  ...Introduction A career in IBM Consulting is built on long-term client relationships and close collaboration worldwide. You’ll work...  ...experiences. Your role and responsibilities The Azure Security Engineer will support a large team of infrastructure, security and... 
    Worldwide

    IBM

    Raleigh, NC
    2 days ago
  • $118.3k - $219.8k

     ...each legal use case. About the Role : As a Senior Consulting Principal AWS Cloud Engineer, you will provide technical strategy, deep AWS...  ...Kubernetes, DevOps, Infrastructure as Code (IaC), and security architectures, with a strong ability to mentor and drive... 
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    LexisNexis

    Raleigh, NC
    4 days ago
  •  ...Group (LDG) is an award-winning, employee-owned Architecture, Engineering, and Consulting Firm. Guided by our core values, we’re expanding our team,...  ...personal growth.     Your Opportunity + Impact The Principal Engineer functions as a licensed, technical leader and... 
    For contractors
    Work at office
    Local area
    Flexible hours

    Larson Design Group

    Raleigh, NC
    26 days ago
  • * Lead and develop high-performing managers and engineering teams across global locations* Establish clear accountability, ownership, and...  ..., Product, Legal, Compliance, and business leaders to align security with business outcomes* Support regulatory and audit requirements... 
    Temporary work
    Work experience placement
    Flexible hours

    Inmar Inc.

    Raleigh, NC
    3 days ago
  • $250k - $315k

     ...environments” - Marc Hamilton, VP, Solutions Architecture & Engineering | NVIDIA   DDN is the global leader in AI and multi-...  ...Job Description DDN is seeking a highly accomplished Principal Engineer – Security Architecture to define and drive the security strategy for... 
    Local area
    Remote work

    DataDirect Networks Inc

    Raleigh, NC
    20 hours ago
  •  ...PES Security and Compliance Engineer Location: Austin (Onsite) - Culver City, CA - Elk Grove, CA - Raleigh, NC RFR Due Date: Jan 16, 2023...  ...years and today we are an Award-Winning Global Software Consultancy solving complex problems with technology. We recognize that... 

    InterSources

    Raleigh, NC
    11 days ago
  • $170.6k - $390k

     ...working world. Join EY’s Cybersecurity consulting practice – the best place in the world to grow your career in information security! The opportunity The Senior...  ...team as a Senior Manager in Cybersecurity Engineering, where you will play a pivotal role in developing... 
    Summer holiday
    Remote work
    Flexible hours

    EY

    Raleigh, NC
    1 day ago
  • An Engineering Consulting Firm is seeking a Senior Project Manager / Civil Engineer to lead technical efforts for diverse Power sector projects. The role involves managing project budgets, ensuring timely delivery of high-quality work, and developing client relationships... 

    Stantec Consulting International Ltd.

    Raleigh, NC
    2 days ago
  • $80k - $100k

    A consulting firm in the pharmaceutical industry seeks a senior engineer with 8+ years in commissioning and qualification. The successful candidate will lead teams, engage in validation projects, and work closely with cross-functional departments in Raleigh, NC. Responsibilities... 

    MMR Consulting

    Raleigh, NC
    4 days ago
  • $110k - $150k

     ...for the world’s built and natural environments. As a team of engineers, architects, designers, scientists, creators and a community of...  ...complexity of the assignment; Liaising with clients, contractors, consultants, mining staff, and other stakeholders; Continuing own... 
    For contractors

    EXP

    Raleigh, NC
    1 day ago
  • $95.3k - $158.8k

     ...This position is a Hybrid role on site in the Raleigh N.C. office 2-3 days a week. Senior Security Engineer II - Compliance Automation & Controls About Us LexisNexis, a part of RELX, is a leading global provider of legal, regulatory, and business information... 
    Work at office
    Local area
    Remote work
    Flexible hours
    2 days per week
    3 days per week

    RELX Group plc

    Raleigh, NC
    6 days ago
  • $65.1k - $108.5k

     ...Monitoring Maintain continuous operational visibility into the security posture of FedRAMP systems, including vulnerabilities, assets,...  ...ConMon artifacts, including monthly summaries Partner with engineering, cloud, and security teams to support timely remediation... 
    Local area

    RELX

    Raleigh, NC
    1 day ago
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar) Some... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Raleigh, NC
    4 days ago
  • $150k - $250k

     ...to thrive - in our offices or yours. Job Summary The Security Engineer - Google collaborates with account and specialty teams to assess...  ...a customer-facing cloud security expert.?They will take a consultative approach to security projects and have a holistic... 
    Work experience placement
    Work at office
    Worldwide
    Flexible hours

    SHI GmbH

    Raleigh, NC
    1 day ago
  • $65 - $70 per hour

     ...Title: Wiz DSPM Security Engineer Location: Research Triangle Park (RTP), North Carolina, area. (Onsite position) Duration: 6+ Month Contract Compensation: $65-$70 HR Target Work Requirements: US Citizen, GC Holders or Authorized to Work in the U.S. Skillset... 
    Contract work
    For contractors
    Local area
    Flexible hours

    INSPYR Solutions

    Raleigh, NC
    13 hours ago
  •  ...NAVA Software solutions is looking for a Network Security Engineer Details: Network Security Engineer Location: Raleigh, NC - Hybrid Duration: 6-12 months We are looking for outstanding candidates to join an agile, highly professional... 
    Temporary work
    Work at office
    Remote work
    Monday to Friday

    Nava Software Solutions

    Raleigh, NC
    13 hours ago
  •  ...Job Description Network Security Engineer Raleigh, NC (on-site) - local candidates will only be considered US or Green Card will only be considered US based work experience required The Network Security Engineer to protect the integrity and confidentiality... 
    Work experience placement
    Local area

    System Soft Technologies

    Raleigh, NC
    3 days ago
  •  ...The Network Security Engineer is responsible for the day-to-day operations, maintenance, and continuous improvement of perimeter security services across global data centers and cloud environments. This role focuses on firewall, proxy, and zero-trust solutions, ensuring... 
    Permanent employment
    Temporary work
    Remote work
    Flexible hours

    Honeywell

    Raleigh, NC
    2 days ago
  • $105.1k - $164.13k

     ...highly technical professionals with a strong foundation in network architecture, design, and security - individuals who are ready to step up from traditional network engineering roles to take ownership of strategic, architecture-level responsibilities. Ideal candidates... 
    Permanent employment
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Noblis

    Raleigh, NC
    1 day ago
  • $98.9k

     ...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal candidate brings broad technical expertise and hands-on experience in end-to-end product security. In this role, you'll collaborate with... 
    Work at office
    Remote work

    Zoom Corporation

    Raleigh, NC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Consulting/Principal Security Engineer. Be the first to apply!