Principal Engineer - Detection and Response jobs in United States
cer-icon
Apply on Employer Site
company-logo

Wells Fargo · 11 hours ago

Principal Engineer - Detection and Response

Wells Fargo is seeking a Principal Engineer in Technology as part of Cybersecurity. This role will serve as the senior technical leader responsible for engineering and maturing the Cyber Incident Detection & Response ecosystem, ensuring rapid response and alignment with enterprise risk and regulatory expectations.

BankingFinancial ServicesFinTechInsurancePayments
badNo H1Bnote

Responsibilities

Act as an advisor to leadership to develop or influence applications, network, information security, database, operating systems, or web technologies for highly complex business and technical needs across multiple groups
Lead the strategy and resolution of highly complex and unique challenges requiring in-depth evaluation across multiple areas or the enterprise, delivering solutions that are long-term, large-scale and require vision, creativity, innovation, advanced analytical and inductive thinking
Translate advanced technology experience, an in-depth knowledge of the organizations tactical and strategic business objectives, the enterprise technological environment, the organization structure, and strategic technological opportunities and requirements into technical engineering solutions
Provide vision, direction and expertise to leadership on implementing innovative and significant business solutions
Maintain knowledge of industry best practices and new technologies and recommends innovations that enhance operations or provide a competitive advantage to the organization
Strategically engage with all levels of professionals and managers across the enterprise and serve as an expert advisor to leadership
Serve as the senior technical advisor for the CIDR ecosystem, including architecture, engineering, workflow orchestration, automation, and emerging AI-enabled capabilities
Define and maintain the long-term architectural vision, technical standards, and reference designs for detection and response platforms, ensuring cohesive integration across cloud, endpoint, identity, network, and third-party environments
Translate enterprise risk, threat intelligence, operational data, and regulatory expectations into actionable engineering direction, roadmaps, and platform investments
Lead evaluation of emerging tools and industry trends to drive continuous modernization of CIDR capabilities
Provide deep technical expertise and engineering leadership across detection architecture, SIEM design, log/telemetry pipelines, correlation logic, enrichment workflows, alert lifecycle management, and SOAR automation
Engineer reliable, scalable detection pipelines aligned with MITRE ATT&CK, NIST 800-61, and other frameworks
Lead design and engineering of playbooks, automated workflows, metrics, reporting, and escalation paths into Incident Management and CSIRT
Ensure telemetry coverage, detection fidelity, and tuning processes meet enterprise quality, performance, and risk requirements
Serve as the primary technical architect and decision authority for large-scale, multi-platform, cross-organizational CIDR engineering initiatives
Resolve complex design tradeoffs across scale, performance, data quality, automation reliability, and security risk
Partner with teams across CDM, infrastructure, cloud, identity, engineering, and application platforms to resolve dependencies and drive successful execution
Act as a senior escalation point and technical authority for detection and response issues surfaced through routine SOC operations or major investigations
Partner daily with SOC analysts, threat intelligence teams, CSIRT, engineering teams, and business stakeholders to ensure consistent operational readiness and high-quality detection outcomes
Drive continuous improvement across the detection and response lifecycle, including triage, investigation, containment, and handoff to Incident Management
Ensure CIDR capabilities align with enterprise risk posture, resiliency expectations, and regulatory scrutiny

Qualification

Cybersecurity engineeringSIEM architectureIncident response engineeringDetection engineeringSOC workflow designThreat intelligenceCloud technologiesAI/ML capabilitiesExceptional communicationLeadership skills

Required

7+ years of cybersecurity engineering and technology experience, designing and operating complex security systems at enterprise scale
5+ years of hands-on SOC or incident response engineering experience, including alert pipelines, detection logic, response automation, and case management workflows
Deep technical expertise in SIEM architecture, data onboarding, normalization, correlation, large-scale tuning, and performance optimization
Strong experience in detection engineering, SOC workflow design, and playbook/runbook development
Demonstrated ability to translate threat intelligence into detection logic at scale
Strong knowledge of incident response and detection frameworks (NIST 800-61, MITRE ATT&CK/DEFEND)
Exceptional communication skills and proven experience engaging executive, technical, and operational audiences

Preferred

Familiarity with cloud, endpoint, identity, network, and third-party ecosystems that underpin enterprise-scale detection and response
Experience integrating internal and external threat intelligence feeds into SOC workflows
Experience using AI/ML capabilities in SOC environments (triage, correlation, anomaly detection)
Professional certifications such as CISSP, CISM, CISA, GIAC-GCIA/GCIH/GCTI, or equivalent

Benefits

Health benefits
401(k) Plan
Paid time off
Disability benefits
Life insurance, critical illness insurance, and accident insurance
Parental leave
Critical caregiving leave
Discounts and savings
Commuter benefits
Tuition reimbursement
Scholarships for dependent children
Adoption reimbursement

Company

Wells Fargo

company-logo
Wells Fargo & Company is a financial services firm that provides banking, insurance, investments, and mortgage services.

Funding

Current Stage
Public Company
Total Funding
unknown
1978-10-06IPO

Leadership Team

leader-logo
Charlie Scharf
CEO
leader-logo
Fernando Rivas
CEO of Corporate & Investment Banking
linkedin
Company data provided by crunchbase