Consulting/Principal Security Engineer

RELX

Raleigh (NC)

On-site

USD 104,900 - 174,700

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

RELX in Raleigh, NC seeks a Principal Incident Response Lead to provide strategic and tactical leadership for enterprise incident response within a complex hybrid environment. This role serves as the senior incident commander and technical authority for high-severity security events, delivering executive-ready decision support based on evolving threats and cloud capabilities.

The position drives readiness, containment, and recovery actions, coordinating across technical teams and guiding

Qualifications

  • 10+ years IT security experience with incident response leadership.
  • BS in Engineering or Computer Science; advanced degree preferred.
  • Certifications like GCIH/GCFA and cloud security certs are preferred.

Responsibilities

  • Lead senior incident commander for high-severity events.
  • Develop and maintain incident response playbooks and readiness.
  • Coordinate cross-functional teams across on-prem and cloud.
  • Drive improvements in detection and response via lessons learned.

Skills

Incident response leadership
Hybrid/multi-cloud experience
AWS security monitoring
Executive communication
Tabletop exercises
Threat detection

Education

BS Engineering/Computer Science
Advanced degree preferred

Tools

AWS
Azure
GCP

Job description

Profile Summary

The Principal Incident Response Lead position provides strategic and tactical leadership for enterprise incident response across a complex hybrid environment. This role serves as the senior incident commander and technical authority for high-severity security events, providing executive-ready decision support based on evolving threats, attack techniques, and advances in technology. The position supports the Information Security department’s goals and objectives by leading escalations, guiding containment and recovery actions, and driving measurable improvements to response readiness and detection effectiveness. This role requires deep expertise in leading complex incident response efforts across hybrid environments and advancing cloud-native detection and monitoring capabilities, particularly within AWS. The role also owns the incident response program’s readiness lifecycle—including tabletops, cyber range exercises, and after-action governance to ensure continuous improvement and operational resilience.

Job Description

BASIC FUNCTIONS: This position will provide strategic and tactical incident response leadership, providing management with insight and input into overall security operations decisions based on advances in technology and the evolving threat landscape. The position supports the Information Security department’s goals and objectives by leading escalations and coordinating response activities across multiple technical teams, ensuring consistent execution of triage, containment, eradication, and recovery. This position serves as the senior incident commander, establishes and maintains incident response readiness (playbooks, communications patterns, exercises), and drives detection and response improvements through lessons learned and measurable program outcomes.

Qualifications
  • 10+ years of IT security experience, including significant incident response leadership in enterprise environments
  • BS Engineering/Computer Science or equivalent experience required; advanced degree preferred
  • Preferred: incident handling/forensics-focused certifications (e.g., GCIH, GCFA or equivalent) and cloud security certification(s) (AWS/Azure/GCP)
Technical Skills
  • Advanced knowledge of modern security operations environments, including hybrid enterprise architectures and common attack paths.
  • Demonstrated experience leading incident response activities across complex hybrid environments, including on-premises infrastructure and multi-cloud platforms (AWS, Azure, GCP).
  • Strong hands-on experience engineering detections, telemetry, and monitoring solutions within AWS (e.g., CloudTrail, GuardDuty, VPC Flow Logs, and related services).
  • Expertise in incident command practices: severity assessment, stakeholder coordination, containment strategies, evidence handling, eradication and recovery planning, and post-incident review.
  • Strong ability to monitor, triage, and investigate security events; apply structured analysis for anomalous activity and adversary behaviors.
  • Experience with enterprise logging and telemetry pipelines, log onboarding strategies, and data quality expectations (coverage, fidelity, retention).
  • Experience improving detection quality and signal-to-noise (e.g., tuning, suppression, enrichment, validation, and feedback loops).
  • Working knowledge of identity and access security concepts (SSO/MFA, privileged access, conditional access) and identity-driven attack patterns and detections.
  • Understanding of compliance and governance initiatives and the ability to translate requirements into operational controls, procedures, and evidence.
  • Vulnerability and exposure understanding sufficient to prioritize response actions (active exploitation, blast radius, compensating controls) and guide remediation.
  • Familiarity with automation/SOAR concepts and scripting for investigation and response workflows (e.g., Python/PowerShell or equivalent).
  • Ability to develop and implement incident response programs with measurable outcomes (response readiness, containment speed, detection coverage, exercise cadence).
  • Strong organization/project planning, time management, and change management skills across multiple functional groups and departments, including prioritizing work during incident conditions.
  • Advanced problem-solving experience involving leading teams in identifying, researching, and coordinating resources necessary to troubleshoot/diagnose complex issues; success translating findings into options/solutions; identifying risks/impacts and schedule adjustments to facilitate management decision-making.
  • Advanced communication (verbal and written) and customer service skills, including the ability to brief senior/executive leadership with clear, concise, decision-oriented updates.
Accountabilities
  • Serve as the senior incident commander and technical lead for high-severity incidents; drive structured triage, containment, eradication, and recovery across the enterprise.
  • Lead and coordinate incident response efforts for high-severity events spanning hybrid and multi-cloud environments (on-prem, AWS, Azure, GCP), ensuring effective containment, eradication, and recovery.
  • Own and continuously improve the incident response program: playbooks/runbooks, severity definitions, escalation paths, on-call expectations, evidence handling standards, and crisis communications patterns.
  • Plan, run, and mature readiness activities including tabletop exercises and cyber range events; define objectives, measure outcomes, and ensure follow-through on remediation actions.
  • Own after-action governance: facilitate post-incident reviews, establish root cause and contributing-factor analysis, drive corrective action plans, and track closure to completion (closed-loop improvement).
  • Lead analysis and review of security events for anomalous activity; collaborate with peer groups to take appropriate action to safeguard company information assets against current and foreseen threats.
  • Drive improvements to detection, investigation, and response processes through lessons learned, measurable corrective actions, and operational performance metrics.
  • Drive the design, implementation, and continuous improvement of detection engineering and monitoring capabilities within AWS environments.
  • Partner with infrastructure, cloud, endpoint, identity, and application teams to ensure response-ready logging, telemetry, and access to required investigative data sources.
  • Provide guidance for threat-informed mitigation and hardening activities resulting from incidents (e.g., containment controls, identity protections, logging improvements, segmentation, credential hygiene).
  • Communicate incident status, impact, and risk in executive-ready written and verbal updates; produce high-quality incident summaries and post-incident reports.
  • Support compliance and governance efforts by operationalizing response procedures, documenting evidence, and ensuring repeatable execution aligned to policy and regulatory expectations.
  • Assist with reviewing tools, applications, and processes to strengthen and optimize current incident response and detection capabilities, identify gaps, and recommend practical solutions to enhance effectiveness.
  • Assess and measure incident response program effectiveness to ensure closed-loop operations (e.g., readiness/exercise cadence, time-to-contain, repeat incident reduction, detection coverage and quality).
  • All other duties as assigned.

U.S. National Base Pay Range: $104,900 - $174,700. Geographic differentials may apply in some locations to better reflect local market rates. This job is eligible for an annual incentive bonus.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Security Engineering, AWS Security Incident Response
Manager, Security Engineering, AWS Security Incident Response

Amazon • Seattle (WA)

On-site
USD 175,100 - 236,900
Health insurance
401(k) matching
Paid time off
+1
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
Senior Incident Responder, Global CSIRT
Senior Incident Responder, Global CSIRT

Jobtailor • United States

On-site
USD 120,000 - 180,000
Incident Response Lead
Incident Response Lead

ECS Corporate Services • Washington

Hybrid
USD 140,000 - 150,000
Engineer - Security Operations and Incident Response
Engineer - Security Operations and Incident Response

Jobgether • United States

Hybrid
USD 125,000 - 190,000
Remote or hybrid work
Technical Enterprise Incident Manager
Technical Enterprise Incident Manager

Peraton • Reston (VA)

On-site
USD 86,000 - 138,000
Incident Response Lead
Incident Response Lead

ECS • Washington

Hybrid
USD 140,000 - 150,000
Senior Incident Response Engineer
Senior Incident Response Engineer

Elsevier • New Jersey

Hybrid
USD 89,000 - 143,000
Annual incentive bonus
Incident Response Engineer - Cyber Defense
Incident Response Engineer - Cyber Defense

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000