Principal Security Engineer- Cyber Defense

Volvo GroupGreensboro, NC
$128,300 - $158,400

About The Position

Transport is at the core of modern society. Imagine using your expertise to shape sustainable transport and infrastructure solutions for the future. If you seek to make a difference on a global scale, working with next-gen technologies and the sharpest collaborative teams, then we could be a perfect match. We are seeking a Principal Security Engineer to join our global Cyber Defense Center (CDC) Engineering team. You will apply an Everything-as-Code approach to build and manage our software-defined security operations architecture, designing the logic and systems that power our global detection and response platform.

Requirements

  • Problem-solving mindset with the ability to bridge the gap between engineering and SOC operations effectively. Able to convey targeted messages to different audiences.
  • Strong background in SOC and/or SecOps engineering.
  • Proficiency in Python or PowerShell, software engineering best practices, APIs, and data structures (JSON/YAML).
  • Deep proficiency in security query languages (Splunk SPL, KQL, SQL) and Python/TypeScript.
  • Hands-on experience with Git and CI/CD platforms for managing infrastructure and logic as code.
  • Technical experience configuring and administering enterprise security controls (XDR/EDR/NDR, Firewalls, Cloud Security, DLP, Identity).
  • Familiarity with Graph Databases (Neo4j, Cosmos DB Gremlin) and entity relationship modeling.
  • Experience integrating LLMs or building RAG pipelines for enterprise use cases.
  • Experience with Docker, API Gateways, and Infrastructure-as-Code (Terraform/Bicep).
  • Experience working with compiled languages (C# / .NET).
  • Exposure to Operational Technology (OT) and manufacturing environments.

Responsibilities

  • Engineer Detection-as-Code: Write detection logic using KQL, SPL, SQL, and Python. Manage the lifecycle strictly through version control and CI/CD pipelines. Create new monitoring use cases based on red team exercises, CTIC reports, and your own hypothesis-driven threat research.
  • Automate Threat Response: Build and integrate modular automation playbooks across the security stack to accelerate incident response.
  • Optimize Security Controls: Configure and tune enterprise security controls (XDR, firewalls, cloud security, DLP) to adapt to new threats.
  • Drive Capability Engineering: Partner with cross-functional teams to translate analytical needs into architecture and working code. Ensure engineering output directly supports frontline defenders without adding operational friction.
  • Establish AI & Data Foundations: Integrate contextual data models (like knowledge graphs), API gateways, and threat intelligence pipelines to support our targeted AI and ML workloads.
  • Leverage Hybrid Data Ecosystems: Develop detection and automation use cases across a variety of different data architectures (SIEM, data lakes, S3/Storage blobs, Federated Search).
  • Mitigate Security Gaps: Mitigate detection and response gaps through the creation of new detection rules, improvement of processes, new architectural designs, and hand-over to other technical teams.
  • Enforce Pipeline Quality: Build and maintain CI/CD pipelines with automated validation gates for secure content deployment. Use breach attack simulation & threat intelligence verification where applicable in larger validation workflows.

Benefits

  • Competitive medical, dental and vision insurance.
  • Generous paid time off.
  • Competitive matching retirement savings plans.
  • Working environment where your safety, health and wellbeing come first.
  • Focus on professional and personal development through Volvo Group University.
  • Programs that make today’s challenging reality of combining work and personal life easier.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service