Principal Security Engineer- Cyber Defense

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Software Engineering

In short

Volvo Group is looking for a Principal Security Engineer to join their Cyber Defense Center in Greensboro, NC. The role involves building and managing the software-defined security operations architecture, focusing on detection-as-code, automated threat response, and optimizing security controls using a variety of tools and languages. The ideal candidate has a strong background in SOC/SecOps engineering, proficiency in Python, security query languages, GitOps, and experience with enterprise security controls and data modeling.

Responsibilities

  • Engineer Detection-as-Code using KQL, SPL, SQL, and Python, managing the lifecycle through version control and CI/CD pipelines.
  • Create new monitoring use cases based on red team exercises, CTIC reports, and threat research.
  • Automate threat response by building and integrating modular automation playbooks.
  • Optimize security controls like XDR, firewalls, cloud security, and DLP.
  • Partner with cross-functional teams to translate analytical needs into architecture and code.
  • Establish AI & Data Foundations by integrating contextual data models, API gateways, and threat intelligence pipelines.
  • Develop detection and automation use cases across SIEM, data lakes, S3/Storage blobs, and Federated Search.
  • Mitigate security gaps through new detection rules, process improvements, and architectural designs.
  • Build and maintain CI/CD pipelines with automated validation gates for secure content deployment.

Requirements

  • Problem-solving mindset with the ability to bridge engineering and SOC operations.
  • Strong background in SOC and/or SecOps engineering.
  • Proficiency in Python or PowerShell, software engineering best practices, APIs, and data structures (JSON/YAML).
  • Deep proficiency in security query languages (Splunk SPL, KQL, SQL) and Python/TypeScript.
  • Hands-on experience with Git and CI/CD platforms for managing infrastructure and logic as code.
  • Technical experience configuring and administering enterprise security controls (XDR/EDR/NDR, Firewalls, Cloud Security, DLP, Identity).
  • Familiarity with Graph Databases (Neo4j, Cosmos DB Gremlin) and entity relationship modeling.
  • Experience integrating LLMs or building RAG pipelines for enterprise use cases.
  • Experience with Docker, API Gateways, and Infrastructure-as-Code (Terraform/Bicep).
  • Experience working with compiled languages (C# / .NET).
  • Exposure to Operational Technology (OT) and manufacturing environments.

Benefits

  • Competitive medical, dental and vision insurance.
  • Generous paid time off.
  • Competitive matching retirement savings plans.
  • Working environment where your safety, health and wellbeing come first.
  • Focus on professional and personal development through Volvo Group University.
  • Programs that make today’s challenging reality of combining work and personal life easier.
#cyber defense#security engineering#SOC#SecOps
Volvo Group Logo

Company

Volvo Group

Job Posted

3 weeks ago

Employment Type

Full Time

WorkMode

On Site

Experience Level

Senior

Locations

Greensboro, United States

Applicants

Be an early applicant