Principal Enterprise Security Engineer
Seattle, King County, Washington, 98127, USA
Listed on 2026-02-23
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security, Security Manager
Pay Rate
$152k - $228k (estimate)
Job DescriptionAn employer is looking for a Remote Principal Enterprise Security Engineer to design, implement, and manage enterprise-wide security solutions. You'll shape our security strategy across endpoint protection, network, SaaS, IAM, and observability, while aligning to NIST and CIS standards. This role reports to the Head of Enterprise Security, with close collaboration with the CISO, CISO staff, and cross‑functional teams.
Key Responsibilities- Security Architecture & Governance:
- Architect enterprise security solutions across endpoints (EDR/XDR), networks, SaaS, and identity/infrastructure.
- Ensure compliance with NIST SP800‑53, CIS benchmarks, and FedRAMP (Low/Moderate/High) standards.
- Design for DoD Impact Levels IL‑4 and IL‑5 environments, integrating enhanced controls beyond FedRAMP High.
- IAM & Access Management:
- Implement and manage IAM frameworks: RBAC, MFA, SAML, OAuth, SCIM.
- Regularly review and optimize privilege configurations.
- Endpoint & Network Security:
- Deploy and manage endpoint security tools (e.g., Crowd Strike, Sentinel One).
- Define network security strategies including firewalls (e.g., Palo Alto), micro‑segmentation, VPNs.
- Develop and maintain device health assessments and dashboards leveraging device telemetry from enterprise security tooling.
- Configure and maintain Data Loss Prevention (DLP) tooling & policies.
- Support security deployments and configurations across multiple operating systems:
Windows 10/11, macOS, Windows Server, RHEL, Oracle, CentOS. - Experience with Security Service Edge and Software‑Defined Perimeter enables ZTNA solutions such as NetSCOPE, Zscaler, and PAN.
- SaaS Security & Cloud Compliance:
- Secure SaaS applications using SSPM tools and integrate them into governance frameworks.
- Maintain compliance evidence for FedRAMP/DoD IL audits and ATO packages.
- Incident Response & Threat Intelligence:
- Lead incident response efforts: detection, triage, investigation, mitigation, and post‑mortems.
- Coordinate with threat intel teams to feed strategic threat insights into detection logic and tools.
- Vulnerability Management & Observability:
- Own vulnerability scanning, CVE tracking, patch‑rollout, and POA&M development.
- Build and tune observability systems (SIEM, EDR, logging, telemetry) to support security posture.
- Automation & Scripting:
- Automate security workflows using Python, Power Shell, Bash, or similar languages.
- Integrate automation into tooling for reporting, incident response, compliance, detection, and remediation.
- Collaboration & Communication:
- Collaborate with the CISO and staff to align security initiatives with organizational strategy.
- Communicate technical concepts clearly to leadership, compliance, legal, and engineering teams.
- Develop and deliver security training and awareness for teams across the enterprise.
- 7+ years in enterprise or cloud security with hands‑on background in IAM, endpoint/network/SaaS security, incident management, vulnerability management, and log analytics.
- 7+ years of experience with DoD IL‑4/IL‑5 programs—understand added encryption, personnel restrictions, and control overlays.
- 6+ years of experience working with tools like Crowd Strike, Palo Alto, F5, Splunk/ELK, and IAM platforms (Okta, Entra , etc.).
- 7+ years of experience with scripting/automation using Python, Power Shell, Bash, etc.
- 5+ years of experience with security frameworks: NIST SP800‑53/171, CIS Benchmarks, FedRAMP, DoD CC SRG.
- Solid understanding of FedRAMP security controls and audit frameworks.
- Strong verbal and written communication; ability to convey complex topics to executives; experience working with stakeholders across multiple time zones.
- Bachelor’s degree in cybersecurity, computer science, engineering—or equivalent years of corporate security/SOC experience.
- Experience with BigIP LTM
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).