Government Jobs
  • Principal Detection & Response Engineer

  • Lawrence Harvey
  • New York, New York United States US View Map

Summary

Lawrence Harvey is partnered with a financial services firm that's looking to expand their security team. This client is looking for a D&R Engineer to take ownership of the program and build it from the ground up.


The Opportunity

We are seeking a Principal Detection & Response Engineer to take ownership of the organization's detection and response capabilities across a complex, highly regulated environment.

This is a senior individual contributor role with broad technical ownership across the full detection and response lifecycle: from telemetry collection and threat intelligence through detection engineering, AI-assisted triage, investigation, and incident response.

The ideal candidate is highly hands-on, technically strong, and passionate about engineering detection and response capabilities rather than simply operating them. You will set technical standards, build scalable security tooling, improve automation, and apply AI where it can meaningfully improve security operations.


What You'll Do

  • Own the end-to-end detection and response pipeline, including telemetry collection, processing and enrichment, detection, AI-assisted triage, investigation, escalation, and incident response.
  • Build and maintain an intelligence-informed prioritization framework that translates threat intelligence and organizational risk into prioritized hardening, detection, and automation initiatives.
  • Develop detections as code, including versioned, tested, peer-reviewed detection logic and pipeline configuration mapped to MITRE ATT&CK or a comparable framework.
  • Engineer, tune, and operate SIEM, security data pipelines, EDR, SOAR, and case-management platforms to improve signal quality, coverage, reliability, and cost efficiency.
  • Establish standards for alert triage, investigation, escalation, and response while developing tooling and AI-assisted workflows to support those standards.
  • Participate in an on-call rotation and remain directly involved in the operational realities of detection and response.
  • Lead incident response from identification through containment, investigation, remediation, and post-incident activities across corporate, cloud, production, and operational technology environments.
  • Develop detection and response coverage for threats
  • Evaluate and implement new security technologies and AI capabilities, including rigorous testing, guardrails, and build-vs-buy-vs-retire recommendations.
  • Lead tabletop exercises and continuously improve incident response playbooks.
  • Partner closely with Security Engineering, Infrastructure, Platform, and GRC teams.
  • Translate technical threats into business risk, security controls, and executive-level communication.
  • Mentor engineers and help establish a higher engineering standard across the broader security operations function.


Required Experience

  • 10+ years of experience across security operations, detection engineering, and incident response, including experience building or maturing detection and response capabilities in complex environments.
  • Strong software engineering skills in Python or Go, including API-driven integrations and automation.
  • Experience with Infrastructure as Code and detections as code, ideally using Terraform and Git-based development/review workflows.
  • Proven experience designing, operating, and measuring an end-to-end detection and response program across modern SIEM, security data pipeline, EDR, and automation platforms.
  • Strong experience detecting and responding in cloud and identity-centric environments, including AWS, Okta or another enterprise identity provider, Microsoft 365 or Google Workspace, and SaaS audit logging.
  • Strong understanding of attacker tactics, techniques, and procedures, with the ability to translate threat intelligence into high-fidelity detections and prioritized security improvements.
  • Demonstrated use of AI in security operations, including LLM-assisted investigation and detection development, agentic tooling, and integrations such as Claude Code and MCP.
  • Strong judgment around AI-generated output, including the ability to identify when models are inaccurate or introducing risk.
  • Ability to operate at a principal-level IC capacity, setting technical direction and influencing teams without direct authority.
  • Strong communication skills with the ability to connect threat → risk → control → business impact.


Job Description

Lawrence Harvey is partnered with a financial services firm that's looking to expand their security team. This client is looking for a D&R Engineer to take ownership of the program and build it from the ground up.


The Opportunity

We are seeking a Principal Detection & Response Engineer to take ownership of the organization's detection and response capabilities across a complex, highly regulated environment.

This is a senior individual contributor role with broad technical ownership across the full detection and response lifecycle: from telemetry collection and threat intelligence through detection engineering, AI-assisted triage, investigation, and incident response.

The ideal candidate is highly hands-on, technically strong, and passionate about engineering detection and response capabilities rather than simply operating them. You will set technical standards, build scalable security tooling, improve automation, and apply AI where it can meaningfully improve security operations.


What You'll Do

  • Own the end-to-end detection and response pipeline, including telemetry collection, processing and enrichment, detection, AI-assisted triage, investigation, escalation, and incident response.
  • Build and maintain an intelligence-informed prioritization framework that translates threat intelligence and organizational risk into prioritized hardening, detection, and automation initiatives.
  • Develop detections as code, including versioned, tested, peer-reviewed detection logic and pipeline configuration mapped to MITRE ATT&CK or a comparable framework.
  • Engineer, tune, and operate SIEM, security data pipelines, EDR, SOAR, and case-management platforms to improve signal quality, coverage, reliability, and cost efficiency.
  • Establish standards for alert triage, investigation, escalation, and response while developing tooling and AI-assisted workflows to support those standards.
  • Participate in an on-call rotation and remain directly involved in the operational realities of detection and response.
  • Lead incident response from identification through containment, investigation, remediation, and post-incident activities across corporate, cloud, production, and operational technology environments.
  • Develop detection and response coverage for threats
  • Evaluate and implement new security technologies and AI capabilities, including rigorous testing, guardrails, and build-vs-buy-vs-retire recommendations.
  • Lead tabletop exercises and continuously improve incident response playbooks.
  • Partner closely with Security Engineering, Infrastructure, Platform, and GRC teams.
  • Translate technical threats into business risk, security controls, and executive-level communication.
  • Mentor engineers and help establish a higher engineering standard across the broader security operations function.


Required Experience

  • 10+ years of experience across security operations, detection engineering, and incident response, including experience building or maturing detection and response capabilities in complex environments.
  • Strong software engineering skills in Python or Go, including API-driven integrations and automation.
  • Experience with Infrastructure as Code and detections as code, ideally using Terraform and Git-based development/review workflows.
  • Proven experience designing, operating, and measuring an end-to-end detection and response program across modern SIEM, security data pipeline, EDR, and automation platforms.
  • Strong experience detecting and responding in cloud and identity-centric environments, including AWS, Okta or another enterprise identity provider, Microsoft 365 or Google Workspace, and SaaS audit logging.
  • Strong understanding of attacker tactics, techniques, and procedures, with the ability to translate threat intelligence into high-fidelity detections and prioritized security improvements.
  • Demonstrated use of AI in security operations, including LLM-assisted investigation and detection development, agentic tooling, and integrations such as Claude Code and MCP.
  • Strong judgment around AI-generated output, including the ability to identify when models are inaccurate or introducing risk.
  • Ability to operate at a principal-level IC capacity, setting technical direction and influencing teams without direct authority.
  • Strong communication skills with the ability to connect threat → risk → control → business impact.


Government Jobs

Government Jobs

Government jobs offer stability, competitive benefits, and the chance to make a meaningful impact on your community and country.

Whether you’re starting your career or seeking new opportunities, these roles provide pathways for growth, security, and service.

Explore positions across a wide range of fields and take the first step toward a rewarding future in public service.

Show more

MORE JOBS

  • Budget and Policy Analyst- Information Technology

    • Albany, New York
    • NEW YORK DIVISION OF THE BUDGET
    • Sep 30, 2026
    NEW YORK DIVISION OF THE BUDGET
    $59,204 - $70,139 / year - 70139
  • Office Assistant

    • Albany, New York
    • NEW YORK DIVISION OF THE BUDGET
    • Oct 10, 2026
    NEW YORK DIVISION OF THE BUDGET
    $44,879 - $56,718 / year - 56718
  • Economic Analyst

    • Albany, New York
    • NEW YORK DIVISION OF THE BUDGET
    • Sep 30, 2026
    NEW YORK DIVISION OF THE BUDGET
    $90,678 - $113,292 / year - 113292
  • Budget and Policy Analyst - OPWDD

    • Albany, New York
    • NEW YORK DIVISION OF THE BUDGET
    • Sep 30, 2026
    NEW YORK DIVISION OF THE BUDGET
    $59,204 - $70,139 / year - 70139
  • Budget and Policy Analyst - Family Support State Operations

    • Albany, New York
    • NEW YORK DIVISION OF THE BUDGET
    • Sep 30, 2026
    NEW YORK DIVISION OF THE BUDGET
    $59,204 - $70,139 / year - 70139
  • Principal Software Engineer

    • New York, New York
    • Prestige Staffing
    • Oct 10, 2026
    Prestige Staffing
    $202313.000000