Principal Cyber Security Engineer

Ally Financial

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Detroit, MI
Salary
$110,000–$180,000 / yr
Employment
Full-time
Posted
5 days ago
Freshness
Confirmed live yesterday
Closes
Oct 13, 2026

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $185k
This role $145k
$95k most similar roles pay here $250k

This role pays less than 82% of similar roles. Most pay $156,100–$213,125 — the shaded band above. At the midpoint, this role pays about $145k versus about $185k for comparable roles.

Based on 240 similar postings.

Employer

About Ally Financial

Ally Financial is a US-based digital financial services company offering online banking, auto financing, mortgage, and investment products. It is one of the largest all-digital banks in the United States.

Ally Financial currently has 12 open roles on FindRole.

Listed pay typically runs $110,000–$180,000 across 12 roles with salary data.

Most-posted roles

View all roles at Ally Financial

At a glance

TL;DR · Principal Cyber Security Engineer

As a Principal Cyber Security Engineer, you will join the security team to own the end-to-end lifecycle of SIEM capabilities, including architecture, data onboarding, content engineering, and automation. You will design and maintain SIEM infrastructure, manage ingestion pipelines, and ensure high-fidelity detections for various log sources like EDR, firewalls, and cloud platforms such as AWS, Azure, and GCP. The role involves optimizing performance through indexing and storage management while ensuring compliance with standards like SOC 2 and PCI-DSS. You will utilize tools including Splunk, Cribl, Python, PowerShell, Terraform, and Ansible to build detection rules and automate workflows. Key technical skills include proficiency in KQL, SPL, and Grok for data parsing, as well as experience with Kafka, Kubernetes, and threat detection frameworks like MITRE ATT&CK to solve complex security visibility challenges.

What you'll do

  • Design and maintain SIEM architecture including data ingestion pipelines, parsers, normalization schemas, and storage tiers.
  • Onboard logs from diverse sources such as EDR, firewalls, cloud platforms, and identity providers.
  • Optimize SIEM performance regarding indexing, search speed, cost control, and high availability.
  • Develop detection rules, correlation logic, and automated content using scripting languages like Python or PowerShell.
  • Monitor data quality and create SLA-driven dashboards for ingestion health and parser accuracy.
  • Conduct purple-team exercises and assessment of detection gaps to drive remediation efforts.
  • Ensure SIEM data handling complies with regulatory requirements such as SOC 2, PCI-DSS, and GDPR.
  • Provide runbooks, training materials, and technical documentation for SOC and IT teams.

What we're looking for

  • 5+ years of experience in SIEM engineering or closely related security engineering roles.
  • Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
  • Proven expertise with at least one enterprise SIEM platform such as Splunk, Microsoft Sentinel, QRadar, or Elastic Security.
  • Proficiency in data parsing and normalization using regex, grok, KQL, SPL, AQL, or Lucene.
  • Experience with scripting and automation using Python, PowerShell, REST APIs, Terraform, or Ansible (preferred).
  • Experience with public cloud platforms (AWS, Azure, GCP) and associated logging and security services.
  • Knowledge of data pipelines/messaging (Kafka, Kinesis, Event Hubs) and experience in regulated environments like financial services or healthcare.
  • Relevant certifications such as GCDA, GCIA, GCFE, GCIH, GMON, Splunk Certified Architect, Microsoft Certified: Cybersecurity Architect, AWS/Azure security certs, or CISSP.

More like this

Similar roles

Cybersecurity Engineer Principal

General Dynamics

Bossier City, LA 67 days ago $146,200–$197,800
Splunk CrowdStrike Falcon Microsoft Sentinel IBM QRadar Palo Alto XSOAR Python PowerShell Bash Active Directory IAM PKI EDR SIEM SOAR Qualys Tenable Rapid7 AWS Azure GCP MITRE ATT&CK NIST 800-53 FISMA DISA STIGs CIS Benchmarks
8+ yrs exp Hybrid

Security Data Solutions Engineer

State Street

Quincy, MA +4 58 days ago
Python SQL Spark Kafka Databricks Snowflake Splunk Microsoft Sentinel QRadar Elastic Cribl OpenTelemetry FluentBit AWS Azure Google Cloud ETL ELT DevSecOps NIST CSF MITRE ATT&CK
8+ yrs exp Hybrid

SIEM & Security Data Staff Engineer

USAA

San Antonio, TX +3 4 days ago $164,780–$314,960
SIEM Splunk Microsoft Sentinel Google SecOps Elastic QRadar Snowflake Databricks Kafka Cribl Kinesis Event Hubs Python PowerShell SQL Data Lake
8+ yrs exp Hybrid

Information Security Risk Analyst

Lam Research

Tualatin, OR 79 days ago
SIEM Microsoft Sentinel Splunk KQL SPL SQL Python PowerShell MITRE ATT&CK UEBA Azure AWS Cloud Platform Entra ID Logic Apps MISP STIX/TAXII Threat Hunting Incident Response

Information Security Risk Analyst

Lam Research

Tualatin, OR 88 days ago
SIEM KQL SPL SQL Python PowerShell Microsoft Sentinel Splunk Exabeam Securonix Microsoft Defender XDR Entra ID Azure AWS Cloud Platform MITRE ATT&CK UEBA STIX/TAXII MISP Logic Apps

Principal Cybersecurity Engineer

Leidos

Adelphi, MD 32 days ago $131,300–$237,350
Cybersecurity Architecture Hybrid-Cloud Multi-Cloud NIST FISMA FedRAMP Security Operations Center (SOC) Threat Management Systems Engineering Agile CISSP CISM CCISO Vulnerability Management Incident Response
10+ yrs exp Hybrid