Back to All Jobs

Principal Security Engineer

Scholastic

EngineeringFull Time$165k - $185k
Location
New York, NY
Posted
October 7, 2026

Job Description

This Principal Security Engineer role is based in New York City and encourages a minimum of two days per week in the SoHo office. Some roles or teams may require additional in-office attendance if the essential functions of the role require it.

The Principal Security Engineer will be part of the Scholastic Security organization and report to the Executive Director of Information Security and Compliance. This role will work closely with the CISO and the SVP of Technology Operations to proactively identify, assess, and reduce security risk across Scholastic's network, systems, applications, and third-party ecosystem.

The position is responsible for assessing information risk, identifying vulnerabilities, facilitating remediation, documenting mitigation options, monitoring remediation progress, and reporting findings and recommendations. The Principal Security Engineer will also support IT audits, risk assessments, regulatory compliance, vulnerability assessments, third-party risk management activities, and weekly project status reporting.

Responsibilities

  • Design and implement security architecture and controls across cloud, network, endpoint, and application environments
  • Work closely with team members to enhance, implement, and configure scalable security technologies and improve detection and response capabilities
  • Lead engineering efforts to build, tune, and scale security tooling, including SIEM, EDR, vulnerability management, identity and access management, TPRM and secrets management platforms
  • Work closely with the SOC to review, develop, and maintain incident response playbooks
  • Serve as an escalation point for SOC incidents, providing technical guidance and support during investigation and response activities
  • Develop metrics and KPIs that demonstrate security posture, control effectiveness, and tooling consolidation progress
  • Automate security controls and evidence collection to support audit and compliance programs, including SOX IT General Controls, PCI DSS, SOC 2
  • Ensure CIS benchmark controls are applied, configurations are maintained across the enterprise, continuous monitoring is performed, and remediation plans are developed for identified gaps
  • Continuously improve the security framework, methodology, standards, and system of internal controls
  • Lead and assist in security risk assessments for systems and applications
  • Address questions from internal and external audits and examinations
  • Develop policies, procedures, and standards that meet existing and newly developed policy and regulatory requirements, including SOX, PCI, and Privacy
  • Research business and technical challenges and provide solution recommendations to mitigate risk and improve our security posture
  • Perform security reviews, identify gaps in security architecture, and develop a security risk management plan
  • Serve as a project lead within IT security projects
  • Provide advice on project costs, design concepts, or design changes
  • Define and document how the implementation of a new system, or interfaces between systems, impacts the security posture of the current environment
  • Drive and deliver Enterprise security roadmap and initiatives
  • Conduct a cybersecurity incident response tabletop exercise at least annually
  • Identify opportunities to reduce risk and document remediation options regarding acceptance or mitigation of risk scenarios
  • Investigate security incidents and lead incident response activities, including minimizing impact, performing technical and forensic analysis, determining root cause, and assessing the extent of damage
  • Build tools and automation scripts that enable developers to consume security services delivered by the Security Engineering and Automation team
  • Monitor emerging threats, vulnerabilities, and industry best practices to inform risk decisions and security roadmap priorities
  • Develop metrics/KPIs to show security posture and tools consolidation
  • Develop and maintain documentation, runbooks, and standards for security engineering practices
  • Track emerging threats, vulnerabilities, and industry best practices, and translate relevant developments into actionable recommendations for leadership
  • Mentor and provide technical leadership to other security analysts, engineers, and contribute to hiring and skill development

Qualifications

  • A bachelor's degree in information systems, engineering, or equivalent work experience
  • Candidates with the following certifications are preferred: ISC2, SANS, ISACA, or other recognized security professional credentialing organizations
  • Minimum 10+ years of experience in designing and implementing security solutions, including IAM, EDR, MDM, SIEM, KMS, and PAM
  • 5+ years of experience in a Security Operations Center or Continuous Monitoring role
  • 5+ years working and supporting Incident Response functions
  • Hands-on experience with software development languages and technologies, including Java, C#, C++, JavaScript, and HTML
  • Strong hands-on infrastructure security skills, including IDS/IPS, firewalls, SIEM, server and operating system hardening, malware detection, physical security, and encryption for data in transit and at rest across file systems, databases, and other data persistence mechanisms
  • Experience managing application security testing tools, including SAST, DAST, and open-source vulnerability scanning
  • Experience implementing SOX, PCI, NIST CSF, CIS Controls, and SANS Controls is required
  • Excellent written and verbal communication skills — including the ability to effectively communicate security- and risk-related concepts to technical and non-technical audiences — and strong interpersonal and collaborative skills
  • Ability to operate with minimal supervision as a self-starter who can identify and resolve problems, manage multiple priorities, deliver results, and meet deadlines
  • Knowledge of tactics, techniques, and procedures that are leveraged to perform recon, which can be used to gain persistence, move laterally, or exfiltrate data
  • In-depth knowledge and understanding of information risk concepts and principles as a means of relating business needs to security controls, excellent understanding of information security concepts, protocols, industry best practices, and strategies
  • Ability to work in a highly fast-paced environment with high expectations

Compensation and Benefits

  • Annual Salary: $165,000.00 - $185,000.00
  • Full suite of health and wellness benefits (including a $0 deductible Medical Plan)
  • Retirement Savings Plan 401(k) with options for both Roth and Traditional Contributions
  • Tuition-Free programs for undergraduate and graduate degrees
  • Generous Parental Leave Program
  • Employee Stock Purchase Plan (ESPP) with opportunity for discounted stock at a 15% discount

Time Type: Full time

Job Type

Regular

Job Family Group: Information Technology

Location

Region/State: New York