Security Engineer - Cloud Threat Detection

RoShay Services

Hartford (CT)

Hybrid

USD 140,000 - 210,000

Full time

9 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RoShay Services seeks a Senior Security Engineer specializing in cloud threat detection to design enterprise-scale detection across AWS and GCP. You will implement detections, dashboards, and incident response playbooks.

Bring 5+ years in cybersecurity, hands-on cloud security, and skilled in SIEM tooling like Splunk. Hybrid work with three days in-office, competitive benefits, and opportunities to influence security operations.

Qualifications

  • 5+ years in cybersecurity with SOC or detection engineering.
  • Hands-on AWS and GCP security implementations.
  • Experience developing and tuning SIEM detections from cloud telemetry.
  • Familiarity with MITRE ATT&CK and threat modeling.

Responsibilities

  • Develop, test, and deploy cloud threat detections.
  • Integrate cloud telemetry from AWS and GCP into enterprise SIEM platforms such as Splunk.
  • Create and optimize detections, dashboards, and alerting based on cloud security data sources.
  • Map detections to MITRE ATT&CK techniques and participate in adversary emulation exercises.
  • Develop SOPs, runbooks, and investigation guides for cloud security operations.
  • Train and mentor SOC analysts on cloud threat techniques, tools, and investigation workflows.
  • Provide escalation support during cloud security incidents and participate in on-call rotations.

Skills

Cloud threat detection
AWS & GCP security
SIEM detections
Threat hunting
Documentation & training
Communication

Education

Bachelor's in CS or Cybersecurity

Tools

Splunk Enterprise Security
Python/PowerShell/Bash
SOAR platforms
Endpoint detection tools

Job description

Role: Senior Security Engineer specializing in Cloud Threat Detection, responsible for designing and enhancing enterprise-scale detection capabilities across AWS and GCP.

Key Responsibilities
  • Develop, test, and deploy detection content for cloud threats and suspicious activities.
  • Integrate cloud telemetry from AWS and GCP into enterprise SIEM platforms such as Splunk.
  • Create and optimize detections, dashboards, and alerting based on cloud security data sources.
  • Map detections to MITRE ATT&CK techniques and participate in adversary emulation exercises.
  • Develop SOPs, runbooks, and investigation guides for cloud security operations.
  • Train and mentor SOC analysts on cloud threat techniques, tools, and investigation workflows.
  • Provide escalation support during cloud security incidents and participate in on-call rotations.
Qualifications & Skills
  • 5+ years in cybersecurity, with experience in security operations, incident response, or detection engineering.
  • Hands-on experience securing AWS and GCP environments, with knowledge of their security services.
  • Proficiency in developing and tuning SIEM detections using cloud telemetry.
  • Strong understanding of cloud attack techniques, identity compromise, and threat hunting.
  • Ability to produce operational documentation and training materials.
  • Excellent communication skills.
Preferred Skills & Certifications
  • Experience with Splunk Enterprise Security, scripting (Python, PowerShell, Bash), and security automation.
  • Knowledge of adversary behavior frameworks like MITRE ATT&CK and threat modeling.
  • Certifications such as AWS Security Specialty, Google Cloud Security Engineer, or Splunk Certified Architect.
  • Experience with SOAR platforms, threat hunting, and endpoint detection tools.
Note:

Candidates must be authorized to work in the US without sponsorship. The role offers a competitive salary range and comprehensive benefits. The position involves hybrid work with in-office presence expected three days a week.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Cloud Threat Detection
Security Engineer - Cloud Threat Detection

val's services • Charlotte (NC)

Hybrid
USD 120,000 - 150,000
Hybrid work arrangement
In-office three days/week
Sr. Security Engineer - Cloud Threat Detection
Sr. Security Engineer - Cloud Threat Detection

thehartford • Hartford (CT)

Hybrid
USD 120,000 - 180,000
Cloud Security Research & Threat Detection Engineer
Cloud Security Research & Threat Detection Engineer

Colossus Technologies Group • Sunnyvale (CA)

Hybrid
USD 200,000 - 240,000
Medical insurance
Dental insurance
Vision insurance
+5
Senior Cloud Threat Detection Engineer (AWS & GCP)
Senior Cloud Threat Detection Engineer (AWS & GCP)

val's services • Charlotte (NC)

Hybrid
USD 120,000 - 150,000
Hybrid work arrangement
In-office three days/week
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • New York (NY)

On-site
USD 237,000 - 297,000
Comprehensive health coverage
Equity options
Paid time off
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • San Francisco (CA)

On-site
USD 237,000 - 297,000
Health benefits
Retirement benefits
Learning and development stipend
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • Washington

On-site
USD 237,000 - 297,000
Comprehensive health, dental, vision coverage
Retirement benefits
Learning and development stipend
+2
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • Seattle (WA)

On-site
USD 237,000 - 297,000
Comprehensive health benefits
Retirement benefits
Learning and development stipend
+2
Lead Cloud Security Engineer - Boston/Cloud Security/AWS/Azure
Lead Cloud Security Engineer - Boston/Cloud Security/AWS/Azure

Motion Recruitment • Boston (MA)

On-site
USD 150,000 - 190,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
Detection Engineer Cloud
Detection Engineer Cloud

BreakPoint Labs • Charleston (SC)

On-site
USD 100,000 - 130,000