Senior Cloud Security Engineer

Chubb

Philadelphia (Philadelphia County)

On-site

USD 140,000 - 190,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Chubb Global Information Security is seeking a hands-on Senior Cloud Security Engineer to detect, respond to, and harden our multi-cloud environment (Azure, AWS, GCP, and Microsoft 365). You will build detections, respond to incidents, and reduce attack surface through automation.

Ideal candidates have strong incident response fundamentals, apply them to cloud and SaaS, and can deliver detection content and automation rather than just consume it.

Qualifications

  • 7+ years IT Security experience, with 3+ years hands-on in Azure and/or AWS security.
  • Strong incident response background.
  • Experience writing or tuning detection logic (KQL, Sigma, or equivalent) in a SIEM (Microsoft Sentinel preferred)
  • Proficient with core security tooling: SIEM, EDR, cloud-native logging/posture tools (Defender for Cloud, GuardDuty, etc.)
  • Comfortable using AI coding/analysis tools (Claude Code or similar) and automation workflows to streamline operations and accelerate investigations.
  • Scripting ability (PowerShell and/or Python) for automation and tooling
  • Strong time management and organizational skills
  • Excellent communication skills, both verbal and written
  • Solid problem-solving and decision-making skills
  • Ability to be on-call or available after hours for emergencies

Responsibilities

  • Detect, respond to, and remediate cyber threats across Azure, AWS, GCP, and Microsoft 365
  • Build and tune detection content (KQL analytics rules, Sigma rules, Sentinel workbooks) to close coverage gaps as new threats and cloud services emerge
  • Lead and support incident response engagements end-to-end — triage, containment, eradication, and after-action reporting
  • Harden cloud and SaaS environments against known attack techniques in partnership with infrastructure, IAM, and application teams
  • Create workflows and automations (logic apps, scripts, or AI-assisted tooling) to solve recurring security challenges and speed up triage/response
  • Investigate anomalous activity using SIEM, EDR, and native cloud logging; drive tuning to reduce false positives without losing coverage
  • Prepare operational reporting and after-action reports for business and IT Security management
  • Stay current on emerging cloud attack techniques and translate them into new detections or hardening controls before they're needed

Skills

Incident response
Cloud security
Threat detection
KQL/Sigma
PowerShell
Python
Automation
SIEM/EDR

Tools

Microsoft Sentinel
Defender for Cloud
GuardDuty
Cloud logging tools
SIEM tooling

Job description

Job Description

Chubb Global Information Security is looking for a hands‑on security engineer to detect, respond to, and harden against cyber threats across our multi‑cloud environment (Azure primary, AWS and GCP, and Microsoft 365). As a Senior Cloud Security Engineer, you will build and tune detections, respond to incidents, and close down attack paths before they\'re exploited. The ideal candidate has strong traditional incident response fundamentals, applies them to cloud and SaaS environments, and can build detection content and automation rather than just consume it. IAM architecture and posture program ownership sit with a dedicated team — this role is about detecting, responding, and hardening, not designing access models. This role requires practical experience securing and responding to incidents in large, global, regulated enterprise environments, and comfort using modern AI tooling (Claude/Claude Code or similar) as part of daily engineering work.


Job Description

Chubb Global Information Security is looking for a hands‑on security engineer to detect, respond to, and harden against cyber threats across our multi‑cloud environment (Azure primary, AWS and GCP, and Microsoft 365). As a Senior Cloud Security Engineer, you will build and tune detections, respond to incidents, and close down attack paths before they\'re exploited. The ideal candidate has strong traditional incident response fundamentals, applies them to cloud and SaaS environments, and can build detection content and automation rather than just consume it. IAM architecture and posture program ownership sit with a dedicated team — this role is about detecting, responding, and hardening, not designing access models. This role requires practical experience securing and responding to incidents in large, global, regulated enterprise environments, and comfort using modern AI tooling (Claude/Claude Code or similar) as part of daily engineering work.


Responsibilities


  • Detect, respond to, and remediate cyber threats across Azure, AWS, GCP, and Microsoft 365

  • Build and tune detection content (KQL analytics rules, Sigma rules, Sentinel workbooks) to close coverage gaps as new threats and cloud services emerge

  • Lead and support incident response engagements end-to-end — triage, containment, eradication, and after‑action reporting

  • Harden cloud and SaaS environments against known attack techniques (identity abuse, misconfiguration, lateral movement, persistence) in partnership with infrastructure, IAM, and application teams

  • Create workflows and automations (logic apps, scripts, or AI‑assisted tooling) to solve recurring security challenges and speed up triage/response

  • Investigate anomalous activity using SIEM, EDR, and native cloud logging; drive tuning to reduce false positives without losing coverage

  • Prepare operational reporting and after‑action reports for business and IT Security management

  • Stay current on emerging cloud attack techniques and translate them into new detections or hardening controls before they\'re needed


Qualifications

Required Qualifications:



  • 7+ years IT Security experience, with 3+ years hands‑on in Azure and/or AWS security

  • Strong, demonstrable incident response background.

  • Experience writing or tuning detection logic (KQL, Sigma, or equivalent) in a SIEM (Microsoft Sentinel preferred)

  • Proficient with core security tooling: SIEM, EDR, cloud‑native logging/posture tools (Defender for Cloud, GuardDuty, etc.)

  • Comfortable using AI coding/analysis tools (Claude Code or similar) and automation workflows to streamline operations and accelerate investigations.

  • Scripting ability (PowerShell and/or Python) for automation and tooling

  • Strong time management and organizational skills

  • Excellent communication skills, both verbal and written

  • Solid problem‑solving and decision‑making skills

  • Ability to be on‑call or available after hours for emergencies


Preferred Qualifications


  • Working knowledge of Microsoft 365 security (Entra ID, Defender products) and exposure to GCP

  • Security certifications such as GCIH, GCFA, CCSP, CISSP, OSCP

  • Microsoft certifications, including Azure Security

  • Experience building or maintaining internal security automation/tooling


About Us

Chubb is a world leader in insurance. With operations in 54 countries, Chubb provides commercial and personal property and casualty insurance, personal accident and supplemental health insurance, reinsurance, and life insurance to a diverse group of clients. The company is distinguished by its extensive product and service offerings, broad distribution capabilities, exceptional financial strength, underwriting excellence, superior claims handling expertise and local operations globally.


At Chubb, we are committed to equal employment opportunity and compliance with all laws and regulations pertaining to it. Our policy is to provide employment, training, compensation, promotion, and other conditions or opportunities of employment, without regard to race, color, religious creed, sex, gender, gender identity, gender expression, sexual orientation, marital status, national origin, ancestry, mental and physical disability, medical condition, genetic information, military and veteran status, age, and pregnancy or any other characteristic protected by law. Performance and qualifications are the only basis upon which we hire, assign, promote, compensate, develop and retain employees. Chubb prohibits all unlawful discrimination, harassment and retaliation against any individual who reports discrimination or harassment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Koitecc Solutions • Philadelphia, Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Socket.dev • Philadelphia

On-site
USD 140,000 - 170,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Chubb Insurance Hong Kong • Philadelphia

On-site
USD 130,000 - 165,000
Sr. Technical Security Lead, North America
Sr. Technical Security Lead, North America

Koitecc Solutions • Philadelphia

On-site
USD 140,000 - 190,000
Senior Cloud Security Engineer - Multi-Cloud IR & Detection
Senior Cloud Security Engineer - Multi-Cloud IR & Detection

Chubb • Philadelphia

On-site
USD 140,000 - 190,000
Sr. Technical Security Lead, North America
Sr. Technical Security Lead, North America

Chubb • Philadelphia

On-site
USD 140,000 - 190,000
Senior Application Penetration Tester
Senior Application Penetration Tester

Chubb in • Philadelphia

On-site
USD 120,000 - 180,000
Senior Cloud Security Engineer: Detect & Harden Clouds
Senior Cloud Security Engineer: Detect & Harden Clouds

Koitecc Solutions • Philadelphia, Northern (KY)

Hybrid
USD 140,000 - 190,000
Hands-On Cloud Security Engineer - Detect, Respond, Harden
Hands-On Cloud Security Engineer - Detect, Respond, Harden

Socket.dev • Philadelphia

On-site
USD 140,000 - 170,000
Senior Cloud Security Engineer: Multi-Cloud IR & Detection
Senior Cloud Security Engineer: Multi-Cloud IR & Detection

Chubb Insurance Hong Kong • Philadelphia

On-site
USD 130,000 - 165,000