Senior Cloud Threat Detection Engineer

The Hartford

Hartford (CT)

Hybrid

USD 128,000 - 193,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Hartford is seeking a Sr. Security Engineer for Cloud Threat Detection to design and enhance enterprise-scale detections across AWS and GCP, integrating telemetry into Splunk and the SIEM and strengthening cloud security monitoring. The role collaborates with Cloud Operations, Incident Response, Detection Engineering, and SOC teams to improve threat visibility.

Hybrid schedule with in-office work 3 days a week (Tue-Thu) in Columbus, OH; Chicago, IL; Hartford, CT; or Charlotte, NC.

Qualifications

  • 5+ years of cybersecurity experience with security operations, incident response, threat detection, or detection engineering.
  • Hands-on experience securing AWS and Google Cloud Platform environments.
  • Strong knowledge of AWS and GCP security services.
  • Experience developing and tuning enterprise SIEM detections using cloud telemetry.
  • Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.
  • Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques.
  • Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
  • Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.
  • Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.
  • Strong written and verbal communication skills.

Responsibilities

  • Design, develop, test, and deploy detection content focused on AWS and GCP threats and suspicious activity.
  • Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
  • Develop detections leveraging data sources including AWS GuardDuty, AWS CloudTrail, AWS VPC Flow Logs, AWS Config, Google SCC, Google Cloud Audit Logs, Google Cloud Logging, IAM telemetry, and other 3rd party CSMPs.
  • Create and maintain SIEM detections, analytics, risk-based detections, dashboards, assets, identities, and alerting content.
  • Continuously tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.
  • Map detections to MITRE ATT&CK and cloud-specific attack techniques.
  • Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
  • Develop detection requirements and enrichment strategies to support AI/SOAR automation and incident response workflows.
  • Create and maintain SOPs, runbooks, and investigation guides for cloud-based detections and alerts.
  • Train and mentor L1/L2 SOC analysts on cloud threat investigation and triage processes.
  • Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.
  • Participate in on-call support rotations (approx. 5 weeks annually).

Skills

Cloud threat detection
Incident response
Threat detection engineering
SOC operations
Communication skills

Tools

Splunk Enterprise Security
QRadar
Cortex XSIAM
SOAR platforms
Scripting (Python/PowerShell/Bash)

Job description

The Hartford is seeking a Sr. Security Engineer for Cloud Threat Detection to design and enhance enterprise-scale detections across AWS and GCP, integrating telemetry into Splunk and the SIEM and strengthening cloud security monitoring. The role collaborates with Cloud Operations, Incident Response, Detection Engineering, and SOC teams to improve threat visibility.

Hybrid schedule with in-office work 3 days a week (Tue-Thu) in Columbus, OH; Chicago, IL; Hartford, CT; or Charlotte, NC.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Threat Detection Engineer
Senior Cloud Threat Detection Engineer

The Hartford • Charlotte (NC)

Hybrid
USD 128,000 - 193,000
Senior Cloud Threat Detection Engineer
Senior Cloud Threat Detection Engineer

The Hartford • Columbus (OH)

Hybrid
USD 128,000 - 193,000
Senior Cloud Threat Detection Engineer (Hybrid)
Senior Cloud Threat Detection Engineer (Hybrid)

thehartford • Hartford (CT)

Hybrid
USD 120,000 - 180,000
Sr. Security Engineer - Cloud Threat Detection
Sr. Security Engineer - Cloud Threat Detection

thehartford • Hartford (CT)

Hybrid
USD 120,000 - 180,000
Sr. Security Engineer - Cloud Threat Detection
Sr. Security Engineer - Cloud Threat Detection

The Hartford • Charlotte (NC)

Hybrid
USD 128,000 - 193,000
Sr. Security Engineer - Cloud Threat Detection
Sr. Security Engineer - Cloud Threat Detection

The Hartford • Hartford (CT)

Hybrid
USD 128,000 - 193,000
Sr. Security Engineer - Cloud Threat Detection
Sr. Security Engineer - Cloud Threat Detection

The Hartford • Columbus (OH)

Hybrid
USD 128,000 - 193,000
Senior Cloud Architect - Data & AI Platform Lead (Remote)
Senior Cloud Architect - Data & AI Platform Lead (Remote)

The Hartford • Columbus (OH)

Hybrid
USD 137,000 - 206,000
Senior Cloud Architect - Hybrid/Remote Data Platform Leader
Senior Cloud Architect - Hybrid/Remote Data Platform Leader

The Hartford • Chicago (IL)

Hybrid
USD 137,000 - 206,000
Senior Cloud Architect - Remote/Hybrid Data Platform
Senior Cloud Architect - Remote/Hybrid Data Platform

The Hartford • Hartford (CT)

Hybrid
USD 137,000 - 206,000