Sr. Security Engineer - Cloud Threat Detection

thehartford

Hartford (CT)

Hybrid

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Hartford is seeking a Senior Security Engineer to design and enhance enterprise cloud threat detection across AWS and Google Cloud, integrating telemetry into Splunk and other SIEMs. You will develop high‑fidelity detections, work with SOC teams, and strengthen cloud security monitoring and response. Hybrid role with in‑office days in designated U.S.

locations. Strong collaboration with Incident Response, Detection Engineering, and Cloud Operations is required to ensure rapid detection and

Qualifications

  • 5+ years in security operations, incident response, or threat detection.
  • Hands-on experience securing AWS and Google Cloud Platform environments.
  • Experience integrating cloud telemetry into SIEM platforms.

Responsibilities

  • Design, develop, test, and deploy cloud threat detection content for AWS and GCP.
  • Integrate cloud telemetry into enterprise SIEM and standardize detections.
  • Tune detection logic to reduce false positives and improve coverage.
  • Map detections to MITRE ATT&CK and cloud techniques.
  • Mentor SOC analysts on cloud threat investigation methods.

Skills

5+ years cybersecurity
Cloud security
Threat detection
Incident response
Documentation
Communication skills

Tools

Splunk Enterprise Security
Microsoft Sentinel
QRadar
Cortex XSIAM

Job description

Senior Security Engineer - IS07FE

We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too. Join our team as we help shape the future.

The Hartford's Information Protection (THIP) organization is seeking a Sr. Security Engineer, Cloud Threat Detection Engineer to design and enhance enterprise-scale cloud threat detection capabilities across AWS and Google Cloud Platform (GCP) . This role will develop high-fidelity detections, integrate cloud telemetry into Splunk (RBA) and the enterprise SIEM, and improve visibility into cloud-based threats. The ideal candidate has hands‑on experience with AWS GuardDuty, AWS CloudTrail, Google Security Command Center (SCC), Cloud Logging , and other cloud-native security tools, partnering closely with Cloud Operations, Incident Response, Detection Engineering, and SOC teams to strengthen cloud security monitoring and response.

This role will have a Hybrid work schedule, with the expectation of working in an office (Columbus, OH, Chicago, IL, Hartford, CT or Charlotte, NC) 3 days a week (Tuesday - Thursday).

Responsibilities
  • Design, develop, test, and deploy detection content focused on AWS and GCP threats and suspicious activity.
  • Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
  • Develop detections leveraging data sources including: AWS GuardDuty
  • AWS CloudTrail
  • AWS VPC Flow Logs
  • AWS Config
  • Google Security Command Center (SCC)
  • Google Cloud Audit Logs
  • Google Cloud Logging
  • Identity and Access Management (IAM) telemetry
  • Other 3 rd party CSMPs (Orca, CrowdStrike, Wiz)
  • Create and maintain SIEM detections, analytics, risk‑based detections, dashboards, assets, identities, and alerting content.
  • Continuously tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.
  • Map detections to MITRE ATT&CK and cloud-specific attack techniques.
  • Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
  • Develop detection requirements and enrichment strategies to support AI/SOAR automation and incident response workflows.
  • Create and maintain Standard Operating Procedures (SOPs), runbooks, and investigation guides for cloud-based detections and alerts.
  • Train and mentor L1 and L2 SOC analysts on: Cloud attack techniques and tactics
  • Use of cloud-native security tooling
  • Investigation workflows in the SIEM
  • CloudTrail and GCP Audit Log analysis
  • Pivoting from SIEM alerts to AWS and GCP consoles for validation and triage
  • Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.
  • Participate in on-call support rotations (approximately 5 weeks annually).
Required Qualifications
  • 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
  • Hands‑on operational experience securing both AWS and Google Cloud Platform (GCP) environments.
  • Strong knowledge of AWS security services and GCP security services.
  • Experience developing and tuning enterprise SIEM detections using cloud telemetry.
  • Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.
  • Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques.
  • Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
  • Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.
  • Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.
  • Strong written and verbal communication skills.
Preferred Qualifications
  • Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, Risk‑Based Alerting (RBA), dashboard creation, etc.
  • Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling.
  • Experience with SOAR platforms and security automation workflows.
  • Scripting and automation experience using Python, PowerShell, or Bash.
  • Experience supporting multi-cloud security programs.
  • Hands‑on threat hunting experience in cloud environments.
  • Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint
Preferred Certifications
  • AWS Certified Security - Specialty
  • Google Professional Cloud Security Engineer
  • GIAC Cloud Threat Detection (GCTD)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Splunk Certified Architect or Consultant

Candidate must be authorized to work in the US without company sponsorship. The company will not support the STEM OPT I

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Engineer - Cloud Threat Detection
Sr. Security Engineer - Cloud Threat Detection

The Hartford • Hartford (CT)

Hybrid
USD 128,000 - 193,000
Sr. Security Engineer - Cloud Threat Detection
Sr. Security Engineer - Cloud Threat Detection

The Hartford • Charlotte (NC)

Hybrid
USD 128,000 - 193,000
Sr. Security Engineer - Cloud Threat Detection
Sr. Security Engineer - Cloud Threat Detection

The Hartford • Columbus (OH)

Hybrid
USD 128,000 - 193,000
Senior Cloud Threat Detection Engineer
Senior Cloud Threat Detection Engineer

The Hartford • Charlotte (NC)

Hybrid
USD 128,000 - 193,000
Senior Cloud Threat Detection Engineer
Senior Cloud Threat Detection Engineer

The Hartford • Hartford (CT)

Hybrid
USD 128,000 - 193,000
Senior Cloud Threat Detection Engineer
Senior Cloud Threat Detection Engineer

The Hartford • Columbus (OH)

Hybrid
USD 128,000 - 193,000
Senior Cloud Threat Detection Engineer (Hybrid)
Senior Cloud Threat Detection Engineer (Hybrid)

thehartford • Hartford (CT)

Hybrid
USD 120,000 - 180,000
Principal Security Operations Engineer
Principal Security Operations Engineer

Digital Turbine Media, Inc. • Austin (TX)

Hybrid
USD 130,000 - 180,000
Bonus plan
Equity plan
401(k)
+1
Lead Cloud Security Engineer - Boston/Cloud Security/AWS/Azure
Lead Cloud Security Engineer - Boston/Cloud Security/AWS/Azure

Motion Recruitment • Boston (MA)

On-site
USD 150,000 - 190,000
Medical Insurance
Dental Benefits
Vision Benefits
+2
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

roguefitness • United States

On-site
USD 140,000 - 170,000