Sr. Security Engineer - Cloud Threat Detection
Indexed description
We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.
The Hartford's Information Protection (THIP) organization is seeking a Sr. Security Engineer, Cloud Threat Detection Engineer to design and enhance enterprise-scale cloud threat detection capabilities across AWS and Google Cloud Platform (GCP). This role will develop high-fidelity detections, integrate cloud telemetry into Splunk (RBA) and the enterprise SIEM, and improve visibility into cloud-based threats. The ideal candidate has hands-on experience with AWS GuardDuty, AWS CloudTrail, Google Security Command Center (SCC), Cloud Logging, and other cloud-native security tools, partnering closely with Cloud Operations, Incident Response, Detection Engineering, and SOC teams to strengthen cloud security monitoring and response.
This role will have a Hybrid work schedule, with the expectation of working in an office (Columbus, OH, Chicago, IL, Hartford, CT or Charlotte, NC) 3 days a week (Tuesday - Thursday).
Responsibilities
- Design, develop, test, and deploy detection content focused on AWS and GCP threats and suspicious activity.
- Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
- Develop detections leveraging data sources including:
- AWS GuardDuty
- AWS CloudTrail
- AWS VPC Flow Logs
- AWS Config
- Google Security Command Center (SCC)
- Google Cloud Audit Logs
- Google Cloud Logging
- Identity and Access Management (IAM) telemetry
- Other 3rd party CSMPs (Orca, CrowdStrike, Wiz)
- Create and maintain SIEM detections, analytics, risk-based detections, dashboards, assets, identities, and alerting content.
- Continuously tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.
- Map detections to MITRE ATT&CK and cloud-specific attack techniques.
- Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
- Develop detection requirements and enrichment strategies to support AI/SOAR automation and incident response workflows.
- Create and maintain Standard Operating Procedures (SOPs), runbooks, and investigation guides for cloud-based detections and alerts.
- Train and mentor L1 and L2 SOC analysts on:
- Cloud attack techniques and tactics
- Use of cloud-native security tooling
- Investigation workflows in the SIEM
- CloudTrail and GCP Audit Log analysis
- Pivoting from SIEM alerts to AWS and GCP consoles for validation and triage
- Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.
- Participate in on-call support rotations (approximately 5 weeks annually).
- 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
- Hands-on operational experience securing both AWS and Google Cloud Platform (GCP) environments.
- Strong knowledge of AWS security services and GCP security services.
- Experience developing and tuning enterprise SIEM detections using cloud telemetry.
- Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.
- Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques.
- Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
- Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.
- Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.
- Strong written and verbal communication skills.
- Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, Risk-Based Alerting (RBA), dashboard creation, etc.
- Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling.
- Experience with SOAR platforms and security automation workflows.
- Scripting and automation experience using Python, PowerShell, or Bash.
- Experience supporting multi-cloud security programs.
- Hands-on threat hunting experience in cloud environments.
- Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint
- AWS Certified Security – Specialty
- Google Professional Cloud Security Engineer
- GIAC Cloud Threat Detection (GCTD)
- GIAC Certified Incident Handler (GCIH)
- GIAC Cyber Threat Intelligence (GCTI)
- Splunk Certified Architect or Consultant
$128,400 - $192,600
Equal Opportunity Employer/Sex/Race/Color/Veterans/Disability/Sexual Orientation/Gender Identity or Expression/Religion/Age
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search