CybersecurityJobs.io
← Back to all jobs

Job Description

The Hartford is looking for a Sr. Security Engineer for Cloud Threat Detection to help design and evolve enterprise-scale detection capabilities across AWS and Google Cloud Platform (GCP). In this hybrid role based in Charlotte, NC, you will build high-fidelity detection content, connect cloud telemetry into the enterprise SIEM, and partner with security teams to improve visibility and response to cloud-based threats.

You will work across AWS and GCP data sources, translate suspicious activity into actionable detections, and support the SOC with runbooks, investigation guidance, and escalation during cloud security investigations.

Responsibilities

  • Design, develop, test, and deploy cloud threat detections and analytics for AWS and GCP suspicious activity.
  • Integrate and normalize AWS and GCP cloud security telemetry into the enterprise SIEM.
  • Create and maintain SIEM detections, analytics, risk-based detections, dashboards, assets and identities, and alerting content.
  • Tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.
  • Map detections to MITRE ATT&CK and cloud-specific attack techniques.
  • Develop detections using cloud telemetry sources including:
    • AWS GuardDuty
    • AWS CloudTrail
    • AWS VPC Flow Logs
    • AWS Config
    • Google Security Command Center (SCC)
    • Google Cloud Audit Logs
    • Google Cloud Logging
    • Identity and Access Management (IAM) telemetry
    • Other 3rd party CSMPs including Orca, CrowdStrike, and Wiz
  • Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
  • Develop detection requirements and enrichment strategies that support AI/SOAR automation and incident response workflows.
  • Create and maintain Standard Operating Procedures (SOPs), runbooks, and investigation guides for cloud detections and alerts.
  • Train and mentor L1 and L2 SOC analysts on cloud attack techniques and tactics.
  • Train and mentor L1 and L2 SOC analysts on using cloud-native security tooling.
  • Train and mentor L1 and L2 SOC analysts on SIEM investigation workflows.
  • Train and mentor L1 and L2 SOC analysts on CloudTrail and GCP Audit Log analysis.
  • Train and mentor L1 and L2 SOC analysts on pivoting from SIEM alerts to the AWS and GCP consoles for validation and triage.
  • Provide advanced escalation support to SOC and Incident Response teams during cloud security investigations.
  • Participate in on-call support rotations (approximately 5 weeks annually).

Requirements

  • 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
  • Hands-on operational experience securing both AWS and GCP environments.
  • Strong knowledge of AWS security services and GCP security services.
  • Experience developing and tuning enterprise SIEM detections using cloud telemetry.
  • Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, and Cortex XSIAM.
  • Strong understanding of cloud attack methodologies including identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques.
  • Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
  • Ability to create operational documentation such as investigation guides, SOPs, and analyst playbooks.
  • Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.
  • Strong written and verbal communication skills.

Technologies

  • AWS, Google Cloud Platform (GCP)
  • AWS GuardDuty, AWS CloudTrail, AWS VPC Flow Logs, AWS Config
  • Google Security Command Center (SCC), Google Cloud Audit Logs, Google Cloud Logging
  • Identity and Access Management (IAM)
  • Splunk (RBA), Splunk Enterprise Security
  • Microsoft Sentinel, QRadar, Cortex XSIAM
  • MITRE ATT&CK, AI/SOAR
  • Python, PowerShell, Bash
  • CrowdStrike, Wiz, Orca
  • EDR platforms including SentinelOne, Microsoft Defender XDR for Endpoint

Hybrid Work Schedule

  • Hybrid schedule with expectation of working in an office 3 days per week (Tuesday to Thursday).
  • Office locations include Columbus, OH, Chicago, IL, Hartford, CT, or Charlotte, NC.

Preferred Qualifications

  • Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, and Risk-Based Alerting (RBA), including dashboard creation.
  • Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling.
  • Experience with SOAR platforms and security automation workflows.
  • Scripting and automation experience using Python, PowerShell, or Bash.
  • Experience supporting multi-cloud security programs.
  • Hands-on threat hunting experience in cloud environments.
  • Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint.

Preferred Certifications

  • AWS Certified Security – Specialty
  • Google Professional Cloud Security Engineer
  • GIAC Cloud Threat Detection (GCTD)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Splunk Certified Architect or Consultant

Compensation

  • Annualized base pay range: USD 128,400 - 192,600

Authorization to Work: The company will not support the STEM OPT I-983 Training Plan endorsement for this position. Candidate must be authorized to work in the US without company sponsorship.

Similar Jobs