Sr. Security Engineer - Cloud Threat Detection
Job Description
The Hartford is looking for a Senior Security Engineer to build and improve enterprise-scale cloud threat detection across AWS and Google Cloud Platform (GCP). In this hybrid role, you will design high-fidelity detections, connect cloud security telemetry to the enterprise SIEM, and help the SOC reduce false positives while strengthening visibility into cloud-based threats.
What you’ll do
- Design, develop, test, and deploy detection content for suspicious activity and threats across AWS and GCP.
- Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
- Build detections using sources including AWS GuardDuty, AWS CloudTrail, AWS VPC Flow Logs, AWS Config, Google Security Command Center (SCC), Google Cloud Audit Logs, Google Cloud Logging, IAM telemetry, and other 3rd-party CSMPs (Orca, CrowdStrike, Wiz).
- Create and maintain SIEM detections and related content such as analytics, risk-based detections, dashboards, assets, identities, and alerting logic.
- Tune and optimize detection logic over time to improve detection fidelity and coverage while reducing false positives.
- Map detections to MITRE ATT&CK and relevant cloud-specific attack techniques.
- Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
- Develop detection requirements and enrichment strategies that support AI/SOAR automation and incident response workflows.
- Create and maintain SOPs, runbooks, and investigation guides for cloud-based detections and alerts.
- Train and mentor L1 and L2 SOC analysts on cloud threat tactics and investigation workflows, including CloudTrail and GCP Audit Log analysis and triage steps using AWS and GCP consoles.
- Provide advanced escalation support to SOC and Incident Response teams during cloud security investigations.
- Join on-call support rotations (approximately 5 weeks annually).
Required qualifications
- 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
- Hands-on operational experience securing both AWS and GCP environments.
- Strong knowledge of AWS security services and GCP security services.
- Experience developing and tuning enterprise SIEM detections using cloud telemetry.
- Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, and others.
- Strong understanding of cloud attack methodologies including identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration.
- Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
- Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.
- Experience training and mentoring SOC analysts on cloud threat investigation and triage.
- Strong written and verbal communication skills.
Location and schedule
- Hartford, CT (hybrid)
- Office expectation: 3 days a week (Tuesday to Thursday) in Columbus, OH, Chicago, IL, Hartford, CT, or Charlotte, NC.
Compensation
Base pay range: USD 128,400 - 192,600 per year.
Technologies you may work with
AWS, GCP, AWS GuardDuty, AWS CloudTrail, Splunk (RBA), Splunk Enterprise Security, Google Security Command Center (SCC), Google Cloud Logging, AWS VPC Flow Logs, AWS Config, Google Cloud Audit Logs, IAM, Microsoft Sentinel, QRadar, Cortex XSIAM, Orca, CrowdStrike, Wiz, MITRE ATT&CK, SOPs, AI/SOAR, Python, PowerShell, Bash.
Preferred qualifications
- Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, Risk-Based Alerting (RBA), and dashboard creation.
- Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling.
- Experience with SOAR platforms and security automation workflows.
- Scripting and automation experience using Python, PowerShell, or Bash.
- Experience supporting multi-cloud security programs.
- Hands-on threat hunting in cloud environments.
- Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint.
Preferred certifications
- AWS Certified Security – Specialty
- Google Professional Cloud Security Engineer
- GIAC Cloud Threat Detection (GCTD)
- GIAC Certified Incident Handler (GCIH)
- GIAC Cyber Threat Intelligence (GCTI)
- Splunk Certified Architect or Consultant
Work authorization: Candidate must be authorized to work in the US without company sponsorship. The company will not support the STEM OPT I-983 Training Plan endorsement for this position.