EngineerJobs.io
← Back to all jobs

Job Description

The Hartford is seeking a Sr. Security Engineer focused on cloud threat detection. In this role, you will design and enhance enterprise-scale detection capabilities across AWS and Google Cloud Platform (GCP), integrating cloud telemetry into the organization’s SIEM for improved visibility and response to cloud threats. This position supports hybrid work in Charlotte, NC.

Key Responsibilities

  • Design, develop, test, and deploy detection content for AWS and GCP threats and suspicious activity.
  • Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
  • Create SIEM detections, analytics, risk-based detections, dashboards, assets, identities, and alerting content.
  • Develop detections using sources including AWS GuardDuty, AWS CloudTrail, AWS VPC Flow Logs, and AWS Config.
  • Develop detections using sources including Google Security Command Center (SCC), Google Cloud Audit Logs, Google Cloud Logging, and Identity and Access Management (IAM) telemetry.
  • Incorporate detections leveraging Other 3rd party CSMPs such as Orca, CrowdStrike, and Wiz.
  • Continuously tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.
  • Map detections to MITRE ATT&CK and cloud-specific attack techniques.
  • Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
  • Develop detection requirements and enrichment strategies to support AI/SOAR automation and incident response workflows.
  • Create and maintain Standard Operating Procedures (SOPs), runbooks, and investigation guides for cloud-based detections and alerts.
  • Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.
  • Train and mentor L1 and L2 SOC analysts on cloud attack tactics and techniques, cloud-native security tooling, SIEM investigation workflows, and how to pivot from SIEM alerts to AWS and GCP consoles for validation and triage.
  • Conduct analysis training for CloudTrail and GCP Audit Log investigations.
  • Participate in on-call support rotations (approximately 5 weeks annually).

Required Qualifications

  • 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
  • Hands-on operational experience securing both AWS and GCP environments.
  • Strong knowledge of AWS security services and GCP security services.
  • Experience developing and tuning enterprise SIEM detections using cloud telemetry.
  • Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, and Cortex XSIAM.
  • Strong understanding of cloud attack methodologies, including identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration.
  • Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
  • Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.
  • Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.
  • Strong written and verbal communication skills.

Technology Stack

  • AWS, Google Cloud Platform (GCP)
  • AWS GuardDuty, AWS CloudTrail, AWS VPC Flow Logs, AWS Config
  • Google Security Command Center (SCC), Google Cloud Audit Logs, Google Cloud Logging
  • Identity and Access Management (IAM)
  • Splunk (RBA), Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM
  • MITRE ATT&CK, AI/SOAR
  • Python, PowerShell, Bash
  • CrowdStrike, Wiz, Orca; EDR platforms including SentinelOne and Microsoft Defender XDR for Endpoint

Hybrid Work Schedule

  • Hybrid with an expectation of working from an office 3 days per week (Tuesday through Thursday).
  • Office locations include Columbus, OH, Chicago, IL, Hartford, CT, or Charlotte, NC.

Preferred Qualifications

  • Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, Risk-Based Alerting (RBA), and dashboard creation.
  • Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling.
  • Experience with SOAR platforms and security automation workflows.
  • Scripting and automation experience using Python, PowerShell, or Bash.
  • Experience supporting multi-cloud security programs.
  • Hands-on threat hunting experience in cloud environments.
  • Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint.

Preferred Certifications

  • AWS Certified Security – Specialty
  • Google Professional Cloud Security Engineer
  • GIAC Cloud Threat Detection (GCTD)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Splunk Certified Architect or Consultant

Compensation

The listed annualized base pay range is USD 128,400 - 192,600.

Work Authorization

The candidate must be authorized to work in the US without company sponsorship. The company will not support the STEM OPT I-983 Training Plan endorsement for this position.

Similar Jobs