The Hartford is hiring a Sr. Security Engineer focused on Cloud Threat Detection, partnering with teams across cloud security to strengthen enterprise visibility across AWS and Google Cloud Platform (GCP). The role designs high-fidelity detections, brings cloud telemetry into the enterprise SIEM, and helps reduce false positives through continuous tuning.
Based in Hartford, CT with a hybrid schedule, you can expect in-office collaboration 3 days per week (Tuesday through Thursday).
What youβll do
- Design, develop, test, and deploy detection content for AWS and GCP threats and suspicious activity.
- Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
- Build detections using data sources including AWS GuardDuty, AWS CloudTrail, AWS VPC Flow Logs, AWS Config, Google Security Command Center (SCC), Google Cloud Audit Logs, Google Cloud Logging, IAM telemetry, and third-party CSMPs such as Orca, CrowdStrike, and Wiz.
- Create and maintain SIEM detections, analytics, risk-based detections, dashboards, assets, identities, and alerting content.
- Continuously tune and optimize detection logic to improve detection fidelity and coverage while reducing false positives.
- Map detections to MITRE ATT&CK and cloud-specific attack techniques.
- Validate detection effectiveness through adversary emulation, purple team exercises, and cloud attack simulations.
- Develop detection requirements and enrichment strategies that support AI/SOAR automation and incident response workflows.
- Create and maintain SOPs, runbooks, and investigation guides for cloud-based detections and alerts.
- Train and mentor L1 and L2 SOC analysts on cloud attack tactics and investigation workflows in the SIEM, including pivoting from alerts to AWS and GCP consoles for validation and triage.
- Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.
- Participate in on-call support rotations (approximately 5 weeks annually).
What you bring
- 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
- Hands-on operational experience securing AWS and GCP environments.
- Strong knowledge of AWS security services and GCP security services.
- Experience developing and tuning enterprise SIEM detections using cloud telemetry.
- Experience integrating cloud-native security tools and log sources into enterprise monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, and Cortex XSIAM.
- Strong understanding of cloud attack methodologies, including identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration.
- Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
- Ability to create operational documentation such as investigation guides, SOPs, and analyst playbooks.
- Experience training and mentoring SOC analysts on cloud threat investigation and triage.
- Strong written and verbal communication skills.
- Authorization to work in the US without company sponsorship (the company will not support the STEM OPT I-983 Training Plan endorsement for this position).
Compensation
The listed annualized base pay range is USD 128,400 - 192,600.
Technologies youβll work with
AWS, GCP, AWS GuardDuty, AWS CloudTrail, Splunk (RBA), Splunk Enterprise Security, Google Security Command Center (SCC), Google Cloud Logging, AWS VPC Flow Logs, AWS Config, Google Cloud Audit Logs, IAM, Microsoft Sentinel, QRadar, Cortex XSIAM, Orca, CrowdStrike, Wiz, MITRE ATT&CK, SOPs, AI/SOAR, Python, PowerShell, Bash, plus GIAC certifications and Splunk Certified Architect or Consultant.
Preferred qualifications
- Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, and Risk-Based Alerting (RBA), including dashboard creation.
- Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling.
- Experience with SOAR platforms and security automation workflows.
- Scripting and automation experience using Python, PowerShell, or Bash.
- Experience supporting multi-cloud security programs.
- Hands-on threat hunting in cloud environments.
- Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint.
Preferred certifications
- AWS Certified Security β Specialty
- Google Professional Cloud Security Engineer
- GIAC Cloud Threat Detection (GCTD)
- GIAC Certified Incident Handler (GCIH)
- GIAC Cyber Threat Intelligence (GCTI)
- Splunk Certified Architect or Consultant