Jobs Companies The Hartford Sr. Security Engineer - Cloud Threat Detection

Sobre este puesto de Sr. Security Engineer - Cloud Threat Detection en The Hartford

The Hartford · Híbrido · Hartford, CT
Senior Security Engineer - IS07FE

We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.   

         

The Hartford's Information Protection (THIP) organization is seeking a Sr. Security Engineer, Cloud Threat Detection Engineer to design and enhance enterprise-scale cloud threat detection capabilities across AWS and Google Cloud Platform (GCP). This role will develop high-fidelity detections, integrate cloud telemetry into Splunk (RBA) and the enterprise SIEM, and improve visibility into cloud-based threats. The ideal candidate has hands-on experience with AWS GuardDuty, AWS CloudTrail, Google Security Command Center (SCC), Cloud Logging, and other cloud-native security tools, partnering closely with Cloud Operations, Incident Response, Detection Engineering, and SOC teams to strengthen cloud security monitoring and response.

This role will have a Hybrid work schedule, with the expectation of working in an office (Columbus, OH, Chicago, IL, Hartford, CT or Charlotte, NC) 3 days a week (Tuesday - Thursday). 

Responsibilities

  • Design, develop, test, and deploy detection content focused on AWS and GCP threats and suspicious activity. 
  • Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
  • Develop detections leveraging data sources including:
    • AWS GuardDuty
    • AWS CloudTrail
    • AWS VPC Flow Logs
    • AWS Config
    • Google Security Command Center (SCC)
    • Google Cloud Audit Logs
    • Google Cloud Logging
    • Identity and Access Management (IAM) telemetry
    • Other 3rd party CSMPs  (Orca, CrowdStrike, Wiz) 
  • Create and maintain SIEM detections, analytics, risk-based detections, dashboards, assets, identities, and alerting content.
  • Continuously tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.
  • Map detections to MITRE ATT&CK and cloud-specific attack techniques.
  • Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
  • Develop detection requirements and enrichment strategies to support AI/SOAR automation and incident response workflows.
  • Create and maintain Standard Operating Procedures (SOPs), runbooks, and investigation guides for cloud-based detections and alerts.
  • Train and mentor L1 and L2 SOC analysts on:
    • Cloud attack techniques and tactics
    • Use of cloud-native security tooling
    • Investigation workflows in the SIEM
    • CloudTrail and GCP Audit Log analysis
    • Pivoting from SIEM alerts to AWS and GCP consoles for validation and triage
  • Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.
  • Participate in on-call support rotations (approximately 5 weeks annually).

Required Qualifications

  • 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
  • Hands-on operational experience securing both AWS and Google Cloud Platform (GCP) environments.
  • Strong knowledge of AWS security services and GCP security services.
  • Experience developing and tuning enterprise SIEM detections using cloud telemetry.
  • Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.
  • Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques.
  • Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
  • Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.
  • Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.
  • Strong written and verbal communication skills.

Preferred Qualifications

  • Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, Risk-Based Alerting (RBA), dashboard creation, etc.
  • Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling.
  • Experience with SOAR platforms and security automation workflows.
  • Scripting and automation experience using Python, PowerShell, or Bash.
  • Experience supporting multi-cloud security programs.
  • Hands-on threat hunting experience in cloud environments.
  • Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint

Preferred Certifications

  • AWS Certified Security – Specialty
  • Google Professional Cloud Security Engineer
  • GIAC Cloud Threat Detection (GCTD)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Splunk Certified Architect or Consultant

Candidate must be authorized to work in the US without company sponsorship. The company will not support the STEM OPT I-983 Training Plan endorsement for this position.

Compensation

The listed annualized base pay range is primarily based on analysis of similar positions in the external market. Actual base pay could vary and may be above or below the listed range based on factors including but not limited to performance, proficiency and demonstration of competencies required for the role. The base pay is just one component of The Hartford’s total compensation package for employees. Other rewards may include short-term or annual bonuses, long-term incentives, and on-the-spot recognition. The annualized base pay range for this role is:

$128,400 - $192,600

Equal Opportunity Employer/Sex/Race/Color/Veterans/Disability/Sexual Orientation/Gender Identity or Expression/Religion/Age

About Us | Our Culture | What It’s Like to Work Here | Perks & Benefits

¿Listo para postularte en The Hartford?
Postúlate en The Hartford

Cómo se compara este salario de Security Engineer

Este puesto paga $160,500/yren línea con el rango típico para los puestos de Security Engineer.

$104,103 la mediana de $171,000 $256,270

Rango típico $135,000–$207,500/yr, a partir de 1,593 ofertas comparables de Security Engineer en JobsRadar (salario anualizado en USD). Ver datos salariales de Security Engineer →

Sobre The Hartford

Every day, a day to do right. Showing up for people isn’t just what we do. It’s who we are – and have been for more than 200 years. We’re devoted to finding innovative ways to serve our customers, communities and employees—continually asking ourselves what more we can do. Is our policy language as simple and inclusive as it can be? Can we better help businesses navigate our ever-changing world? What else can we do to destigmatize mental health in the workplace? Can we make our communities more equitable? That we can rise to the challenge of these questions is due in no small part to our company values that our employees have shaped and defined. And while how we contribute looks different for

Ver todos los empleos en The Hartford →

Empleos similares

The Hartford
Senior Security Engineer
The Hartford
⚡ Postúlate pronto Hartford, CT Híbrido $128,400–$192,600
● Nuevo 👁 Visto ✓ Postulado hace 5d
RTX
Principal Cybersecurity Software Engineer P4 (Onsite)
RTX
⚡ Postúlate pronto US-CT-EAST HARTFORD-OBF2 ~ 400... Híbrido
● Nuevo 👁 Visto ✓ Postulado hace 2sem
Dijital Team Pty Ltd
Senior Escalation Engineer - (Systems, Networking & Security)
Dijital Team Pty Ltd
⚡ Postúlate pronto Colombo · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 4h
CI
Principal, Security Engineer
Coupang Internal
⚡ Postúlate pronto Seattle, USA Presencial
● Nuevo 👁 Visto ✓ Postulado hace 6h
Coupang
Principal, Security Engineer
Coupang
⚡ Postúlate pronto Mountain View, USA; Seattle, U... Híbrido $209,000–$209,000
● Nuevo 👁 Visto ✓ Postulado hace 6h
GDIT
Cybersecurity Systems Engineer
GDIT
⚡ Postúlate pronto Any Location / Remote · restringido por ubicación $97,968–$126,500
● Nuevo 👁 Visto ✓ Postulado hace 7h
Centorrino Technologies
Senior Network Security Engineer
Centorrino Technologies
⚡ Postúlate pronto Melbourne, Victoria, Australia Presencial
● Nuevo 👁 Visto ✓ Postulado hace 7h
Abnormal
Software Engineer II - Behavioral Identity Security
Abnormal
⚡ Postúlate pronto Remote - Singapore · restringido por ubicación
● Nuevo 👁 Visto ✓ Postulado hace 7h
TT
Lead Senior Software Engineer - Platform Security
The Trade Desk
⚡ Postúlate pronto New York Presencial $124,900–$228,900
● Nuevo 👁 Visto ✓ Postulado hace 7h

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en The Hartford

Ver todos los empleos en The Hartford →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis