The Hartford logo
The HartfordPosted 2 weeks ago

Sr. Security Engineer - Cloud Threat Detection

$128,400–$192,600 year

HybridCharlotte, North Carolina, United States or Hartford, Connecticut, United States

Full TimeSenior LevelEnterprise

Job Summary

Design and deploy high-fidelity cloud threat detections for AWS and Google Cloud Platform, integrating telemetry into the enterprise SIEM to improve visibility. Develop analytics, dashboards, and risk-based alerts while continuously tuning logic to reduce false positives and map findings to MITRE ATT&CK. Participate in adversary emulation and purple team exercises to validate effectiveness, then create SOPs and runbooks for SOC analysts. Provide advanced escalation support during investigations and mentor L1/L2 analysts on cloud attack techniques and tooling usage. This role includes a hybrid schedule with three days in the office (Columbus, OH, Chicago, IL, Hartford, CT, or Charlotte, NC) and an annual on-call rotation of approximately five weeks.

Required Qualifications

  • 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering
  • Hands-on operational experience securing both AWS and Google Cloud Platform (GCP) environments
  • Strong knowledge of AWS security services and GCP security services
  • Experience developing and tuning enterprise SIEM detections using cloud telemetry
  • Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.
  • Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques
  • Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs
  • Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks
  • Experience training and mentoring SOC analysts on cloud threat investigation and triage processes
  • Strong written and verbal communication skills
  • Hybrid work schedule, with the expectation of working in an office (Columbus, OH, Chicago, IL, Hartford, CT or Charlotte, NC) 3 days a week (Tuesday - Thursday)
  • Candidate must be authorized to work in the US without company sponsorship

Desired Qualifications

  • Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, Risk-Based Alerting (RBA), dashboard creation, etc.
  • Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling
  • Experience with SOAR platforms and security automation workflows
  • Scripting and automation experience using Python, PowerShell, or Bash
  • Experience supporting multi-cloud security programs
  • Hands-on threat hunting experience in cloud environments
  • Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint
  • AWS Certified Security – Specialty
  • Google Professional Cloud Security Engineer
  • GIAC Cloud Threat Detection (GCTD)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Splunk Certified Architect or Consultant

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce