Sr. Security Engineer - Cloud Threat Detection
$128,400–$192,600 year
HybridCharlotte, North Carolina, United States or Hartford, Connecticut, United States
Job Summary
Design and deploy high-fidelity cloud threat detections for AWS and Google Cloud Platform, integrating telemetry into the enterprise SIEM to improve visibility. Develop analytics, dashboards, and risk-based alerts while continuously tuning logic to reduce false positives and map findings to MITRE ATT&CK. Participate in adversary emulation and purple team exercises to validate effectiveness, then create SOPs and runbooks for SOC analysts. Provide advanced escalation support during investigations and mentor L1/L2 analysts on cloud attack techniques and tooling usage. This role includes a hybrid schedule with three days in the office (Columbus, OH, Chicago, IL, Hartford, CT, or Charlotte, NC) and an annual on-call rotation of approximately five weeks.
Required Qualifications
- 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering
- Hands-on operational experience securing both AWS and Google Cloud Platform (GCP) environments
- Strong knowledge of AWS security services and GCP security services
- Experience developing and tuning enterprise SIEM detections using cloud telemetry
- Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.
- Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques
- Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs
- Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks
- Experience training and mentoring SOC analysts on cloud threat investigation and triage processes
- Strong written and verbal communication skills
- Hybrid work schedule, with the expectation of working in an office (Columbus, OH, Chicago, IL, Hartford, CT or Charlotte, NC) 3 days a week (Tuesday - Thursday)
- Candidate must be authorized to work in the US without company sponsorship
Desired Qualifications
- Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, Risk-Based Alerting (RBA), dashboard creation, etc.
- Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling
- Experience with SOAR platforms and security automation workflows
- Scripting and automation experience using Python, PowerShell, or Bash
- Experience supporting multi-cloud security programs
- Hands-on threat hunting experience in cloud environments
- Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint
- AWS Certified Security – Specialty
- Google Professional Cloud Security Engineer
- GIAC Cloud Threat Detection (GCTD)
- GIAC Certified Incident Handler (GCIH)
- GIAC Cyber Threat Intelligence (GCTI)
- Splunk Certified Architect or Consultant
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.