More jobs:
Sr. Security Engineer - Cloud Threat Detection
Job in
Hartford, Hartford County, Connecticut, 06132, USA
Listed on 2026-08-16
Listing for:
The Hartford
Part Time
position Listed on 2026-08-16
Job specializations:
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Security Management & Operations
Job Description & How to Apply Below
We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too. Join our team as we help shape the future.
The Hartford's Information Protection (THIP) organization is seeking a
** Sr. Security Engineer, Cloud Threat Detection Engineer
** to design and enhance enterprise-scale cloud threat detection capabilities across
** AWS and Google Cloud Platform (GCP)** . This role will develop high-fidelity detections, integrate cloud telemetry into
** Splunk (RBA)
** and the enterprise SIEM, and improve visibility into cloud-based threats. The ideal candidate has hands-on experience with
** AWS Guard Duty, AWS Cloud Trail, Google Security Command Center (SCC), Cloud Logging** , and other cloud-native security tools, partnering closely with Cloud Operations, Incident Response, Detection Engineering, and SOC teams to strengthen cloud security monitoring and response.
_This role will have a_ _Hybrid work schedule,_ _with the expectation of working in an office (Columbus, OH, Chicago, IL, Hartford, CT or Charlotte, NC) 3 days a week (Tuesday - Thursday)._
** Responsibilities*
* + Design, develop, test, and deploy detection content focused on AWS and GCP threats and suspicious activity.
+ Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
+ Develop detections leveraging data sources including:
+ AWS Guard Duty
+ AWS Cloud Trail
+ AWS VPC Flow Logs
+ AWS Config
+ Google Security Command Center (SCC)
+ Google Cloud Audit Logs
+ Google Cloud Logging
+ Identity and Access Management (IAM) telemetry
+ Other 3rd party CSMPs(Orca, Crowd Strike, Wiz)
+ Create and maintain SIEM detections, analytics, risk-based detections, dashboards, assets, identities, and alerting content.
+ Continuously tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.
+ Map detections to MITRE ATT&CK and cloud-specific attack techniques.
+ Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
+ Develop detection requirements and enrichment strategies to support AI/SOAR automation and incident response workflows.
+ Create and maintain Standard Operating Procedures (SOPs), runbooks, and investigation guides for cloud-based detections and alerts.
+ Train and mentor L1 and L2 SOC analysts on:
+ Cloud attack techniques and tactics
+ Use of cloud-native security tooling
+ Investigation workflows in the SIEM
+ Cloud Trail and GCP Audit Log analysis
+ Pivoting from SIEM alerts to AWS and GCP consoles for validation and triage
+ Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.
+ Participate in on-call support rotations (approximately 5 weeks annually).
** _Required Qualifications _*
* + 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
+ Hands-on operational experience securing both AWS and Google Cloud Platform (GCP) environments.
+ Strong knowledge of AWS security services and GCP security services.
+ Experience developing and tuning enterprise SIEM detections using cloud telemetry.
+ Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.
+ Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques.
+ Experience investigating alerts using raw cloud telemetry, including Cloud Trail and GCP Audit Logs.
+ Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.
+ Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.
+ Strong written and verbal communication skills.
** _Preferred Qualifications _*
* + Demonstrated experience with…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×