×
Register Here to Apply for Jobs or Post Jobs. X

Sr. Security Engineer - Cloud Threat Detection

Job in Hartford, Hartford County, Connecticut, 06132, USA
Listing for: The Hartford
Part Time position
Listed on 2026-08-16
Job specializations:
  • IT/Tech
    Cybersecurity, Cloud Computing: Infrastructure & Operations, Security Management & Operations
Job Description & How to Apply Below
Senior Security Engineer - IS07FE

We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too. Join our team as we help shape the future.

The Hartford's Information Protection (THIP) organization is seeking a  
** Sr. Security Engineer, Cloud Threat Detection Engineer
** to design and enhance enterprise-scale cloud threat detection capabilities across  
** AWS and Google Cloud Platform (GCP)** . This role will develop high-fidelity detections, integrate cloud telemetry into  
** Splunk (RBA)
** and the enterprise SIEM, and improve visibility into cloud-based threats. The ideal candidate has hands-on experience with  
** AWS Guard Duty, AWS Cloud Trail, Google Security Command Center (SCC), Cloud Logging** , and other cloud-native security tools, partnering closely with Cloud Operations, Incident Response, Detection Engineering, and SOC teams to strengthen cloud security monitoring and response.

_This role will have a_   _Hybrid work schedule,_   _with the expectation of working in an office (Columbus, OH, Chicago, IL, Hartford, CT or Charlotte, NC) 3 days a week (Tuesday - Thursday)._

** Responsibilities*
* + Design, develop, test, and deploy detection content focused on AWS and GCP threats and suspicious activity.

+ Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.

+ Develop detections leveraging data sources including:

+ AWS Guard Duty

+ AWS Cloud Trail

+ AWS VPC Flow Logs

+ AWS Config

+ Google Security Command Center (SCC)

+ Google Cloud Audit Logs

+ Google Cloud Logging

+ Identity and Access Management (IAM) telemetry

+ Other 3rd party CSMPs(Orca, Crowd Strike, Wiz)

+ Create and maintain SIEM detections, analytics, risk-based detections, dashboards, assets, identities, and alerting content.

+ Continuously tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.

+ Map detections to MITRE ATT&CK and cloud-specific attack techniques.

+ Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.

+ Develop detection requirements and enrichment strategies to support AI/SOAR automation and incident response workflows.

+ Create and maintain Standard Operating Procedures (SOPs), runbooks, and investigation guides for cloud-based detections and alerts.

+ Train and mentor L1 and L2 SOC analysts on:

+ Cloud attack techniques and tactics

+ Use of cloud-native security tooling

+ Investigation workflows in the SIEM

+ Cloud Trail and GCP Audit Log analysis

+ Pivoting from SIEM alerts to AWS and GCP consoles for validation and triage

+ Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.

+ Participate in on-call support rotations (approximately 5 weeks annually).

** _Required Qualifications _*
* + 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.

+ Hands-on operational experience securing both AWS and Google Cloud Platform (GCP) environments.

+ Strong knowledge of AWS security services and GCP security services.

+ Experience developing and tuning enterprise SIEM detections using cloud telemetry.

+ Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.

+ Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques.

+ Experience investigating alerts using raw cloud telemetry, including Cloud Trail and GCP Audit Logs.

+ Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.

+ Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.

+ Strong written and verbal communication skills.

** _Preferred Qualifications _*
* + Demonstrated experience with…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary