The Hartford Financial Services Group, Inc. Logo

The Hartford Financial Services Group, Inc.

Sr. Security Engineer - Cloud Threat Detection

Posted One Month Ago
Be an Early Applicant
In-Office
Charlotte, NC, USA
128K-193K Annually
Senior level
In-Office
Charlotte, NC, USA
128K-193K Annually
Senior level
Design, develop, and deploy cloud threat detection for AWS and GCP; integrate and normalize cloud telemetry into the enterprise SIEM; create and tune detections, dashboards, and alerting; map detections to MITRE ATT&CK; run adversary emulation and purple team exercises; produce SOPs, runbooks, and investigator playbooks; train SOC analysts; provide escalation and on-call support for cloud security incidents.
The summary above was generated by AI
Senior Security Engineer - IS07FE

We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.   

         

The Hartford's Information Protection (THIP) organization is seeking a Sr. Security Engineer, Cloud Threat Detection Engineer to design and enhance enterprise-scale cloud threat detection capabilities across AWS and Google Cloud Platform (GCP). This role will develop high-fidelity detections, integrate cloud telemetry into Splunk (RBA) and the enterprise SIEM, and improve visibility into cloud-based threats. The ideal candidate has hands-on experience with AWS GuardDuty, AWS CloudTrail, Google Security Command Center (SCC), Cloud Logging, and other cloud-native security tools, partnering closely with Cloud Operations, Incident Response, Detection Engineering, and SOC teams to strengthen cloud security monitoring and response.

This role will have a Hybrid work schedule, with the expectation of working in an office (Columbus, OH, Chicago, IL, Hartford, CT or Charlotte, NC) 3 days a week (Tuesday - Thursday). 

Responsibilities

  • Design, develop, test, and deploy detection content focused on AWS and GCP threats and suspicious activity. 
  • Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
  • Develop detections leveraging data sources including:
    • AWS GuardDuty
    • AWS CloudTrail
    • AWS VPC Flow Logs
    • AWS Config
    • Google Security Command Center (SCC)
    • Google Cloud Audit Logs
    • Google Cloud Logging
    • Identity and Access Management (IAM) telemetry
    • Other 3rd party CSMPs  (Orca, CrowdStrike, Wiz) 
  • Create and maintain SIEM detections, analytics, risk-based detections, dashboards, assets, identities, and alerting content.
  • Continuously tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.
  • Map detections to MITRE ATT&CK and cloud-specific attack techniques.
  • Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
  • Develop detection requirements and enrichment strategies to support AI/SOAR automation and incident response workflows.
  • Create and maintain Standard Operating Procedures (SOPs), runbooks, and investigation guides for cloud-based detections and alerts.
  • Train and mentor L1 and L2 SOC analysts on:
    • Cloud attack techniques and tactics
    • Use of cloud-native security tooling
    • Investigation workflows in the SIEM
    • CloudTrail and GCP Audit Log analysis
    • Pivoting from SIEM alerts to AWS and GCP consoles for validation and triage
  • Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.
  • Participate in on-call support rotations (approximately 5 weeks annually).

Required Qualifications

  • 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
  • Hands-on operational experience securing both AWS and Google Cloud Platform (GCP) environments.
  • Strong knowledge of AWS security services and GCP security services.
  • Experience developing and tuning enterprise SIEM detections using cloud telemetry.
  • Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.
  • Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques.
  • Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
  • Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.
  • Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.
  • Strong written and verbal communication skills.

Preferred Qualifications

  • Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, Risk-Based Alerting (RBA), dashboard creation, etc.
  • Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling.
  • Experience with SOAR platforms and security automation workflows.
  • Scripting and automation experience using Python, PowerShell, or Bash.
  • Experience supporting multi-cloud security programs.
  • Hands-on threat hunting experience in cloud environments.
  • Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint

Preferred Certifications

  • AWS Certified Security – Specialty
  • Google Professional Cloud Security Engineer
  • GIAC Cloud Threat Detection (GCTD)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Splunk Certified Architect or Consultant

Candidate must be authorized to work in the US without company sponsorship. The company will not support the STEM OPT I-983 Training Plan endorsement for this position.

Compensation

The listed annualized base pay range is primarily based on analysis of similar positions in the external market. Actual base pay could vary and may be above or below the listed range based on factors including but not limited to performance, proficiency and demonstration of competencies required for the role. The base pay is just one component of The Hartford’s total compensation package for employees. Other rewards may include short-term or annual bonuses, long-term incentives, and on-the-spot recognition. The annualized base pay range for this role is:

$128,400 - $192,600

Equal Opportunity Employer/Sex/Race/Color/Veterans/Disability/Sexual Orientation/Gender Identity or Expression/Religion/Age

About Us | Our Culture | What It’s Like to Work Here | Perks & Benefits

The Hartford Financial Services Group, Inc. Charlotte, North Carolina, USA Office

Charlotte, United States

Similar Jobs

38 Minutes Ago
Remote or Hybrid
US
128K-193K Annually
Expert/Leader
128K-193K Annually
Expert/Leader
Information Technology
Designs and delivers Snowflake data architectures on AWS, including dbt-based data engineering and AI-enabled solutions. Leads RAG, vector search, embedding, semantic search, and analytics initiatives from proof of concept through production. Directs project teams, oversees solution quality and budgets, supports proposals and business cases, and serves as a trusted technical advisor to clients. Requires strong data engineering, governance, documentation, communication, and stakeholder-management skills, with travel as needed.
Top Skills: AWSDbtEmbedding PipelinesGenerative AiPrompt OrchestrationRetrieval-Augmented GenerationSemantic SearchSnowflakeSQLVector Search
38 Minutes Ago
Remote or Hybrid
US
78K-108K Annually
Mid level
78K-108K Annually
Mid level
Information Technology
Provide customer-facing Microsoft infrastructure support in a case-based break/fix environment. Troubleshoot and resolve Azure, Microsoft 365, Windows Server, and related technology issues; manage cases, document resolutions, meet SLAs, collaborate with peers and Microsoft support, and participate in on-call coverage. The role also involves customer communication, technical documentation, mentoring, training, and identifying potential customer needs.
Top Skills: Active DirectoryIntuneMicrosoft 365AzureMicrosoft SupportSccmWindows Server
3 Hours Ago
Remote or Hybrid
United States
71K-88K Annually
Junior
71K-88K Annually
Junior
Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Administer and enhance Salesforce for VIP teams by configuring flows, reports, dashboards, access, and data management. Gather stakeholder requirements, troubleshoot user issues, support adoption, and collaborate with development, analytics, and data engineering teams on integrations and technical solutions. Query and validate data using SQL and Snowflake, test system enhancements, and identify process improvements while maintaining Salesforce data accuracy and integrity.
Top Skills: ApexExcelGoogle SheetsSalesforceSalesforce Flow BuilderSnowflakeSQL

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account