The Hartford Financial Services Group, Inc. Logo

The Hartford Financial Services Group, Inc.

Threat Detection Specialist

Posted 2 Days Ago
Be an Early Applicant
In-Office
2 Locations
116K-175K Annually
Mid level
In-Office
2 Locations
116K-175K Annually
Mid level
Develop, test, and deploy detection logic for threats using Splunk, while collaborating with threat hunters. This role involves fine-tuning alerts and participating in attack simulations.
The summary above was generated by AI
Information Security Senior Specialist - IS07EE

We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.   

         

The Hartford’s Information Protection (THIP) organization is seeking an experienced professional with extensive expertise in Splunk and a strong passion for developing high-fidelity SPL-based detections. This role is dedicated to the development, testing, and deployment of detection logic aimed at mitigating real-world threats across diverse environments. The successful candidate will lead the management and evolution of our detection library, working closely with threat hunters and incident response teams. As a key member of our Threat Management team, you will play a pivotal role in expanding our capabilities and adapting to emerging challenges. Collaboration with highly skilled senior engineers responsible for a wide range of systems and initiatives is essential. Your primary focus will be on detection analysis and development, including participation in attack simulations to test and maintain our content portfolio.

This role will have a Hybrid work schedule, with the expectation of working in an office (Hartford, CT or Charlotte, NC) 3 days a week (Tuesday through Thursday). 

RESPONSIBILITIES:

  • Design, write, and test correlation searches and detection rules in Splunk Enterprise Security (ES).
  • Implement and fine-tune Risk-Based Alerting (RBA) to prioritize critical threats, reduce alert fatigue, and improve detection accuracy.
  • Continuously refine, tune, and optimize detections to reduce false positives while maximizing visibility into real-world threats.
  • Align detection content with frameworks like MITRE ATT&CK and tailor it to customer-specific risks and environments.
  • Participating in adversarial emulations to enhance the robustness of our platforms.
  • Providing escalation support for SOC operations, including on-call support (approximately 5 weeks per year).
  • Partner with SOAR engineers to help shape playbook development from an analytical and security-first perspective.
  • Provide detection context, enrichment logic, and response requirements to support meaningful, threat-informed automation.
  • Identify opportunities to scale triage and response processes through intelligent automation.

QUALIFICATIONS:

  • 3+ years in cybersecurity, with direct experience in detection engineering, threat hunting, and incident response
  • Expert-level proficiency in Splunk SPL, including the development of correlation searches, dashboards, and scheduled alerts
  • In-depth knowledge of Splunk Enterprise Security (ES), including hands-on experience configuring and tuning Risk-Based Alerting (RBA)
  • Working knowledge of Splunk SOAR, with the ability to collaborate on automation workflows from a threat detection perspective
  • Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling
  • Experience developing detections for cloud environments (AWS, Azure, or GCP)
  • Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender for Endpoint
  • Scripting/automation skills in Python, PowerShell, or Bash are a plus
  • Relevant certifications are desirable: GCDA, GCTI, GCFA, GCIH, OSCP, Splunk Certified Consultant/Architect/Admin

Candidate must be authorized to work in the US without company sponsorship. The company will not support the STEM OPT I-983 Training Plan endorsement for this position.

Compensation

The listed annualized base pay range is primarily based on analysis of similar positions in the external market. Actual base pay could vary and may be above or below the listed range based on factors including but not limited to performance, proficiency and demonstration of competencies required for the role. The base pay is just one component of The Hartford’s total compensation package for employees. Other rewards may include short-term or annual bonuses, long-term incentives, and on-the-spot recognition. The annualized base pay range for this role is:

$116,400 - $174,600

Equal Opportunity Employer/Sex/Race/Color/Veterans/Disability/Sexual Orientation/Gender Identity or Expression/Religion/Age

About Us | Our Culture | What It’s Like to Work Here | Perks & Benefits

Top Skills

AWS
Azure
Bash
Crowdstrike
GCP
Microsoft Defender For Endpoint
Powershell
Python
Risk-Based Alerting
Sentinelone
Splunk
Splunk Enterprise Security
Splunk Soar

Similar Jobs

2 Hours Ago
Hybrid
67 Locations
124K-280K Annually
Senior level
124K-280K Annually
Senior level
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Manage M365 platform strategies, lead large projects, provide guidance to end-users, and innovate processes while interacting with clients.
Top Skills: Cloud-Based TechnologiesM365Security Protocols
2 Hours Ago
Hybrid
51 Locations
74K-244K
Mid level
74K-244K
Mid level
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
The Senior Business Analyst Manager will analyze data, manage client accounts, supervise teams, and drive project engagement using Agile methodologies.
Top Skills: AgileScrum
4 Hours Ago
Hybrid
28 Locations
77K-214K Annually
Junior
77K-214K Annually
Junior
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
The Senior Associate will manage client accounts, deliver tax solutions, supervise teams, and enhance client relationships while ensuring quality results.
Top Skills: R&D Tax CreditsResearch Credit Regulations

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account