{bc}
company_site

Sr. Security Engineer - Cloud Threat Detection

The Hartford
Charlotte, USA
Full-time
Senior · 5+ years experience
Hybrid
USD 128400-192600 yearly / year
Discovered 1 weeks ago
AWSGoogle Cloud Platform (GCP)AWS GuardDutyAWS CloudTrailAWS VPC Flow LogsAWS Config
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

AWSGoogle Cloud Platform (GCP)AWS GuardDuty
Smart Apply

Full Job Posting

Responsibilities

  • Design, develop, test, and deploy detection content focused on AWS and GCP threats and suspicious activity.
  • Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
  • Develop detections leveraging data sources including: AWS GuardDuty AWS CloudTrail AWS VPC Flow Logs AWS Config Google Security Command Center (SCC) Google Cloud Audit Logs Google Cloud Logging Identity and Access Management (IAM) telemetry Other 3 rd party CSMPs(Orca, CrowdStrike, Wiz)
  • AWS GuardDuty
  • AWS CloudTrail
  • AWS VPC Flow Logs
  • AWS Config
  • Google Security Command Center (SCC)
  • Google Cloud Audit Logs
  • Google Cloud Logging
  • Identity and Access Management (IAM) telemetry
  • Other 3 rd party CSMPs(Orca, CrowdStrike, Wiz)
  • Create and maintain SIEM detections, analytics, risk-based detections, dashboards, assets, identities, and alerting content.
  • Continuously tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.
  • Map detections to MITRE ATT&CK and cloud-specific attack techniques.
  • Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
  • Develop detection requirements and enrichment strategies to support AI/SOAR automation and incident response workflows.
  • Create and maintain Standard Operating Procedures (SOPs), runbooks, and investigation guides for cloud-based detections and alerts.
  • Train and mentor L1 and L2 SOC analysts on: Cloud attack techniques and tactics Use of cloud-native security tooling Investigation workflows in the SIEM CloudTrail and GCP Audit Log analysis Pivoting from SIEM alerts to AWS and GCP consoles for validation and triage
  • Cloud attack techniques and tactics
  • Use of cloud-native security tooling
  • Investigation workflows in the SIEM
  • CloudTrail and GCP Audit Log analysis
  • Pivoting from SIEM alerts to AWS and GCP consoles for validation and triage
  • Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.
  • Participate in on-call support rotations (approximately 5 weeks annually).
  • Required Qualifications
  • 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
  • Hands-on operational experience securing both AWS and Google Cloud Platform (GCP) environments.
  • Strong knowledge of AWS security services and GCP security services.
  • Experience developing and tuning enterprise SIEM detections using cloud telemetry.
  • Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.
  • Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques.
  • Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
  • Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.
  • Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.
  • Strong written and verbal communication skills.

Preferred Qualifications

  • Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, Risk-Based Alerting (RBA), dashboard creation, etc.
  • Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling.
  • Experience with SOAR platforms and security automation workflows.
  • Scripting and automation experience using Python, PowerShell, or Bash.
  • Experience supporting multi-cloud security programs.
  • Hands-on threat hunting experience in cloud environments.
  • Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint

Preferred Certifications

AWS Certified Security – Specialty

Google Professional Cloud Security Engineer

GIAC Cloud Threat Detection (GCTD)

GIAC Certified Incident Handler (GCIH)

GIAC Cyber Threat Intelligence (GCTI)

Splunk Certified Architect or Consultant

Candidate must be authorized to work in the US without company sponsorship. The company will not support the STEM OPT I-983 Training Plan endorsement for this position.

Compensation

  • The listed annualized base pay range is primarily based on analysis of similar positions in the external market. Actual base pay could vary and may be above or below the listed range based on factors including but not limited to performance, proficiency and demonstration of competencies required for the role. The base pay is just one component of The Hartford’s total compensation package for employees. Other rewards may include short-term or annual bonuses, long-term incentives, and on-the-spot recognition. The annualized base pay range for this role is:
  • Equal Opportunity Employer/Sex/Race/Color/Veterans/Disability/Sexual Orientation/Gender Identity or Expression/Religion/Age

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at The Hartford