The Hartford Financial Services Group, Inc

Sr. Security Engineer - Cloud Threat Detection

Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in cybersecurity roles focused on security operations and incident response.
  • Hands-on experience securing both AWS and Google Cloud platforms.
  • Strong knowledge of AWS and GCP security services and their integration.
  • Proficient in developing enterprise SIEM detections using cloud telemetry.
  • Ability to create operational documentation and investigation procedures.
  • Experience training and mentoring SOC analysts on cloud security practices.
  • Strong communication skills, both written and verbal.

Responsibilities

  • Design and deploy detection content targeting AWS and GCP threats.
  • Integrate cloud security telemetry into the enterprise SIEM platform.
  • Develop detections using cloud-native services and data sources.
  • Maintain and enhance SIEM detections, analytics, and alerting content.
  • Tuning detection logic to minimize false positives while enhancing coverage.
  • Conduct adversary emulation and cloud attack simulations for effective detections.
  • Develop SOPs and investigation guides for cloud-based detections.

Benefits

  • Hybrid work schedule with three days in the office each week.
  • Access to professional development and training opportunities.
  • Potential for performance-based bonuses and long-term rewards.
  • Supportive work culture focused on collaboration and mentorship.
Full Job Description
Senior Security Engineer - IS07FE

The Hartford's Information Protection (THIP) organization is seeking a Sr. Security Engineer, Cloud Threat Detection Engineer to design and enhance enterprise-scale cloud threat detection capabilities across AWS and Google Cloud Platform (GCP). This role will develop high-fidelity detections, integrate cloud telemetry into Splunk (RBA) and the enterprise SIEM, and improve visibility into cloud-based threats. The ideal candidate has hands-on experience with AWS GuardDuty, AWS CloudTrail, Google Security Command Center (SCC), Cloud Logging, and other cloud-native security tools, partnering closely with Cloud Operations, Incident Response, Detection Engineering, and SOC teams to strengthen cloud security monitoring and response.

This role will have a Hybrid work schedule, with the expectation of working in an office (Columbus, OH, Chicago, IL, Hartford, CT or Charlotte, NC) 3 days a week (Tuesday - Thursday).

Responsibilities
  • Design, develop, test, and deploy detection content focused on AWS and GCP threats and suspicious activity.
  • Integrate and normalize cloud security telemetry from AWS and GCP into the enterprise SIEM platform.
  • Develop detections leveraging data sources including:
    • AWS GuardDuty
    • AWS CloudTrail
    • AWS VPC Flow Logs
    • AWS Config
    • Google Security Command Center (SCC)
    • Google Cloud Audit Logs
    • Google Cloud Logging
    • Identity and Access Management (IAM) telemetry
    • Other 3rd party CSMPs (Orca, CrowdStrike, Wiz)
  • Create and maintain SIEM detections, analytics, risk-based detections, dashboards, assets, identities, and alerting content.
  • Continuously tune and optimize detection logic to reduce false positives while improving detection fidelity and coverage.
  • Map detections to MITRE ATT&CK and cloud-specific attack techniques.
  • Participate in adversary emulation, purple team exercises, and cloud attack simulations to validate detection effectiveness.
  • Develop detection requirements and enrichment strategies to support AI/SOAR automation and incident response workflows.
  • Create and maintain Standard Operating Procedures (SOPs), runbooks, and investigation guides for cloud-based detections and alerts.
  • Train and mentor L1 and L2 SOC analysts on:
    • Cloud attack techniques and tactics
    • Use of cloud-native security tooling
    • Investigation workflows in the SIEM
    • CloudTrail and GCP Audit Log analysis
    • Pivoting from SIEM alerts to AWS and GCP consoles for validation and triage
  • Provide advanced escalation support to the SOC and Incident Response teams during cloud security investigations.
  • Participate in on-call support rotations (approximately 5 weeks annually).


Required Qualifications
  • 5+ years of cybersecurity experience with direct involvement in security operations, incident response, threat detection, or detection engineering.
  • Hands-on operational experience securing both AWS and Google Cloud Platform (GCP) environments.
  • Strong knowledge of AWS security services and GCP security services.
  • Experience developing and tuning enterprise SIEM detections using cloud telemetry.
  • Experience integrating cloud-native security tools and log sources into enterprise security monitoring platforms such as Splunk Enterprise Security, Microsoft Sentinel, QRadar, Cortex XSIAM, etc.
  • Strong understanding of cloud attack methodologies, identity compromise, privilege escalation, persistence, lateral movement, and data exfiltration techniques.
  • Experience investigating alerts using raw cloud telemetry, including CloudTrail and GCP Audit Logs.
  • Ability to create operational documentation, investigation guides, SOPs, and analyst playbooks.
  • Experience training and mentoring SOC analysts on cloud threat investigation and triage processes.
  • Strong written and verbal communication skills.


Preferred Qualifications
  • Demonstrated experience with Splunk Enterprise Security, SPL, data modeling, Risk-Based Alerting (RBA), dashboard creation, etc.
  • Strong understanding of adversary behavior, MITRE ATT&CK, cyber kill chain, and threat modeling.
  • Experience with SOAR platforms and security automation workflows.
  • Scripting and automation experience using Python, PowerShell, or Bash.
  • Experience supporting multi-cloud security programs.
  • Hands-on threat hunting experience in cloud environments.
  • Exposure to EDR platforms such as CrowdStrike, SentinelOne, or Microsoft Defender XDR for Endpoint


Preferred Certifications
  • AWS Certified Security - Specialty
  • Google Professional Cloud Security Engineer
  • GIAC Cloud Threat Detection (GCTD)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Cyber Threat Intelligence (GCTI)
  • Splunk Certified Architect or Consultant


Candidate must be authorized to work in the US without company sponsorship. The company will not support the STEM OPT I-983 Training Plan endorsement for this position.

Compensation

The listed annualized base pay range is primarily based on analysis of similar positions in the external market. Actual base pay could vary and may be above or below the listed range based on factors including but not limited to performance, proficiency and demonstration of competencies required for the role. The base pay is just one component of The Hartford's total compensation package for employees. Other rewards may include short-term or annual bonuses, long-term incentives, and on-the-spot recognition. The annualized base pay range for this role is:

$128,400 - $192,600

About The Hartford Financial Services Group, Inc

The Hartford is an industry leading provider of property and casualty insurance, group benefits and mutual funds. Throughout our rich history of more than 200 years, countless businesses and individuals, including Robert E. Lee, Abraham Lincoln and Babe Ruth, have turned to our company for protection. The Hartford celebrated its 200th anniversary in 2010.

The Hartford Financial Services Group, Inc. Careers

Join the esteemed team at The Hartford Financial Services Group, Inc., a leader in investment and insurance, where we offer more than just job opportunities—we provide a platform for professional growth and innovation. As one of the most respected names in the financial services industry, The Hartford is dedicated to fostering a culture of diversity, leadership, and continuous development.

Work You’ll Do

Embark on a career with The Hartford and contribute to our mission of helping customers achieve amazing financial outcomes. You will have the chance to work alongside a team of experts who are not only skilled in their fields but are also passionate about making a difference.

Transform Your Career

At The Hartford, we believe in nurturing talent through comprehensive training programs and robust career development opportunities. Our commitment to professional growth is evident in our dynamic leadership and diversity training programs that prepare you for the future.

Innovate with Us

Innovation is at the heart of everything we do at The Hartford. Join us and bring your unique perspective to help shape the future of financial services. Our collaborative environment encourages creativity and is the perfect place to advance your skills in groundbreaking ways.

Be Part of a Great Team

The Hartford is not just a company; it's a community. We pride ourselves on a workplace culture that upholds the values of inclusivity and teamwork. By joining us, you’ll work on diverse teams that value your insights and encourage networking and mutual support.

Future-Proof Your Career

With a wide range of job opportunities, from internships to full-time positions, The Hartford offers a path for everyone. Whether you’re just starting out or looking to take your career to the next level, we provide the tools and support needed to succeed. Our benefits package is designed to ensure that our team members are well taken care of, not only at work but in all aspects of life.

Explore Job Opportunities and Internships

Whether you're polishing your resume, preparing for an interview, or seeking to enhance your employment experience, The Hartford has a position to match your skills and ambitions. We are continuously hiring and looking for new talent to join our thriving team.

Stay Connected

Join Our Team Search open positions that match your skills and interest at The Hartford. We look for passionate, curious, creative, and solution-driven team players.

Keep Up to Date

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at The Hartford Financial Services Group, Inc. Join us at The Hartford—where careers thrive and futures are made.
Learn more about The Hartford Financial Services Group, Inc
Size
18,500 employees
Market Cap
$24.1 billion
Industry
Net Income
$1.7 billion
Founded
1810
5 Year Trend
+6.5%
Revenue
$20.5 billion
NASDAQ

Similar Jobs

More Jobs at The Hartford Financial Services Group, Inc

More Information Technology Jobs

Find similar Sr. Security Engineer - Cloud Threat Detection jobs: