IND Lead Engineer, Security - Security Operation Centre Specialist
The Hartford · India · 1d ago
We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.
Senior Security Specialist - Security Operations Center (SOC)
About the Role
The Hartford's Information Protection (THIP) organization is looking for an experienced cybersecurity professional to join our Threat Management team. In this role, you will help protect the company by detecting, investigating, and responding to security threats across our enterprise environment.
As a Level 2 SOC Analyst, you will serve as an escalation point for security incidents, support threat hunting activities, and work closely with our Security Operations Center (SOC) and Incident Response teams. This is an excellent opportunity to make a meaningful impact while working with modern security technologies across cloud, endpoint, network, and email environments.
What You'll Do
- Investigate and respond to cybersecurity alerts and incidents escalated from Level 1 analysts.
- Monitor and analyze security events using SIEM and other security monitoring platforms.
- Perform threat hunting activities to proactively identify suspicious behavior and emerging threats.
- Review and investigate activity across networks, endpoints, cloud platforms, email systems, and security tools.
- Leverage threat intelligence to identify risks and improve detection capabilities.
- Coordinate with infrastructure, cloud, application, and security teams during incident response activities.
- Help improve monitoring, detection content, and incident response processes.
- Participate in a rotating 24x7 on-call support schedule.
Desired Experience
Required
- 3+ years of experience in Information Security, Threat Management, or Security Operations.
- 4+ years of experience in technical IT roles such as networking, systems administration, or infrastructure support.
- Strong analytical and investigative skills with the ability to assess risk and make sound security decisions.
- Experience working collaboratively across technical and business teams.
Preferred Technical Skills
- SIEM platforms such as Splunk, CrowdStrike Next-Gen SIEM, or Microsoft Sentinel.
- Endpoint Detection and Response (EDR) technologies such as CrowdStrike, Microsoft Defender XDR, Carbon Black, or Sentinel One.
- Cloud security monitoring and investigation across AWS, Microsoft Azure (M365), Google Cloud.
- Cloud security tools such as AWS GuardDuty, Google Security Command Center (SCC), Orca, Wiz, or similar CSPM solutions.
- Email security, phishing, and Business Email Compromise (BEC) investigations.
- Threat Intelligence Platforms (TIPs) and threat hunting methodologies.
- Knowledge of malware analysis, attack techniques, indicators of compromise, and modern threat actor tactics.
Education & Certifications
- Bachelor's degree in Computer Science, Information Security, Engineering, or equivalent experience.
- Industry certifications such as ISC2, GIAC, or ISACA certifications are preferred.