Senior Cloud Security Engineer
Chubb Global Information Security is looking for a hands-on security engineer to detect, respond to, and harden against cyber threats across our multi-cloud environment (Azure primary, AWS and GCP, and Microsoft 365). As a Senior Cloud Security Engineer, you will build and tune detections, respond to incidents, and close down attack paths before they're exploited. The ideal candidate has strong traditional incident response fundamentals, applies them to cloud and SaaS environments, and can build detection content and automation rather than just consume it. IAM architecture and posture program ownership sit with a dedicated team — this role is about detecting, responding, and hardening, not designing access models. This role requires practical experience securing and responding to incidents in large, global, regulated enterprise environments, and comfort using modern AI tooling (Claude/Claude Code or similar) as part of daily engineering work.
Responsibilities:
- Detect, respond to, and remediate cyber threats across Azure, AWS, GCP, and Microsoft 365
- Build and tune detection content (KQL analytics rules, Sigma rules, Sentinel workbooks) to close coverage gaps as new threats and cloud services emerge
- Lead and support incident response engagements end-to-end — triage, containment, eradication, and after-action reporting
- Harden cloud and SaaS environments against known attack techniques (identity abuse, misconfiguration, lateral movement, persistence) in partnership with infrastructure, IAM, and application teams
- Create workflows and automations (logic apps, scripts, or AI-assisted tooling) to solve recurring security challenges and speed up triage/response
- Investigate anomalous activity using SIEM, EDR, and native cloud logging; drive tuning to reduce false positives without losing coverage
- Prepare operational reporting and after-action reports for business and IT Security management
- Stay current on emerging cloud attack techniques and translate them into new detections or hardening controls before they're needed
Required Qualifications:
- 7+ years IT Security experience, with 3+ years hands-on in Azure and/or AWS security
- Strong, demonstrable incident response background.
- Experience writing or tuning detection logic (KQL, Sigma, or equivalent) in a SIEM (Microsoft Sentinel preferred)
- Proficient with core security tooling: SIEM, EDR, cloud-native logging/posture tools (Defender for Cloud, GuardDuty, etc.)
- Comfortable using AI coding/analysis tools (Claude Code or similar) and automation workflows to streamline operations and accelerate investigations.
- Scripting ability (PowerShell and/or Python) for automation and tooling
- Strong time management and organizational skills
- Excellent communication skills, both verbal and written
- Solid problem-solving and decision-making skills
- Ability to be on-call or available after hours for emergencies
Preferred Qualifications:
- Working knowledge of Microsoft 365 security (Entra ID, Defender products) and exposure to GCP
- Security certifications such as GCIH, GCFA, CCSP, CISSP, OSCP
- Microsoft certifications, including Azure Security
- Experience building or maintaining internal security automation/tooling