Senior Security Engineer - IS07FE
We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too. Join our team as we help shape the future.
The
Enterprise Cyber Focal Office -Sr. SecurityEngineeris a senior, hands-on technicalleaderand trusted partner to the Enterprise Cyber Focal Lead. This roleis responsible fordesigning, developing, and implementing complex,AIdrivencyber security solutions that strengthen application security, vulnerability management, and enterprise cyber resilience.Operating at atechnical lead/manager (T7)level, this role combines
deep engineeringexpertise,
cloud-native architecture, and
applied AIwith strong leadership and influence across Cyber, ReliabilityEngineering,Infrastructure Engineeringand Software Engineering teams. The role also provides technicalleadership anddirection to offshore teams and drives adoption of secure-by-design engineering practices across the enterprise.
This role will have aHybrid work schedule,with the expectation of working in an office (Columbus, OH, Hartford, CT or Charlotte, NC) 3 days a week (Tuesday through Thursday).Technical Leadership & Solution Delivery- Serve as atrusted technical advisorto the Enterprise Cyber Focal Lead, translating cyber strategy into scalable,highimpacttechnical solutions.
- Design, build, and implement complex cyber solutionsleveragingAI/ML to improve threat detection, vulnerability management, risk prioritization, and automation.
- Leadend-to-end solution architecture, including design reviews, implementation, and operational readiness for cyber platforms and tooling.
- Applyfullstackapplication developmentexpertiseto build secure, resilient, andperformantcyber applications and services.
Cloud & AI Engineering- Architect and deliver solutions usingAWS cloud services, following cloud-native,wellarchitected, andsecurityprinciples.
- Applyhands-on AI/ML capabilities(GCP preferred) to build and operationalize intelligent cyber capabilities (e.g., analytics, anomaly detection, automation,decision support).
- Partner with data, AI, and platform teams to ensure solutions are scalable, secure, andproduction-ready.
ApplicationSecurity- Demonstratedhandsonexperience with enterprise security, logging, and monitoring platforms (e.g., Splunk, Dynatrace, Orca Security, Akamai),leveragingthese tools to drive threat detection, observability, and risk reduction at scale.
- Applies deep technicalexpertisein security telemetry, application logging, and runtime monitoring to design, integrate, andoptimizeapplication levelsecurity and observability capabilitiesenterprisewide.
- Experienced in LeveragingGitHub Copilotas ahandsonproductivity and quality accelerator for secure software development, including code scaffolding, refactoring, test generation, and documentation, while ensuring adherence to enterprise security and coding standards.
Application Vulnerability Management- Own and lead application vulnerability managementfrom a technical standpoint, including tooling,integrations, automation, and remediation workflows.
- Partner with CISO (THIP) and Engineering organization and drive modernization and automation of vulnerability intake, prioritization, and reporting using AI and data-driven techniques.
- Partner with application teams to embed vulnerability remediation into SDLC and CI/CD pipelines.
Engineering Partnership & Best Practices- Act as atrusted partner toSecurity, Platform,Reliability and Software Engineers, enabling secure, reliable, and resilient application delivery.
- Define, promote, and enforceapplication security best practices, including secure coding, dependency management, secrets handling, logging, and monitoring.
- Influence engineering teams through technical standards, referencearchitectures, and hands-on guidance rather than mandate.
Team Leadership & Delivery Excellence- Provide technical leadership to anoffshore engineering team, including design guidance, code reviews, mentoring, and delivery oversight.
- Ensure high engineering quality, operational stability, and adherence to enterprise security and compliance standards.
- Contribute to roadmap planning, prioritization, and continuous improvement of cyber platforms and capabilities.
Required Experience & Qualifications- 6+ yearsof experience in cyber-focused application development (security engineering), with time in technical leadership roles.
- Strongsecurity application developmentexperience (frontend, backend, APIs, integrations). This includesproficiencyin modern frameworks and languages such as Angular, React, or Vue.js withstrict Content Security Policy (CSP) and XSS prevention.Node.js orNestJSusing security modules like Helmet, Jose, andexpress-validator.
- Proven experience designing and deliveringenterprise-scale cyber, security or application platforms.
- Experience leading and mentoringdistributed/offshore technical teams, using Splunk, Dynatrace, Akamai or other events and logs.
- Ability tooperateas atrusted partner and influenceracross Cyber, Engineering, and Infrastructure organizations.
- Experience acrosslogging and monitoring, edge and application security,AIassisteddevelopment, ITSM workflows, CI/CD pipelines, and automated deployment platforms, ensuring scalable, secure, and repeatable engineering practices.
- Knowledge ofapplication security, vulnerability management, and secure SDLC practices is preferred.
- The role requiresexpertisein API design (REST/GraphQL), database technologies (SQL and NoSQL), andcloudnativedevelopment on platforms such as Azure or AWS. Afullstacktech lead is also adept in CI/CD practices,infrastructureascode, containerization (e.g., Docker, Kubernetes), and secure coding principles, withhandsonexperience integrating security, logging, monitoring, and performance tools.
- Strongproblemsolvingskills,systemlevelthinking, and the ability to collaborate across product, security, and operations teams are essential to delivering scalable, resilient, and secure applications.
- Deep hands-on experience withAWS cloud architecture and related services. Demonstratedhands-on AI/ML implementation experience, withGCP preferred(Vertex AI,BigQuery, ML pipelines, or equivalent).
Candidate must be authorized to work in the US without company sponsorship.The company will not support the STEM OPT I-983 Training Plan endorsement for this position.Required Certifications:- One or more Security Certification focused on app sec - (e.g., CSPM, CSSM, CISSP, CISM, CSSLP, CCSP, CompTIA, ISC2, GIAC, EC-Council)
- One or more cloud security -
- TheAWS Certified Security - Specialty(often called AWS Security Specialty, SCS-C02)
- Google Professional Cloud Security Engineer
Preferred Certifications:- AI / ML Certification (AWS, GCP, or equivalent)
- AWS Certification (e.g., Solutions Architect, DevOps Engineer)
Compensation
The listed annualized base pay range is primarily based on analysis of similar positions in the external market. Actual base pay could vary and may be above or below the listed range based on factors including but not limited to performance, proficiency and demonstration of competencies required for the role. The base pay is just one component of The Hartford's total compensation package for employees. Other rewards may include short-term or annual bonuses, long-term incentives, and on-the-spot recognition. The annualized base pay range for this role is:
$128,400 - $192,600
Equal Opportunity Employer/Sex/Race/Color/Veterans/Disability/Sexual Orientation/Gender Identity or Expression/Religion/Age
About Us|Our Culture|What It's Like to Work Here|Perks & Benefits