Senior Cloud Security Engineer

Chubb
Chubb

Other Engineering

Philadelphia, PA, USA

Posted on Aug 25, 2026

Chubb Global Information Security is looking for a hands-on security engineer to detect, respond to, and harden against cyber threats across our multi-cloud environment (Azure primary, AWS and GCP, and Microsoft 365). As a Senior Cloud Security Engineer, you will build and tune detections, respond to incidents, and close down attack paths before they're exploited. The ideal candidate has strong traditional incident response fundamentals, applies them to cloud and SaaS environments, and can build detection content and automation rather than just consume it. IAM architecture and posture program ownership sit with a dedicated team — this role is about detecting, responding, and hardening, not designing access models. This role requires practical experience securing and responding to incidents in large, global, regulated enterprise environments, and comfort using modern AI tooling (Claude/Claude Code or similar) as part of daily engineering work.

Responsibilities:

  • Detect, respond to, and remediate cyber threats across Azure, AWS, GCP, and Microsoft 365
  • Build and tune detection content (KQL analytics rules, Sigma rules, Sentinel workbooks) to close coverage gaps as new threats and cloud services emerge
  • Lead and support incident response engagements end-to-end — triage, containment, eradication, and after-action reporting
  • Harden cloud and SaaS environments against known attack techniques (identity abuse, misconfiguration, lateral movement, persistence) in partnership with infrastructure, IAM, and application teams
  • Create workflows and automations (logic apps, scripts, or AI-assisted tooling) to solve recurring security challenges and speed up triage/response
  • Investigate anomalous activity using SIEM, EDR, and native cloud logging; drive tuning to reduce false positives without losing coverage
  • Prepare operational reporting and after-action reports for business and IT Security management
  • Stay current on emerging cloud attack techniques and translate them into new detections or hardening controls before they're needed

Chubb is a world leader in insurance. With operations in 54 countries, Chubb provides commercial and personal property and casualty insurance, personal accident and supplemental health insurance, reinsurance, and life insurance to a diverse group of clients. The company is distinguished by its extensive product and service offerings, broad distribution capabilities, exceptional financial strength, underwriting excellence, superior claims handling expertise and local operations globally.

At Chubb, we are committed to equal employment opportunity and compliance with all laws and regulations pertaining to it. Our policy is to provide employment, training, compensation, promotion, and other conditions or opportunities of employment, without regard to race, color, religious creed, sex, gender, gender identity, gender expression, sexual orientation, marital status, national origin, ancestry, mental and physical disability, medical condition, genetic information, military and veteran status, age, and pregnancy or any other characteristic protected by law. Performance and qualifications are the only basis upon which we hire, assign, promote, compensate, develop and retain employees. Chubb prohibits all unlawful discrimination, harassment and retaliation against any individual who reports discrimination or harassment.

Required Qualifications:

  • 7+ years IT Security experience, with 3+ years hands-on in Azure and/or AWS security
  • Strong, demonstrable incident response background.
  • Experience writing or tuning detection logic (KQL, Sigma, or equivalent) in a SIEM (Microsoft Sentinel preferred)
  • Proficient with core security tooling: SIEM, EDR, cloud-native logging/posture tools (Defender for Cloud, GuardDuty, etc.)
  • Comfortable using AI coding/analysis tools (Claude Code or similar) and automation workflows to streamline operations and accelerate investigations.
  • Scripting ability (PowerShell and/or Python) for automation and tooling
  • Strong time management and organizational skills
  • Excellent communication skills, both verbal and written
  • Solid problem-solving and decision-making skills
  • Ability to be on-call or available after hours for emergencies

Preferred Qualifications:

  • Working knowledge of Microsoft 365 security (Entra ID, Defender products) and exposure to GCP
  • Security certifications such as GCIH, GCFA, CCSP, CISSP, OSCP
  • Microsoft certifications, including Azure Security
  • Experience building or maintaining internal security automation/tooling