The Hartford
Senior Security Engineer
At a Glance
About This Role
Responsibilities
- Serve as a trusted technical advisor to the Enterprise Cyber Focal Lead, translating cyber strategy into scalable, high-impact technical solutions
- Design, build, and implement complex cyber solutions leveraging AI/ML to improve threat detection, vulnerability management, risk prioritization, and automation
- Lead end-to-end solution architecture, including design reviews, implementation, and operational readiness for cyber platforms and tooling
- Apply full-stack application development expertise to build secure, resilient, and performant cyber applications and services
- Architect and deliver solutions using AWS cloud services, following cloud-native, well-architected, and security principles
- Apply hands-on AI/ML capabilities (GCP preferred) to build and operationalize intelligent cyber capabilities
- Partner with data, AI, and platform teams to ensure solutions are scalable, secure, and production-ready
- Demonstrate hands-on experience with enterprise security, logging, and monitoring platforms (Splunk, Dynatrace, Orca Security, Akamai) to drive threat detection, observability, and risk reduction at scale
- Leverage GitHub Copilot as a hands-on productivity and quality accelerator for secure software development
- Own and lead application vulnerability management from a technical standpoint, including tooling, integrations, automation, and remediation workflows
- Partner with CISO and Engineering organization to drive modernization and automation of vulnerability intake, prioritization, and reporting using AI and data-driven techniques
- Partner with application teams to embed vulnerability remediation into SDLC and CI/CD pipelines
- Act as a trusted partner to Security, Platform, Reliability and Software Engineers, enabling secure, reliable, and resilient application delivery
- Define, promote, and enforce application security best practices, including secure coding, dependency management, secrets handling, logging, and monitoring
- Influence engineering teams through technical standards, reference architectures, and hands-on guidance rather than mandate
- Provide technical leadership to offshore engineering team, including design guidance, code reviews, mentoring, and delivery oversight
- Ensure high engineering quality, operational stability, and adherence to enterprise security and compliance standards
- Contribute to roadmap planning, prioritization, and continuous improvement of cyber platforms and capabilities
Requirements
- 6+ years of experience in cyber-focused application development (security engineering), with time in technical leadership roles
- Strong security application development experience (frontend, backend, APIs, integrations)
- Proficiency in modern frameworks and languages such as Angular, React, or Vue.js with strict Content Security Policy (CSP) and XSS prevention
- Node.js or NestJS using security modules like Helmet, Jose, and express-validator
- Proven experience designing and delivering enterprise-scale cyber, security or application platforms
- Experience leading and mentoring distributed/offshore technical teams
- Ability to operate as a trusted partner and influencer across Cyber, Engineering, and Infrastructure organizations
- Experience across logging and monitoring, edge and application security, AI-assisted development, ITSM workflows, CI/CD pipelines, and automated deployment platforms
- Knowledge of application security, vulnerability management, and secure SDLC practices
- Expertise in API design (REST/GraphQL), database technologies (SQL and NoSQL), and cloud-native development on platforms such as Azure or AWS
- Full-stack tech lead expertise in CI/CD practices, infrastructure-as-code, containerization (Docker, Kubernetes), and secure coding principles
- Hands-on experience integrating security, logging, monitoring, and performance tools
- Strong problem-solving skills, system-level thinking, and ability to collaborate across product, security, and operations teams
- Deep hands-on experience with AWS cloud architecture and related services
- Demonstrated hands-on AI/ML implementation experience, with GCP preferred (Vertex AI, BigQuery, ML pipelines, or equivalent)
- One or more Security Certification focused on app sec (CSPM, CSSM, CISSP, CISM, CSSLP, CCSP, CompTIA, ISC2, GIAC, EC-Council)
- AWS Certified Security - Specialty (SCS-C02) or Google Professional Cloud Security Engineer
- Preferred: AI/ML Certification (AWS, GCP, or equivalent)
- Preferred: AWS Certification (Solutions Architect, DevOps Engineer)
- Must be authorized to work in the US without company sponsorship
About The Hartford
The University of Hartford is a private, coeducational university located in West Hartford, Connecticut. Established in 1957, it serves approximately 6,000 to 7,000 undergraduate and graduate students across a 350-acre campus. The university is accredited by the New England Commission of Higher Education and offers a wide range of academic programs through seven schools and colleges, including the College of Arts and Sciences, Barney School of Business, and the Hartt School of Music. Students can choose from 82 bachelor's programs, 10 associate degrees, 28 graduate degrees, and several certificate programs. The university emphasizes small class sizes and personalized mentoring, with a student-faculty ratio of about 9:1. The campus features various facilities, including residence halls, a student union, and specialized centers. The university's varsity sports teams, known as the Hawks, compete in NCAA Division I. The University of Hartford is dedicated to providing a comprehensive educational experience with strengths in the arts, engineering, business, and health professions.
Security at The Hartford
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- The Hartford emphasizes responsible management and protection of personal information, adopting reasonable physical, administrative, and technical safeguards and requiring third parties to use reasonable precautions.
- Its Information Security team (THIP) embeds Reliability Engineering within security responsibilities, aligning reliability, resiliency, and secure operational practices with privacy and protection commitments.
Security Team
- The Hartford Information Security team (THIP) includes Reliability Engineering and is accountable for Operations, Reliability Engineering, DevSecOps, Quality, and Middleware.
- THIP is responsible for building and maturing RE tools, managing run processes, and directing critical incident management and remediation.
Key Initiatives
- Priorities include infrastructure provisioning, application availability, testing, deployment quality, resiliency, recovery, and efficiency.
- Goals and success measures include service reliability (availability, latency, quality), feature velocity, deployment quality, reduction of technical debt, and cost efficiency.
- Policy-level initiatives require adoption of reasonable safeguards and contractual expectations for third-party service providers.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn