The Hanover Insurance Group logo
The Hanover Insurance Group

For more than 170 years, The Hanover has been committed to delivering on our promises and being there when it matters the most. We live our values every day, demonstrating we CARE through our values, Sustainability initiatives and inclusive corporate culture.

Senior IT Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 5,001-10,000

Location

United States

Posted

4 days ago

Salary

$111.8K - $139.7K / year

Seniority

Senior

Job Description

Senior IT Security Engineer

The Hanover Insurance Group

Role Description We are seeking a highly experienced and skilled Senior IT Security Engineer to join our IT Security organization in our Worcester, MA office or remote work arrangement. The Senior IT Security Engineer (SIEM & IDS/IPS Administrator) is responsible for the end‑to‑end administration, maintenance, and optimization of the organization’s on‑premise Security Information and Event Management (SIEM) platform and Intrusion Detection/Prevention Systems (IDS/IPS). This role ensures that these critical security technologies remain highly available, strategically aligned with enterprise security objectives, governed according to policy, and operating at peak effectiveness. The engineer will work closely with cybersecurity, infrastructure, and governance teams to ensure that threat detection, alerting, and response capabilities are robust, reliable, and continuously improving. This is a full time, exempt position. Responsibilities - SIEM Administration & Engineering - Manage, maintain, and optimize the on‑premise SIEM platform, including log ingestion, parsing, correlation rules, dashboards, and alerting. - Ensure SIEM availability, performance, and scalability to support enterprise security monitoring needs. - Develop and tune detection rules, correlation logic, and use cases aligned with threat intelligence and organizational risk. - Oversee log source onboarding, configuration, and validation across servers, applications, network devices, and security tools. - Conduct regular SIEM health checks, capacity planning, and lifecycle management. - IDS/IPS Administration & Engineering - Administer and maintain on‑premise IDS/IPS platforms, ensuring accurate detection and prevention of malicious activity. - Tune signatures, policies, and rulesets to reduce false positives while maintaining strong detection coverage. - Monitor IDS/IPS performance, availability, and event trends to identify anomalies or operational issues. - Coordinate with network and security teams to implement policy updates, rule changes, and architectural improvements. - Operational Excellence & Governance - Ensure both SIEM and IDS/IPS solutions are aligned with security governance frameworks, compliance requirements, and organizational policies. - Maintain documentation for system configurations, processes, runbooks, and governance controls. - Support audit activities by providing evidence, reports, and system configuration details. - Participate in incident response activities by providing SIEM/IDS/IPS insights, event analysis, and technical expertise. - Strategic Alignment & Continuous Improvement - Evaluate emerging threats and recommend enhancements to detection logic and monitoring capabilities. - Collaborate with architecture and leadership teams to align SIEM and IDS/IPS strategies with long‑term security objectives. - Identify opportunities to automate processes, improve detection fidelity, and enhance operational efficiency. Qualifications - Minimum 5 years of hands‑on experience administering, managing, and maintaining an on‑premise SIEM security solution and an on‑premise IDS/IPS security solution. - Demonstrated experience ensuring high availability, governance alignment, and operational effectiveness of security monitoring technologies. - Strong understanding of SIEM architecture, log ingestion pipelines, correlation logic, and event normalization. - Expertise with IDS/IPS technologies, signature tuning, network traffic analysis, and threat detection methodologies. - Proficiency with security log formats (syslog, JSON, CEF, LEEF, etc.). - Familiarity with network protocols, firewall rules, and enterprise network architecture. - Experience with Linux/Windows server administration as it relates to security tooling. - Ability to analyze security events, identify patterns, and support incident response. - Strong analytical and problem‑solving abilities. - Excellent communication skills for cross‑team collaboration. - Ability to work independently in a remote environment while managing multiple priorities. - Detail‑oriented mindset with a commitment to governance, documentation, and operational discipline. Preferred Qualifications - Industry certifications such as: - GIAC (GCIA, GCDA, GCED, GMON) - CompTIA Security+ / CySA+ - CISSP or equivalent - Experience with automation (Python, PowerShell, or similar). - Familiarity with threat intelligence platforms and frameworks (MITRE ATT&CK, NIST CSF). Benefits - Medical, dental, vision, life, and disability insurance - 401K with a company match - Tuition reimbursement - PTO - Company paid holidays - Flexible work arrangements - Cultural Awareness Day in support of IDE - On-site medical/wellness center (Worcester only) EEO Statement The Hanover values diversity in the workplace and among our customers. The company provides equal opportunity for employment and promotion to all qualified employees and applicants on the basis of experience, training, education, and ability to do the available work without regard to race, religion, color, age, sex/gender, sexual orientation, national origin, gender identity, disability, marital status, veteran status, genetic information, ancestry or any other status protected by law. Furthermore, The Hanover Insurance Group is committed to providing an equal opportunity workplace that is free of discrimination and harassment based on national origin, race, color, religion, gender, ancestry, age, sexual orientation, gender identity, disability, marital status, veteran status, genetic information or any other status protected by law. As an equal opportunity employer, Hanover does not discriminate against qualified individuals with disabilities. Individuals with disabilities who wish to request a reasonable accommodation to participate in the job application or interview process, or to perform essential job functions, should contact us at: HRServices@hanover.com and include the link of the job posting in which you are interested.

Related Categories

Related Job Pages

More Security Engineer Jobs

Finance of America logo

SVP, Chief Information Security Officer

Finance of America

Empowering 55+ customers with modern reverse mortgage options to fund the next chapter in life. NMLS #2285

Full TimeRemoteTeam 501-1,000H1B Sponsor

• Provides top-level strategic executive leadership oversight • Acts as a key advisor for the enterprise’s systems security and data integrity • Participates in the formulation of general management policy • Develops and monitors short- and long-term security standards and best practices • Provides final approval for strategic information systems security plans • Drives technology risk and change management priorities • Monitors the execution of strategic plans for disaster recovery and business continuity • Analyzes and resolves escalated IT security related issues • Directs the development and production of reporting tools, key performance metrics, and policies • Proactively addresses and resolves conflict and helps others navigate ambiguity

United States
Job Closed
Ascend Technologies logo

Azure Solutions, Security Architect

Ascend Technologies

Innovation & Technology Enabling Business Growth

Full TimeRemoteTeam 201-500Since 2020H1B Sponsor

• Design and lead enterprise Azure solutions across compute, networking, identity, storage, logging, and monitoring. • Architect secure Azure landing zones and hybrid cloud environments aligned with Microsoft best practices and organizational standards. • Lead cloud migration and modernization initiatives from on-premises or legacy platforms to Azure. • Design and implement Infrastructure as Code (IaC) using ARM, Bicep, and/or Terraform. • Design and support CI/CD pipelines to enable automated, repeatable, and compliant infrastructure deployments. • Embed security-by-design and Zero Trust principles into all Azure architectures. • Design and implement Azure-native security controls, including Azure Policy, Microsoft Defender for Cloud, Microsoft Sentinel, identity protection, and conditional access. • Perform cloud security posture reviews and environment readiness assessments. • Serve as a senior advisor for cloud security and compliance initiatives aligned to ISO 27001, SOC 1/2, GDPR, TISAX, and similar regulatory frameworks. • Lead the interpretation, design, implementation, and operationalization of security and compliance controls within Azure environments. • Conduct compliance and risk gap assessments and translate regulatory requirements into Azure-native technical and operational controls. • Support audit readiness activities, including evidence preparation, control validation, and remediation planning. • Act as a trusted advisor to engineering teams, business leaders, and executive stakeholders.

United States
$155K / year
ARGO-HYTOS logo

Security & Compliance Engineer

ARGO-HYTOS

We make your products better. Worldwide.

Full TimeRemoteTeam 1,001-5,000H1B No Sponsor

• Support and continuously improve the ISMS, including compliance activities, audit preparation, evidence collection, risk tracking, and remediation follow-up. • Translate security and compliance requirements into practical technical controls and verify their effectiveness. • Implement and operate core security controls in the Microsoft / Entra environment, including MFA, Conditional Access, role-based access, privileged access practices, access reviews, endpoint security, and hardening. • Coordinate operational security activities such as Cyber Defence Center investigations, vulnerability and patch management, incident response, backup/restore security, ransomware resilience, and restore-test evidence. • Integrate security into IT operations, change/release processes, and service management, and report the security posture using relevant KPIs such as MFA coverage, device compliance, patch status, critical risks, and restore-test success.

Czechia
Boston Consulting Group logo

Global IT Infra/Cloud Engineer Senior Specialist

Boston Consulting Group

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.

Full TimeRemoteTeam 10,001

Role Description As Global IT Senior Infrastructure Developer, you will be responsible for development and technical support of BCG's new GenAI case team assistant. You will work with a team of internal and external developers, product owners, solution architects, and scrum masters to deliver on the roadmap. You will be expected to be hands-on with the latest development technologies and bring innovative ways to execute faster delivery for global BCG users. Therefore, a commitment to collaborative problem solving, sophisticated development practices, and the creation of quality products are essential. Qualifications - BTech/MCA with 5+ years of experience in the development of business applications in a commercial IT setting, or in consulting Requirements - Participate in Agile ceremonies to deliver on the squad mission - Create technical design for using design guardrails and business needs - Security best practices in cloud environments - Monitoring and logging to analyze & track resource utilization, application performance, and identify potential issues (Grafana, Prometheus, Loki or ELK) - Having knowledge of DevSecOps & DevOps - Strong Python experience including async programming - Troubleshoot reported production tickets and provide timely analysis and resolution - Stay abreast of development tools, trends and practices, and act as an advocate and promoter for items that should be considered for future initiatives - Keeping Technical Debt to the bare minimum - Excellent communication skills and the ability to communicate with product owners/business analysts/solution architects and understand requirements carefully and execute Company Description Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.

Costa Rica