Jobs and Careers
AM
Senior Security Engineer, Threat Detection
Amazon.comUnited Statesfull_timeVerifiedPosted 25 May 2023
About the role
Amazon is seeking Security Engineers to join our Threat Detection Services team.
Join the team responsible for delivering Threat Detection capabilities to our Security Product(s) to identify threats relevant to all Amazon businesses. The Detection and Monitoring team works with the Amazon Security Incident Response Team to build and maintain capabilities to detect attacker tactics, techniques and procedures, and provide context critical to investigating alerts. You will use internal and external threat intelligence, your experience hunting threat actors, or your experience performing red team operations to identify emerging threats to Amazon and create innovative detections using network, system and application logs generated from across a large, heterogeneous network. You will develop enrichments to improve the quality and context of alerts, and automated mitigations to minimize the containment time for security incidents.
With your technical expertise, you will be solving security challenges at scale, working to protect the applications powering the most sophisticated e-commerce platform ever built.
Responsibilities:
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
· BA/BS in a related discipline, or equivalent experience
· 3+ years of information security experience in one or more of the following disciplines: detection engineering, intrusion detection and response, threat hunting, or red/purple teams
· Advanced knowledge of cloud, network, system, and web application attacks and mitigations.
· Deep understanding of adversary techniques and the signals they generate
· Expertise in tools and techniques for analyzing large sets of data
· Experience developing automation solutions
· Proficiency in one or more high-level coding or scripting language
· Proficiency Structured Query Language (SQL)
· Strong verbal and written communication skills
· Knowledge of security frameworks such as MITRE ATT&CK
· 5+ years’ experience creating, analyzing and responding to security alerts from large scale, complex networks
· Experience leveraging data science/machine learning techniques to detect anomalous security events
· Experience in using Amazon Web Services to deliver resolution to Cybersecurity problems.
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
Join the team responsible for delivering Threat Detection capabilities to our Security Product(s) to identify threats relevant to all Amazon businesses. The Detection and Monitoring team works with the Amazon Security Incident Response Team to build and maintain capabilities to detect attacker tactics, techniques and procedures, and provide context critical to investigating alerts. You will use internal and external threat intelligence, your experience hunting threat actors, or your experience performing red team operations to identify emerging threats to Amazon and create innovative detections using network, system and application logs generated from across a large, heterogeneous network. You will develop enrichments to improve the quality and context of alerts, and automated mitigations to minimize the containment time for security incidents.
With your technical expertise, you will be solving security challenges at scale, working to protect the applications powering the most sophisticated e-commerce platform ever built.
Responsibilities:
- Work with teams across Amazon to rapidly identify threats on Amazon's network and build threat detections.
- Develop detection engineering strategies to improve the detection engineering lifecycle.
- Build innovative tooling used to detect potential threats on Amazon's networks.
- Research and develop mitigations for new cybersecurity exploits, vulnerabilities, tactics, techniques and procedures.
- Develop platform requirements used to enrich alerts, and automate remediation and response actions.
- Provide tactical detection support during security incidents.
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
Basic Qualifications
· BA/BS in a related discipline, or equivalent experience
· 3+ years of information security experience in one or more of the following disciplines: detection engineering, intrusion detection and response, threat hunting, or red/purple teams
· Advanced knowledge of cloud, network, system, and web application attacks and mitigations.
· Deep understanding of adversary techniques and the signals they generate
· Expertise in tools and techniques for analyzing large sets of data
· Experience developing automation solutions
· Proficiency in one or more high-level coding or scripting language
· Proficiency Structured Query Language (SQL)
· Strong verbal and written communication skills
· Knowledge of security frameworks such as MITRE ATT&CK
Preferred Qualifications
· Relevant industry certifications which demonstrate intimate familiarity with Cybersecurity disciplines. (e.g. GMON, GDAT, GCIH, GCFA, GREM, OSCP)· 5+ years’ experience creating, analyzing and responding to security alerts from large scale, complex networks
· Experience leveraging data science/machine learning techniques to detect anomalous security events
· Experience in using Amazon Web Services to deliver resolution to Cybersecurity problems.
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s