* Degree or Equivalent experience in a technical field. Experience performing security investigations, penetration testing and/or incident response in the context of large organisations * Understanding of security threats, hands-on experience detecting and defending from cyber attacks, and experience using big data analytics and orchestration to address security challenges * Ability to develop code with at least one modern language such as Java, Go, TypeScript, Python, Rust and security code review
Amazon is looking for a focused Security Engineer who can take on a leadership role in responding to security issues across the largest cloud provider in the world. The right candidate must thrive in high-pressure situations, think like both an attacker and defender, and drive relevant teams to take the right actions in the right timeframes to mitigate risks. We are looking for an individual who can balance technical risks against business risks and consistently drive for the right results. They must have the passion for engineering novel solutions to complex security challenges, and recognize and fill gaps in capabilities. The ability to quickly design and build internal-facing tools that enable scaled programmatic automation is a plus. The successful candidate will have a good mix of deep technical knowledge and a demonstrated background in information security. We value broad and deep technical knowledge, specifically in the fields of cryptography, network security, software security, malware analysis, forensics, security operations, incident response, and emergent security intelligence. An ideal candidate should be able to accomplish most of the following: - Confidently and intelligently respond to security incidents, and proactively consider how to prevent the same type of incidents from occurring in the future. - Design and coordinate cohesive responses to security events that involve multiple teams across the organization. - Build security utilities and tools for internal use that enable you and your fellow Security Engineers to operate at high speed and wide scale. - Evaluate the impact to the organization of current security trends, advisories, publications, and academic research. Coordinate responses as necessary across affected teams to do the right thing for our customers and our organization. - Ability to communicate effectively at multiple levels of sensitivity, and multiple audiences. - Recognize, adopt and instill the best practices in security engineering fields throughout the organization: development, cryptography, network security, security operations, incident response, security intelligence. - Provide subject matter expertise on architecture, authentication and system security. - Fulfill regular on-call responsibilities. Key job responsibilities An ideal candidate should be able to accomplish most of the following: - Triage/assess security issues and engage with internal service teams to ensure timely remediation of issues, escalating internally as necessary to ensure appropriate levels of urgency and engagement. - Participate in efforts to promote security throughout the Company and build good working relationships within the team and with others across Amazon. - Demonstrate high capacity and tolerance for extreme context switching and interruptions while remaining productive and effective. - Develop pragmatic solutions that achieve business requirements while maintaining an acceptable level of risk. - Mentoring of junior staff and proactively share knowledge sharing within the team and across the company. - Assist with hiring new employees - Fulfill regular on-call responsibilities. A day in the life Amazon Security Cloud Response is responsible for the security of Cloud services. Our primary focus is to ensure the security of the cloud by working with service teams, vendors, and other stakeholders (both internal and external) to solve security challenges at massive scale, from incident response to emergent patching to helping publish guidance for customer impacting issues. We also work to develop tools and systems, and implement changes to drive automation, scalability and continuous improvements for our organization and Amazon Security as a whole. About the team Here at Amazon, we embrace our differences. We are committed to furthering our culture of inclusion. We have ten employee-led affinity groups, reaching 40,000 employees in over 190 chapters globally. We have innovative benefit offerings, and host annual and ongoing learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences. Amazon’s culture of inclusion is reinforced within our 16 Leadership Principles, which remind team members to seek diverse perspectives, learn and be curious, and earn trust.
- Understanding of the Mitre ATT&CK framework and knowledge of host and network telemetry data (e.g., process lists, application logs, NetFlow)
- Have awareness and understanding of current cyber security threats, actors and their techniques
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice (https://www.amazon.jobs/en/privacy_page) to know more about how we collect, use and transfer the personal data of our candidates.
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.