Amazon Web Services (AWS) is the leading cloud provider providing infrastructure storage networking messaging and many other services to customers all over the world. AWS runs a globally distributed environment operating at massive levels of scale. Businesses from startups to enterprises run their operations and applications on AWSs multitenant infrastructure. Governmental organizations are also looking to and depending on AWS for cloud solutions and services.
The AWS Security Incident Response team is seeking a focused Security Engineer who can take on a leadership role in responding to security issues in support of our National Security program. This engineer will work as a part of a growing team of security engineers who are focused on protecting the AWS infrastructure that is used by our national security customers. Our security engineers perform many duties during an average day: log analysis incident response forensics system/tooling development and risk assessment just to name a few. You must thrive in highpressure situations think like both an attacker and defender and drive relevant teams to take the right actions in the right time frames to mitigate risks. They also need to balance technical risks against business needs and be able to articulate risks and mitigations to members of leadership at various levels.
You should have a good mix of deep technical knowledge and a demonstrated background in information security. We value broad and deep technical knowledge specifically in the fields of cryptography network security software security malware analysis forensics security operations incident response and emergent security intelligence.
This position requires that the candidate selected be a US Citizen and must currently possess and maintain an active TS/SCI security clearance with polygraph.
Key job responsibilities
Confidently and intelligently respond to security incidents and proactively consider how to prevent the same type of incidents from occurring in the future.
Design and coordinate cohesive responses to security events that involve multiple teams across the organization.
Build security utilities and tools for internal use that enable you and your fellow Security Engineers to operate at high speed and wide scale.
Ability to communicate effectively at multiple levels of sensitivity and multiple audiences.
Recognize adopt and instill the best practices in security engineering fields throughout the organization: development cryptography network security security operations incident response security intelligence.
Fulfill regular oncall responsibilities.
About the team
Our team is dedicated to supporting new team members. Our team has a broad mix of experience levels and Amazon tenures and were building an environment that celebrates knowledge sharing and mentorship.
Here at AWS we embrace our differences. We are committed to furthering our culture of inclusion. We have ten employeeled affinity groups reaching 40000 employees in over 190 chapters globally. We have innovative benefit offerings and we host annual and ongoing learning experiences including our Conversations on Race and Ethnicity (CORE) and AmazeCon conferences. Amazons culture of inclusion is reinforced within our 16 Leadership Principles which remind team members to seek diverse perspectives learn and be curious and earn trust.
Our team also puts a high value on worklife balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here which is why we arent focused on how many hours you spend at work or online. Instead were happy to offer a flexible schedule so you can have a more productive and wellbalanced lifeboth in and outside of work.
Bachelors degree or CCSP (Certified Cloud Security Professional) or CEH (Certified Ethical Hacker) or CFR (CyberSec First Responder) or Cloud or CySA (CompTIA Cybersecurity Analyst) or GCED (GIAC Certified Enterprise Defender) or GICSP (Global Industrial Cyber Security Professional) or PenTest
Current active US Government Security Clearance of TS/SCI with Polygraph
Experience with one or more scripting/programming language (Python Ruby Java Perl etc).
Deep understanding of the AWS service catalog. Ideally you have used AWS services in a production capacity.
Experience with log analysis systems like Splunk or ELK.
Relevant certifications from Amazon Web Services or Splunk.
Strong demonstrated knowledge of web protocols common attacks and an indepth knowledge of Linux/Unix tools and architecture.
Familiarity with Windows and Linux logging systems.
Understanding of network protocols (TCP UDP DNS HTTPS TLS etc)
Understanding of highlevel cryptography principles (PKI encryption algorithms etc)
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race national origin gender gender identity sexual orientation protected veteran status disability age or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process including support for the interview or onboarding process please visit
for more information. If the country/region youre applying in isnt listed please contact your Recruiting Partner.