The AWS Cloud Security Response team manages the security and availability of AWS Cloud services. We operate on the AWS side of the Shared Responsibility Model to ensure Security of the Cloud and to protect our customers. This role requires engineers to work tactically with both internal and external stakeholders to solve security challenges at massive scale and to think strategically to develop and implement changes to drive automation scalability and continuous progress for the organization.
Were looking for talented software and systems professionals with a passion for security who thrive in dynamic environments to help us continue to raise the security bar for cloud computing.
Successful candidates should:
* be able to assess technical vs. business risks and consistently drive internal engineering teams to take the right actions in the appropriate time frames to mitigate risks.
* have a good mix of broad and deep technical knowledge and a demonstrated background in information security.
* be technically proficient in the fields of network and operating system security cryptography software security security operations incident response and emergent security intelligence.
* possess a combination of troubleshooting technical and communication skills as well as the ability to manage a mix of disparate tasks which may include smallproject and software development work.
* be comfortable challenging and escalating to senior leadership to always ensure the best outcome for customers.
An ideal candidate should be able to conduct most of the following:
* Triage/assess security issues and engage with internal service teams to ensure prompt remediation of issues escalating internally as necessary to ensure the right level of urgency and engagement.
* Participate in efforts to promote security throughout the Company and build good working relationships within the team and with others across Amazon.
* Demonstrate high ability and tolerance for extreme context switching and interruptions while staying productive and effective.
* Develop pragmatic solutions that achieve business requirements while keeping an acceptable level of risk.
* Help with recruiting activities and administrative work.
* Mentoring of junior staff and proactive knowledge sharing within the team and across the company.
* Fulfill regular oncall responsibilities.
Key job responsibilities
* Supply oversight of inflight security issues.
* Triage new incoming issues to determine the level of risk they present to AWS and then accordingly prioritize its remediation in conjunction with the impacted service team.
* Communicate the state of these issues to various audiences both technical and nontechnical at various levels of seniority (up to and including AWS Chief Information Security Officer).
* Escalate issues to senior AWS leadership if you feel your issues are not being treated at the correct pace due to their impact to ensure that we are putting customers first.
* Explore building and improving our tooling to make your own life easier and at the same time sharing that benefit with all our engineers globally.
A day in the life
As part of our followthesun rotation you will receive a handoff from global peers and be delegated ownership of various security issues presently inflight. The issues could relate to any of our 200 products so you will often need to learn onthefly.
You will engage various stakeholders such as the internal service team who owns the service and its mitigation along with AWS Security Leadership Legal and the leadership of the involved service team.
As the day progresses new issues will be automatically assigned to you based on your workload and you will be responsible for triaging them determining their level of impact and work towards resolving them at the appropriate pace.
At the end of the day you will have documented your work to allow the incoming shift to continue driving issues to resolution.
About the team
Cloud Response is a team within AWS Security Operations. This team is broadly responsible for the AWS side of the Shared Responsibility Model and provides oversight of security issues from their identification through to resolution.
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description we encourage candidates to apply. If your career is just starting hasnt followed a traditional path or includes alternative experiences dont let it stop you from applying.
Why Amazon Security
At Amazon security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazons products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud devices retail entertainment healthcare operations and physical stores.
Inclusive Team Culture
In Amazon Security its in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas perspectives and voices.
Training & Career Growth
Were continuously raising our performance bar as we strive to become Earths Best Employer. Thats why youll find endless knowledgesharing training and other careeradvancing resources here to help you develop into a betterrounded professional.
Work/Life Balance
We value worklife harmony. Achieving success at work should never come at the expense of sacrifices at home which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home theres nothing we cant achieve.
Cloud Response operates with a followthesun model with teams based around four different geographical locations.
We work with other AWS teams to ensure security issues are resolved with the right level of urgency whilst ensuring that our stakeholders are informed.
BS degree in Computer Science Computer Engineering Electrical Engineering or 3 years equivalent technology experience.
3 years or more of proven experience with a focus in areas such as systems network and/or application security.
2 years of scripting/coding experience in any language (including Bash/PowerShell scripting). Previous experience in Python scripting would be ideal.
Understanding and experience with implementation of best practices across multiple security disciplines/domains.
Strong proven knowledge of virtualization technologies (AWS preferred) web protocols common attacks and Linux/Unix tools and architecture.
Demonstrated ability to collaborate/develop partnerships with partner teams work autonomously with a Bias for Action and employ critical and creative thinking.
Maturity judgment negotiation/influence skills analytical skills and leadership skills.
Ability to prioritize multiple tasks and projects in a dynamic environment.
Effective written and oral communication with multiple levels of leadership involving both business and technical sides of the business.
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race national origin gender gender identity sexual orientation protected veteran status disability age or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process including support for the interview or onboarding process please visit
for more information. If the country/region youre applying in isnt listed please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143300/year in our lowest geographic market up to $247600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on jobrelated knowledge skills and experience. Amazon is a total compensation company. Dependent on the position offered equity signon payments and other forms of compensation may be provided as part of a total compensation package in addition to a full range of medical financial and/or other benefits. For more information please visit This position will remain posted until filled. Applicants should apply via our internal or external career site.