AWS Global Services includes experts from across AWS who help our customers design build operate and secure their cloud environments. Customers innovate with AWS Professional Services upskill with AWS Training and Certification optimize with AWS Support and Managed Services and meet objectives with AWS Security Assurance Services. Our expertise and emerging technologies include AWS Partners AWS Sovereign Cloud AWS International Product and the Generative AI Innovation Center. Youll join a diverse team of technical experts in dozens of countries who help customers achieve more with the AWS cloud.
Do you want to work on planetary scale security solutions in the cloud Are you skilled at performing Incident Response activities and helping customers build threat detection and incident response capabilities using highly scalable computing architectures Are you excited to help customers automate security operations giving them unprecedented capability and agility Do you enjoy working on fast-paced complex projects focused on game changing business outcomes for customers globally AWS Security Incident Response Service is seeking a motivated professional who desires to join our global innovative & high-energy Security team. The right candidate must thrive in high-pressure situations think like both an attacker & defender and help relevant teams take the right actions in the right timeframes to mitigate risks. As a member of the AWS Customer Incident Response Team (CIRT) in the AWS Global Services Security Organization you will have the opportunity to pioneer technically excellent security solutions supporting customer initiatives that are meaningful to their business. As a member of AWS CIRT you will be able to delight customers with leading edge security incident response via AWS Security Incident Response service and other escalation mechanisms. Our goal of securing the worlds workloads and building a brighter future for humanity requires us to focus on reliable delivery of bar raising security outcomes and investment in security mechanisms and automation on behalf of our customers. Building on those experiences youll collaborate with AWS service teams on new features innovate with new technologies and explore new challenges.
Key job responsibilities
Perform and oversee incident response operations
Become a deep technical resource that earns the trust of customer stakeholders before during and after a security event.
Independently contribute to teams that include Amazonians partners and customers to build and deploy threat detection and incident response capabilities.
Design build and deploy solutions to automate security operations and incident response on AWS.
Independently contribute to internal builder projects to develop new consulting engagement models and capabilities for customers.
Develop high-quality content such as automation tools reference architectures and white papers to help our consultants partners and customers build on the work that we deliver.
Innovate on behalf of customers by translating your thoughts into action-oriented results.
Mentor and invest in our employees partners and customers to raise the bar for our customers.
Periodic on-call required.
A day in the life
As a Security Engineer on the proactive side of AWS CIRT responsibilities include monitoring networks and systems for potential threats performing triage for security alerts documenting suspicious activity and reporting issues so they can be adequately handled. You will work alongside our security engineers and partner teams to perform daily threat detection and incident response using the full capability of AWS technologies and services to detect and mitigate cyber threats at a massive scale and help protect AWS Customers. You should also enjoy learning about the most up-to-date new technologies and procedures to protect information systems and data.
About the team
Proactive side of AWS CIRT provides 24/7 threat monitoring investigation and response across for customers AWS environments. AWS CIRT enhances existing security capabilities by supporting security monitoring for all native AWS services and supports vendor agnostic detective and protective controls to provide holistic security controls for customers. This is done by leveraging data on common attack techniques to enhance detective controls and incident response then building auto-remediation capabilities to minimize disruption to customer workloads. When a security event does happen you will be there provide guidance.
About AWS
Diverse Experiences
AWS values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description we encourage candidates to apply. If your career is just starting hasnt followed a traditional path or includes alternative experiences dont let it stop you from applying.
Why AWS
Amazon Web Services (AWS) is the worlds most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating thats why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.
Inclusive Team Culture
AWS values curiosity and connection. Our employee-led and company-sponsored affinity groups promote inclusion and empower our people to take pride in what makes us unique. Our inclusion events foster stronger more collaborative teams. Our continual innovation is fueled by the bold ideas fresh perspectives and passionate voices our teams bring to everything we do.
Mentorship & Career Growth
Were continuously raising our performance bar as we strive to become Earths Best Employer. Thats why youll find endless knowledge-sharing mentorship and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home theres nothing we cant achieve.
- Completed Bachelors Degree in Computer Science or equivalent experience
- Demonstrated experience in a technical field and understanding of security concepts and common security threats in host operating systems (Linux/ Windows) Network security concepts log analysis and investigation.
- Familiarity with at least one functional scripting language (e.g. Python JavaScript shell scripting).
- Knowledge of common system security vulnerabilities and remediation techniques.
- Understanding of the tools tactics and techniques used by threat actors during security events.
- Familiarity/experience with AWS services and security concepts.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status disability or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process including support for the interview or onboarding process please visit
for more information. If the country/region youre applying in isnt listed please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $125500/year in our lowest geographic market up to $212800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge skills and experience. Amazon is a total compensation company. Dependent on the position offered equity sign-on payments and other forms of compensation may be provided as part of a total compensation package in addition to a full range of medical financial and/or other benefits. For more information please visit This position will remain posted until filled. Applicants should apply via our internal or external career site.