Security Engineer, AWS Cloud Security Response

Herndon, Virginia, USA

Amazon.com

Free shipping on millions of items. Get the best of Shopping and Entertainment with Prime. Enjoy low prices and great deals on the largest selection of everyday essentials and other products, including fashion, home, beauty, electronics, Alexa...

View all jobs at Amazon.com

Apply now Apply later

The AWS Cloud Response Team manages the security and availability of AWS Cloud services. We operate on the ‘AWS’ side of the Shared Responsibility Model to ensure “Security of the Cloud” and to protect our customers. This role requires engineers to work tactically with both internal and external stakeholders to solve security challenges at massive scale, and to think strategically to develop and implement changes to drive automation, scalability and continuous progress for the organization.


Key job responsibilities
A successful candidate will need a combination of troubleshooting, technical, and communication skills, as well as the ability to handle a mix of disparate tasks which may include small-projects in addition to managing incident response activities. This role will provide career growth opportunities as you gain new security skills in the course of your duties.

- Triage new incoming issues to determine the level of risk they present to AWS, and then accordingly prioritize its remediation in conjunction with the impacted service team.
- Communicate the state of these issues to various audiences, both technical and non-technical, at various levels of seniority (up to and including the AWS Chief Information Security Officer).
- Participate in efforts to promote security throughout the company and build good working relationships with partner security teams and service teams across Amazon
- Demonstrate high capacity for managing priorities appropriately while remaining productive and effective, with tolerance for context switching and interruptions
- Escalate issues early and often, expressing a high degree of security judgement when issues are not progressing at the correct pace based on impact to ensure we are putting customers first.
- Explore and embrace the Amazon builder culture, identifying mechanisms and methods to improve tools and processes to simplify and drive issues at the scale and speed necessary to benefit our global team of engineers.
- Fulfill regular on-call responsibilities during the team's working hours and in support of the global team's on-call weekend rotation

A day in the life
This position supports AWS with security operations and incident response activities. You will be responsible for coordinating and facilitating security response activities for all AWS products and services. You will drive security related issues to resolution across numerous service teams, interacting directly with those teams and other AWS Security engineers.

About the team
Cloud Response is a team inside AWS Security Operations. This team is broadly responsible for the 'AWS' side of the Shared Responsibility Model, and provides oversight of security issues from their identification through to resolution. Cloud Response operates follow-the-sun with teams based around four different geographical locations.

We work with AWS security and service teams to ensure security issues are addressed and resolved with the right level of urgency, while keeping our key stakeholders informed and engaged as necessary throughout the issue lifecycle.

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications


- Bachelor's degree in engineering, cybersecurity, or 4+ years’ equivalent professional experience.
- 3+ years of experience on a Security Operations team, coordinating responses to security events which involve multiple teams across an organization, and programmatically preventing recurrence.
- 2+ years or more of demonstrated experience with a focus in areas such as systems, network, and/or application security.
- Understanding of best practices across multiple security disciplines/domains.

Preferred Qualifications

- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Strong demonstrated knowledge of web protocols, common attacks, and an in-depth knowledge of Linux/Unix tools and architecture.
- 2+ years experience with scripting or programming languages such as Python, Bash, JavaScript, or Java
- Possess strong security judgment, critical thinking, and leadership skills in order to build trust, collaborate with, and influence partner teams to understand security and business impacts of issues.

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Application security Automation AWS Bash CISO Cloud Cryptography DNS Exploits Incident response Java JavaScript Linux Network security Pentesting Python Scripting TCP/IP UNIX Vulnerabilities

Perks/benefits: Career development Flex hours Startup environment Team events

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.