Security Engineer, Threat Detection and Monitoring

2 months agoAustin, TX


Amazon is seeking Security Engineers to join our Detection and Monitoring team in the Amazon Security Operations Center.

Join the team responsible for creating and curating detectors for threats relevant to all Amazon businesses. The Detection and Monitoring team works within the Amazon Security Operations Center to build and maintain mechanisms to detect attacker tactics, techniques and procedures, and to investigate alerts. You will use internal and external threat intelligence, your experience hunting threat actors, or your experience performing red team operations to identify emerging threats to Amazon and create innovative detection techniques using network, system and application logs generated from across a large, heterogeneous network. You will develop automated enrichments to improve the quality and context of alerts, and automated mitigations to minimize the containment time for security incidents.

With your technical expertise, you will be solving security challenges at scale, working to protect the applications powering the most sophisticated e-commerce platform ever built.

• Operate as part of the Security Operations Center to detect and investigate advanced threats on Amazon's networks

• Build innovative new ways to detect potential threats on Amazon's networks

• Build systems to enrich alerts, and automate remediation and response actions

• Work with teams across Amazon to identify and build threat detections supporting InfoSec's customers

• Provide support during security incidents


• BA/BS in a related discipline, or equivalent experience
• 3+ years of information security experience, preferably in intrusion detection and response, threat hunting, or red/purple teams
• Advanced knowledge of network, system, and web application attacks and mitigations.
• Deep understanding of adversary techniques and the signals they generate
• Expertise in tools and techniques for analyzing large sets of data
• Strong verbal and written communication skills
• Experience developing software automation solutions
• Proficiency in one or more high-level coding or scripting language


• Relevant industry certifications which demonstrate intimate familiarity with the cyber-attack lifecycle. (e.g. GMON, GDAT, GCIH, GCFA, GREM, OSCP)
• 3+ years' experience creating, analyzing and responding to security alerts from large scale, complex networks
• Experience leveraging data science/machine learning techniques to detect anomalous security events
• Experience with Amazon Web Services

Job ID: Amazon-1397347