Security Intelligence Engineer, Cyber Threat Intelligence
Listed on 2026-06-07
-
IT/Tech
Cybersecurity, Data Security
Role Overview
The Amazon Customer Ecosystems (ACES) team, part of Amazon Cyber Threat Intelligence (ACTI), develops actionable intelligence on advanced cyber threats to Amazon ecosystems such as AWS, Ads and LEO and their customers. We obtain indicators and other intelligence from a variety of internal and external sources, use that information to understand sophisticated actors and their tools, techniques, and procedures (TTPs), and leverage that understanding to proactively identify and mitigate malicious activity.
The successful candidate will analyze both attributed and unattributed actor TTPs to generate intelligence, insights into current threats, and help enhance capabilities by identifying new data sources, formulating analytic techniques, and working across teams. They will harness expansive data sets, generate actionable insights using database querying and statistical analysis, and contribute to Amazon’s state‑of‑the‑art cyber threat intelligence analysis and dissemination.
- Perform deep dive analysis of malicious artifacts.
- Analyze large, unstructured data sets to identify trends and anomalies indicative of malicious activities.
- Create security techniques and automation for internal use that enable high‑speed and broad‑scale operations.
- Contribute to Amazon’s understanding of the current threat landscape and the techniques, tactics, and procedures associated with specific threats.
- Draft and publish finished written threat intelligence products based on findings.
- Fulfill periodic on‑call responsibilities.
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object‑oriented language.
- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command‑line tools.
- Bachelor’s degree in computer science or equivalent.
- 3+ years of experience in any combination of application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing.
- 2+ years of professional work experience or experience in SQL or other relational databases.
- 3 years of experience tracking highly sophisticated cyber threat groups.
- 2+ years of experience in threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, and network security.
- Knowledge of command‑line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks.
- Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP.
- Experience with AWS products and services.
- Experience performing security activities across one or more phases of the software development life cycle (SDLC) such as security design review, threat modeling, secure code review, and security testing.
- Experience with malware analysis, network flow analysis, and large‑scale data analysis; familiarity with modern threat intelligence platforms (TIPs).
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Salary InformationUSA, MD, Annapolis Junction – $ – $ USD annually
USA, NY, New York – $ – $ USD annually
USA, TX, Austin – $ – $ USD annually
USA, VA, Arlington – $ – $ USD annually
USA, VA, Herndon – $ – $ USD annually
USA, WA, Seattle – $ – $ USD annually
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).