Security Engineer , AWS Security Incident Response
Listed on 2026-09-16
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Description
As part of the AWS Applied AI Solutions organization, we have a vision to provide business applications, leveraging Amazon’s unique experience and expertise, that are used by millions of companies worldwide to manage day‑time operations. We will accomplish this by accelerating our customers’ businesses through delivery of intuitive and differentiated technology solutions that solve enduring business challenges. We blend vision with curiosity and Amazon’s real‑world experience to build opinionated, turnkey solutions.
Where customers prefer to buy over build, we become their trusted partner with solutions that are no‑brainers to buy and easy to use.
As part of the AWS Applied AI Solutions organization, we have a vision to provide business applications, leveraging Amazon’s unique experience and expertise, that are used by millions of companies worldwide to manage day‑time operations. We will accomplish this by accelerating our customers’ businesses through delivery of intuitive and differentiated technology solutions that solve enduring business challenges. We blend vision with curiosity and Amazon’s real‑world experience to build opinionated, turnkey solutions.
Where customers prefer to buy over build, we become their trusted partner with solutions that are no‑brainers to buy and easy to use.
- Respond to threat findings that indicate unauthorized activity, performing triage and escalating issues as appropriate
- Identify, evaluate, and communicate security threats, risks, and vulnerabilities, and recommend remediation actions to reduce risk
- Contribute to security automation, scripting, and tooling efforts — including AI‑augmented investigation tools — that improve the team's triage and response capabilities
- Track and report on the effectiveness of AWS detective controls such as Amazon Guard Duty and partner products such as Crowd Strike Falcon or Wiz Defend
- Develop and refine runbooks, processes, and policies that strengthen security response effectiveness
You will start your day reviewing alerts and triaging potential threats across customer environments, working alongside fellow security engineers, service partner teams, and Trust & Safety Abuse. You might spend the morning investigating a suspicious finding using AWS‑native tools, then shift to documenting your analysis and coordinating remediation with the affected service team. Beyond daily response work, you may contribute to threat research, help improve triage using signals from security partners, or prepare threat intelligence briefings for customers.
AboutThe Team
AWS Security Incident Response is a team of security engineers and incident responders who provide 24/7 threat monitoring, investigation, and response for customers running workloads on AWS. The team takes signals from security partners and Trust & Safety Abuse to improve triage and prevent harm, protecting environments ranging from startups to large enterprises using services like Amazon Guard Duty and partner integrations.
We are investing in AI‑powered forensic tools and auto‑remediation to keep pace with rapid customer growth. Team members regularly present at industry forums such as AWS re:
Invent and deliver threat intelligence briefings to customers. You can grow through automation development, threat research, partner work, or contributing to internal AWS security tooling. If you want to join an inclusive team that is shaping how AWS customers stay secure, we'd love to hear from you.
Amazon values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).