Security Engineer, Threat Detection

Amazon.com, Inc.
Arlington, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Junior
Compensation
$ 184K

Job location

Arlington, United States of America

Tech stack

User Authentication
Bash
Cloud Computing
Perl
Identity and Access Management
Intrusion Detection and Prevention
Python
Network Security
Machine Learning
Powershell
Red Team (Cyber Security)
Secure Coding
Software Engineering
Scripting (Bash/Python/Go/Ruby)
Cyber Threat Analysis
Cybercrime

Job description

Are you excited about advancing the state of threat detection at scale to mitigate risk from an ever-evolving threat landscape impacting a diverse range of businesses?, Amazon Stores Security's Threat Detection team is looking for a highly motivated Security Engineer to join our team. In this role, you will research emerging threats to develop new detection ideas and build high-confidence detections that proactively identify malicious activity across large-scale log data. You will work closely with Incident Response, Threat Hunting, Threat Intelligence, and Red Team to understand threat models and deliver detections that enable rapid response. You will also develop innovative methods utilizing the latest techniques to detect threats at scale. Your expertise will help defend the data of Amazon's millions of customers against the most critical threats., Identify critical threats targeting Amazon's network by leveraging threat intelligence and security research, then deliver high-fidelity threat detections aligned to attacker tactics, techniques, and procedures (TTPs).

  • Enhance detection engineering processes by improving how detections are scoped, prioritized, developed, tested, and maintained throughout their lifecycle.

  • Develop platform requirements to enrich alerts with contextual data, reduce false positives, and automate remediation and response actions in coordination with incident response teams.

  • Research and develop mechanisms to advance detection capabilities through machine learning, advanced data correlation, risk-based alerting, or generative AI.

  • Automate your way through challenges using Python or other scripting languages to build tooling, validate detections, and streamline operational workflows at scale.

A day in the life

Most days you'll be heads-down building and tuning detections, digging into log data to figure out what malicious activity looks like and how to catch it reliably. You'll spend time reading up on the latest threats and turning that research into something actionable. You'll also work on advancing how we detect threats, whether that's prototyping new approaches using machine learning or generative AI, improving enrichment pipelines, or finding ways to scale what we do. It's a mix of deep technical work and close collaboration with security teams across the organization.

About the team

Why Amazon Security

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.

Inclusive Team Culture

In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Requirements

Experience triaging and developing security alerts and response automation, conducting front-line analysis, and providing escalation support

  • Experience scripting with Python, Perl, Bash or PowerShell

  • Knowledge of web protocols, common attacks, and Linux/Unix tools and architecture

  • Knowledge of cloud computing concepts and design considerations

  • 1+ years of non academic experience in any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience, Experience with Machine Learning and Large Language Model fundamentals, including architecture, training/inference lifecycles, and optimization of model execution, or experience leading and influencing your team or organization

Benefits & conditions

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits .

USA, VA, Arlington - 136,000.00 - 184,000.00 USD annually

Apply for this position