> Markdown version of [/jobs/ext/1499931-security-engineer-correlation-and-response-aws-security-hub](https://www.wearedevelopers.com/jobs/ext/1499931-security-engineer-correlation-and-response-aws-security-hub). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Correlation and Response, AWS Security Hub - **Company:** Amazon.com, Inc. - **Location:** Seattle, WA, United States - **Experience:** Experienced - **Salary:** $159,300.0 - $202,400.0 - **Contract:** Internship / Graduate position - **Skills:** Java (Programming Language), .NET Framework, Artificial Intelligence, Amazon Web Services, User Authentication, Microsoft Azure, Bash Shell, C++ (Programming Language), Command-Line Interface, Cloud Computing, Code Review, Cyber Security, Computer Programming, Programming Tools, Domain Name System (DNS), Perl (Programming Language), Hypertext Transfer Protocols (HTTP), HTTP Secure, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Network Security, Machine Learning, Network Protocols, Object-Oriented Software Development, Windows PowerShell, Systems Development Life Cycle, Ruby, Secure Coding, Software Engineering, TCP/IP, Scripting, Google Cloud, Large Language Models, Swift (Programming Language), Information Technology, Golang, Programming Languages - **Published:** July 30, 2026 - **Apply:** https://www.amazon.jobs/en/jobs/10487821/security-engineer-correlation-and-response-aws-security-hub ## About the Role Experience evaluating threats and vulnerabilities, assigning criticality based on impact, and developing response automation - Experience scripting with Python, Perl, Bash or PowerShell - Experience with software development for the cloud using java and AWS Developer Tools - Knowledge of web protocols, common attacks, and Linux/Unix tools and architecture - Knowledge of cloud computing concepts and design considerations for AWS, Azure and GCP - 2+ years of non academic experience in any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience, Experience with Machine Learning and Large Language Model fundamentals, including architecture, training/inference lifecycles, and optimization of model execution, or experience leading and influencing your team or organization - Experience using AI to automate security assessment work flows, implement LLMs and perform agentic threat detection and remediation - Experience with AI-driven development and verification, 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience - 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience - 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience - Bachelor's degree in computer science or equivalent - Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security - Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience - Knowledge of networking protocols such as HTTP, DNS and TCP/IP - Knowledge of industry-based security vulnerabilities and remediation techniques - Experience in scripting, programming, and security code reviewing in a common programming language (non-internship) - Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience), 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience - 2+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience - Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks - Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP - Knowledge of networking protocols, to include HTTP(S), DNS, and TCP/IP - Experience with AWS products and services - Experience with programming languages such as Python, Java, C++ - Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C++ - Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing ## Description Are you excited about advancing the state of threat detection, correlation and response at scale to mitigate risk from an ever-evolving threat landscape for a diverse range of customers?, The AWS Security Hub team is looking for a highly motivated Security Engineer to join our team. In this role, you will research emerging threats to develop new criticality and posture management ideas and build high-confidence markers and rules that correlate criticality across a diverse set of conditions from large-scale data sources. You will work closely with engineering and product teams to shape the analysis, context and inference that drive visibility into the most critical threats and vulnerabilities for AWS customers operating on AWS and other cloud providers. You will also develop innovative methods utilizing the latest techniques to analyze detections at scale. Your expertise will help defend the data of Amazon's millions of customers against the most critical threats., Most days you'll be heads-down building and tuning evaluations, digging into resource analysis and log data to figure out what data markers looks like and how to reliably assess impact. You'll spend time reading up on the latest threats and turning that research into something actionable. You'll also work on advancing how we assess threats, whether that's prototyping new approaches using machine learning or generative AI, improving enrichment pipelines, or finding ways to scale what we do. It's a mix of deep technical work and close collaboration with security teams across the organization. About the team At AWS Security Hub, security is central to maintaining customer trust and protecting customer cloud environments. Our organization is responsible for creating and maintaining a high bar for security analysis across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of customer environments. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)