Security Intelligence Engineer, Incident Response...

Amazon.com, Inc.
Arlington, VA, United States
2 days ago

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$159,300.0 - $202,400.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) .NET Framework Amazon Web Services User Authentication C++ (Programming Language) Command-Line Interface Code Review Cyber Security Computer Programming Database Queries Digital Forensics Domain Name System (DNS)
+19 more
Hypertext Transfer Protocols (HTTP) HTTP Secure Identity and Access Management Python (Programming Language) Network Security Network Protocols Object-Oriented Software Development Ruby Secure Coding Security Information and Event Management Software Engineering TCP/IP Unstructured Data Scripting Swift (Programming Language) Cyber Threat Analysis Cybercrime Golang Programming Languages

Job description

The Threat Intelligence for Global Enterprise Response (TIGER) team, part of Amazon Cyber Threat Intelligence (ACTI), is responsible for developing actionable intelligence on advanced cyber threats to Amazon employees and company assets. Our intelligence supports incident response teams, red teams, detections teams and teams working to prevent financial loss to the company. We obtain indicators and intelligence from a variety of internal and external sources and use that information to develop an understanding of sophisticated actors and their tools, techniques, and procedures. We then leverage that understanding to proactively identify and mitigate malicious activity.

The successful candidate will analyze indicators to generate actionable intelligence and insight into current threats. As a Security Intelligence Engineer, you will help enhance our capabilities by formulating new analytic techniques and working across teams to drive the supporting capabilities. A deep understanding of current cyber threat actors and TTPs as well as experience performing question-driven analysis is required. You will leverage your understanding of networking- and host-based indicators, digital forensics, and database querying as you investigate incidents and threats as well.

This position requires that the candidate selected be a US Citizen.

Key job responsibilities

  • Analyze large and unstructured data sets to identify trends and anomalies indicative of malicious activities.

  • Create security techniques and automation for internal use that enable you to operate at high speed and broad scale.

  • Contribute to Amazon’s understanding of the current threat landscape and the techniques, tactics, and procedures associated with specific threats.

  • Perform deep dive analysis of malicious artifacts.

  • Draft and publish finished written threat intelligence products based on findings.

  • Periodic on-call responsibilities.

About the team

Work/Life Balance

Our team puts a high value on work-life balance. It isn’t about how many hours you spend at home or at work; it’s about the flow you establish that brings energy to both parts of your life. We believe striking the right balance between your personal and professional life is critical to life-long happiness and fulfillment. We offer flexibility in working hours and encourage you to find your own balance between your work and personal lives.

Inclusive Team Culture

In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Mentorship & Career Growth

Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional., At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Requirements

3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience

  • 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience

  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience

  • Bachelor’s degree in a STEM field (Science, Technology, Engineering, Mathematics), or 3+ years of IT Security experience

  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP

  • Experience in scripting, programming, and security code reviewing in a common programming language (non-internship)

Preferred Qualifications

  • 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience

  • 2+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience

  • Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks

  • Knowledge of networking protocols, to include HTTP(S), DNS, and TCP/IP

  • Experience with AWS products and services

  • Experience with programming languages such as Python, Java, C+Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Benefits & conditions

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits .

USA, TX, Austin - 159,300.00 - 202,400.00 USD annually

USA, VA, Arlington - 159,300.00 - 202,400.00 USD annually

USA, VA, Herndon - 159,300.00 - 202,400.00 USD annually

USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

6:16 min

Event-driven Golang backend architecture and cloud deployment

Irina Branovic Irina Branovic · World Congress 2026 Europe

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

Videos

See all

Related articles

See all