Security Engineer, Threat Detection, Threat Detection
Austin, Texas, USA
Amazon.com
Free shipping on millions of items. Get the best of Shopping and Entertainment with Prime. Enjoy low prices and great deals on the largest selection of everyday essentials and other products, including fashion, home, beauty, electronics, Alexa...
Job summary
Amazon is seeking Security Engineers to join our Detection and Monitoring team in the Amazon Security Operations Center.
Join the team responsible for creating and curating detectors for threats relevant to all Amazon businesses. The Detection and Monitoring team works within the Amazon Security Operations Center to build and maintain mechanisms to detect attacker tactics, techniques and procedures, and to investigate alerts. You will use internal and external threat intelligence, your experience hunting threat actors, or your experience performing red team operations to identify emerging threats to Amazon and create innovative detection techniques using network, system and application logs generated from across a large, heterogeneous network. You will develop automated enrichments to improve the quality and context of alerts, and automated mitigations to minimize the containment time for security incidents.
With your technical expertise, you will be solving security challenges at scale, working to protect the applications powering the most sophisticated e-commerce platform ever built.
Responsibilities:
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
· BA/BS in a related discipline, or equivalent experience
· 3+ years of information security experience, preferably in intrusion detection and response, threat hunting, or red/purple teams
· Advanced knowledge of network, system, and web application attacks and mitigations.
· Deep understanding of adversary techniques and the signals they generate
· Expertise in tools and techniques for analyzing large sets of data
· Strong verbal and written communication skills
· Experience developing software automation solutions
· Proficiency in one or more high-level coding or scripting language
· 3+ years’ experience creating, analyzing and responding to security alerts from large scale, complex networks
· Experience leveraging data science/machine learning techniques to detect anomalous security events
· Experience with Amazon Web Services
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
Amazon is seeking Security Engineers to join our Detection and Monitoring team in the Amazon Security Operations Center.
Join the team responsible for creating and curating detectors for threats relevant to all Amazon businesses. The Detection and Monitoring team works within the Amazon Security Operations Center to build and maintain mechanisms to detect attacker tactics, techniques and procedures, and to investigate alerts. You will use internal and external threat intelligence, your experience hunting threat actors, or your experience performing red team operations to identify emerging threats to Amazon and create innovative detection techniques using network, system and application logs generated from across a large, heterogeneous network. You will develop automated enrichments to improve the quality and context of alerts, and automated mitigations to minimize the containment time for security incidents.
With your technical expertise, you will be solving security challenges at scale, working to protect the applications powering the most sophisticated e-commerce platform ever built.
Responsibilities:
- Operate as part of the Security Operations Center to detect and investigate advanced threats on Amazon’s networks
- Build innovative new ways to detect potential threats on Amazon's networks
- Build systems to enrich alerts, and automate remediation and response actions
- Work with teams across Amazon to identify and build threat detections supporting InfoSec's customers
- Provide support during security incidents
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
Basic Qualifications
· BA/BS in a related discipline, or equivalent experience
· 3+ years of information security experience, preferably in intrusion detection and response, threat hunting, or red/purple teams
· Advanced knowledge of network, system, and web application attacks and mitigations.
· Deep understanding of adversary techniques and the signals they generate
· Expertise in tools and techniques for analyzing large sets of data
· Strong verbal and written communication skills
· Experience developing software automation solutions
· Proficiency in one or more high-level coding or scripting language
Preferred Qualifications
· Relevant industry certifications which demonstrate intimate familiarity with the cyber-attack lifecycle. (e.g. GMON, GDAT, GCIH, GCFA, GREM, OSCP)· 3+ years’ experience creating, analyzing and responding to security alerts from large scale, complex networks
· Experience leveraging data science/machine learning techniques to detect anomalous security events
· Experience with Amazon Web Services
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Automation E-commerce GCFA GCIH GREM Intrusion detection Machine Learning Monitoring OSCP Red team Scripting Threat detection Threat intelligence
Perks/benefits: Team events
Region:
North America
Country:
United States
Job stats:
18
1
0
Categories:
Security Engineering Jobs
Threat Intel Jobs
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Ethical hacker / Pentester H/F jobs
- Open Information Security Specialist jobs
- Open Manager Pentest H/F jobs
- Open Senior Cyber Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Cyber Security Specialist jobs
- Open Product Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Principal Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Cybersecurity Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Chief Information Security Officer jobs
- Open IT Security Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open Cybersecurity Consultant jobs
- Open Security Specialist jobs
- Open Senior Information Security Engineer jobs
- Open Cybersecurity Specialist jobs
- Open Senior Penetration Tester jobs
- Open Security Researcher jobs
- Open Sr. Security Engineer jobs
- Open Senior Security Architect jobs
- Open Security Operations Analyst jobs
- Open Clearance-related jobs
- Open ISO 27001-related jobs
- Open Windows-related jobs
- Open Application security-related jobs
- Open Network security-related jobs
- Open Agile-related jobs
- Open Pentesting-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Security assessment-related jobs
- Open Java-related jobs
- Open IDS-related jobs
- Open DevOps-related jobs
- Open Malware-related jobs
- Open Security Clearance-related jobs
- Open EDR-related jobs
- Open Kubernetes-related jobs
- Open CEH-related jobs
- Open IPS-related jobs