Talent.com
Security Engineer II, Threat Hunting, Security Incident Response Team (SIRT)
Security Engineer II, Threat Hunting, Security Incident Response Team (SIRT)Amazon • Arlington, VA, United States
Security Engineer II, Threat Hunting, Security Incident Response Team (SIRT)

Security Engineer II, Threat Hunting, Security Incident Response Team (SIRT)

Amazon • Arlington, VA, United States
30+ days ago
Job type
  • Permanent
Job description

Amazon Security is looking for an experienced Security Engineer who is excited by the idea of searching for undetected threat activities at petabyte scale. In this role, you will work alongside a team of world class security practitioners and develop novel threat detection and mitigation strategies.

Our Threat Hunting team hunts for adversarial activity using a variety of tools, methods, intelligence, and techniques. The team is hands-on with security data and is known for developing innovative solutions to common security problems. Our threat hunting engineers are builders as much as they are security engineers, and as a member of this team, you will solve security challenges at scale and work to protect one of the most sophisticated e-Commerce platforms ever built.

If you are someone who enjoys researching threats, diving deep into large datasets, and developing novel solutions to common security problems, we would like to meet you. Your work will be essential to delighting our customers and maintaining their vital trust.

Export Control Requirement : Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

Key job responsibilities

  • You will query, collate, and evaluate machine-generated data for evidence of potentially damaging activities which could pose a risk to Amazon customers and data.
  • You will work alongside our global incident response team and participate in the scoping and analysis of complex security issues.
  • You will evaluate threat actor tactics, techniques, and procedures (TTPs) for threat detection opportunities.
  • You will design, develop, and deploy early-stage threat detection mechanisms and partner with Threat Detection engineers to establish durable and long-term coverage.
  • You will develop metrics and implement solutions to derive operational insights from custom capabilities.
  • You will identify opportunities to automate repetitive processes and generate efficiencies for multiple teams.
  • You will participate in an on-call rotation and provide ad hoc support to customers during non-business hours, when required.

A day in the life

  • Develop data base queries to extract threat signals and security artifacts from large and diverse datasets.
  • Work alongside and participate in a global effort to improve Amazon's security posture and reduce risk to business operations and customers.
  • Monitor cybersecurity news, media, and blog posts to maintain awareness of changes to the threat landscape.
  • Lead and participate in the development of innovative capabilities to identify cyber threat activities at scale.
  • Contribute individually and as a team to projects and ad hoc efforts designed to address high priority security issues.
  • About the team

    Amazon's Threat Hunting team is a component of a global security incident response organization charged with mitigating security issues which pose a risk to the core retail and subsidiary businesses. Our Threat Hunting engineers leverage robust experience across multiple security disciplines, including digital forensics, threat intelligence, threat detection engineering, security automation, red teaming, and more, to create innovative solutions and maximize value for customers.

    Our Threat Hunting team embraces automation and consistently seek out opportunities to raise the security bar. Their engineers operate from first principles and are builders as much as they are security practitioners. The team is well respected within the security organization and has a strong reputation of delivering value for its customers.

    Why Amazon Security

    At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

    Work / Life Balance

    We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.

    Inclusive Team Culture

    In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

    Training and Career Growth

    We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

    #JoinDefSec

    BASIC QUALIFICATIONS

  • Bachelor's degree, or CCSP (Certified Cloud Security Professional) or CEH (Certified Ethical Hacker) or CFR (CyberSec First Responder) or Cloud+ or CySA+ (CompTIA Cybersecurity Analyst) or GCED (GIAC Certified Enterprise Defender) or GICSP (Global Industrial Cyber Security Professional) or PenTest+
  • 3+ years of any combination of the following : threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  • Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
  • PREFERRED QUALIFICATIONS

  • Experience authoring complex threat detection mechanisms
  • Experience working with large datasets and distributed computing architectures
  • Direct hands-on experience in an Incident Response role or working alongside an Incident Response organization in a direct-support capacity
  • Experience investigating security incidents involving Cloud, Container, and Endpoint (Windows / Linux / MacOS) environments
  • Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

    Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country / region you're applying in isn't listed, please contact your Recruiting Partner.

    Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000 / year in our lowest geographic market up to $212,800 / year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and / or other benefits. For more information, please visit This position will remain posted until filled. Applicants should apply via our internal or external career site.

    Create a job alert for this search

    Security Engineer Ii • Arlington, VA, United States

    Related jobs
    Insider Threat Program Senior System Engineer

    Insider Threat Program Senior System Engineer

    Leidos • Lorton, VA, US
    Full-time
    The Digital Modernization Sector at Leidos currently has an opening for a Senior System Engineer supporting the HEITS Contract as part of the Department of Homeland Security (DHS) Insider Threat Pr...Show more
    Last updated: 30+ days ago • Promoted
    CyberSecurity Engineer III

    CyberSecurity Engineer III

    American Systems • Chantilly, VA, United States
    Full-time
    IT / Cyber Security / Network Systems.AMERICAN SYSTEMS is an employee-owned federal government contractor supporting national priority programs through our strategic solutions in the areas of Infor...Show more
    Last updated: 1 day ago • Promoted
    Sr. Security Engineer - Red Team

    Sr. Security Engineer - Red Team

    NVR • Reston, VA, United States
    Full-time
    Job Category Information Technology.Market Location VA - Northern Virginia.Senior Security Engineer to join our Red Team within the Cybersecurity Engineering group. This role is 100% on-site and is ...Show more
    Last updated: 2 days ago • Promoted
    ISSE Security Engineer

    ISSE Security Engineer

    Metronome LLC • Alexandria, VA, United States
    Full-time
    Job Title : Security Engineer (ISSE).Must hold DoD 8570 IAT Level II (e.Competitive salary and bonus structure, Comprehensive health insurance, 401(k) with company match, Generous PTO and remote wor...Show more
    Last updated: 1 day ago • Promoted
    Security Engineer (ISSE) Columbia, MD

    Security Engineer (ISSE) Columbia, MD

    Polaris Consulting Group • Columbia, MD, United States
    Full-time
    Polaris is looking for an Information Systems Security Engineer (ISSE).Candidate will perform system or network designs that encompass multiple enclaves, to include those with differing data protec...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Verotis, LLC • Washington, DC, United States
    Part-time
    Be among the first 25 applicants.Verotis Is Seeking An Experienced Security Engineer To Support Security Operations, Strategy, Planning, Architecture, Vulnerability Assessments And Remediation, And...Show more
    Last updated: 30+ days ago • Promoted
    IA & SS or Security Engineer

    IA & SS or Security Engineer

    AHU Technologies, Inc. • Washington, DC, United States
    Permanent
    Role : IA & SS Master (Security Engineer).The Security Engineer role will focus on designing and developing security architecture patterns that meet regulatory obligations and data protection requi...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer II

    Security Engineer II

    Trustmark • Washington, DC, United States
    Full-time
    Trustmark's mission is to improve wellbeing - for everyone.It is a mission grounded in a belief in equality and born from our caring culture. It is a culture we can only realize by building trust.Tr...Show more
    Last updated: 2 days ago • Promoted
    Sr. Security Engineer Red Team

    Sr. Security Engineer Red Team

    International Executive Service Corps • Reston, VA, United States
    Full-time
    Senior Security Engineer to join our Red Team within the Cybersecurity Engineering group.This role is 100% on-site and based in our Reston, VA HQ office. At NVR, our technology teams are dedicated t...Show more
    Last updated: 1 day ago • Promoted
    Security Engineer

    Security Engineer

    Agile Defense • Springfield, VA, United States
    Full-time
    At Agile Defense we know that action defines the outcome and new challenges require new solutions.That's why we always look to the future and embrace change with an unmovable spirit and the courage...Show more
    Last updated: 1 day ago • Promoted
    Sr. Security Engineer

    Sr. Security Engineer

    Network Designs, Inc. • Washington, DC, United States
    Full-time
    NDi) is a leading federal contractor specializing in designing, developing, and delivering IT and network solutions for government customers. Founded in 1985, NDi’s core values drive its success and...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer II, Security Incident Response Team (SIRT)

    Security Engineer II, Security Incident Response Team (SIRT)

    Amazon • Arlington, VA, United States
    Full-time
    Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team.In this role you will work within the Amazon Security Incident Response Team (SIRT).SIRT...Show more
    Last updated: 2 days ago • Promoted
    Intrusion Detection Systems (IDS) Engineer

    Intrusion Detection Systems (IDS) Engineer

    Leidos • Gwynn Oak, MD, United States
    Full-time
    Intrusion Detection Systems (IDS) Engineer,.This role focuses on operating Network IDS platforms such as Snort 3.Security Operations through proactive threat detection and analysis.If this sounds l...Show more
    Last updated: 2 days ago • Promoted
    Azure Security Sr. Engineer

    Azure Security Sr. Engineer

    Arena Technical Resources, LLC (ATR) • Washington, DC, United States
    Full-time
    Information Security Analyst Duties and Responsibilities.Design, implement, and maintain secure cloud architectures within Azure Government Secret classified environments.Enforce zero trust princip...Show more
    Last updated: 28 days ago • Promoted
    Cyber Security Incident Response Engineer :

    Cyber Security Incident Response Engineer :

    Akraya • Washington, DC, United States
    Full-time
    Primary Skills : Incident Response-Expert, Scripting-Advanced, TCP / IP-Expert, Security Analysis-Expert, Digital Forensics-Advanced Contract Type : W2 Only Duration : 8+ Months with Possible Extension ...Show more
    Last updated: 1 day ago • Promoted
    Sr. Security Engineer

    Sr. Security Engineer

    Network Designs • Chantilly, VA, United States
    Full-time
    NDi) is a leading Federal contractor that specializes in designing, developing, and delivering information technology and network solutions for government customers. Founded in 1985, NDi's firmly de...Show more
    Last updated: 1 day ago • Promoted
    Senior SOC Security Engineer II

    Senior SOC Security Engineer II

    Aledade, Inc. • Bethesda, MD, United States
    Full-time
    The Senior SOC Security Engineer will serve as a key technical expert within the Security Operations Center (SOC), responsible for leading the design, implementation, and optimization of security m...Show more
    Last updated: 2 days ago • Promoted
    Security Engineer (ISSE) Fort Belvoir, VA -PG

    Security Engineer (ISSE) Fort Belvoir, VA -PG

    Polaris Consulting Group • Fort Belvoir, VA, United States
    Full-time
    Polaris is looking for a Security Engineer / Architect.Candidate will be required to understand and document a systems design and implementation that encompass multiple enclaves, to include those wit...Show more
    Last updated: 30+ days ago • Promoted