Security Engineer, Correlation and Response, AWS Security Hub
About the role
AWS Security Hub is looking for a highly motivated Security Engineer to advance threat detection, correlation, and response at scale. You will research emerging threats, develop criticality and posture management ideas, and build high-confidence markers and rules that correlate criticality across diverse conditions from large-scale data sources. You will work closely with engineering and product teams to shape the analysis, context, and inference that drive visibility into critical threats and vulnerabilities for AWS customers operating on AWS and other cloud providers. You will also develop innovative methods utilizing the latest techniques to analyze detections at scale.
Key job responsibilities
- Research emerging threats and develop criticality and posture management ideas
- Build high-confidence markers and rules that correlate criticality across diverse conditions from large-scale data sources
- Shape analysis, context, and inference that drive visibility into critical threats and vulnerabilities
- Develop innovative methods utilizing the latest techniques to analyze detections at scale
A day in the life
Most days you'll be heads-down building and tuning evaluations, digging into resource analysis and log data to figure out what data markers look like and how to reliably assess impact. You'll spend time reading up on the latest threats and turning that research into something actionable. You'll also work on advancing how we assess threats, whether that's prototyping new approaches using machine learning or generative AI, improving enrichment pipelines, or finding ways to scale what we do. It's a mix of deep technical work and close collaboration with security teams across the organization.
About the team
At AWS Security Hub, security is central to maintaining customer trust and protecting customer cloud environments. Our organization is responsible for creating and maintaining a high bar for security analysis across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of customer environments.
Basic qualifications
- Experience evaluating threats and vulnerabilities, assigning criticality based on impact, and developing response automation
- Experience scripting with Python, Perl, Bash, or PowerShell
- Experience with software development for the cloud using Java and AWS Developer Tools
- Knowledge of web protocols, common attacks, and Linux/Unix tools and architecture
- Knowledge of cloud computing concepts and design considerations for AWS, Azure, and GCP
- 2+ years of non-academic experience in any combination of: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, and network security
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++, or similar object-oriented language
- 2+ years of scripting, programming, and security code review in a common programming language (non-internship)
- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship)
- Bachelor's degree in computer science or equivalent, or Bachelor's degree in a STEM field, or 2+ years of IT Security experience
- Knowledge of networking protocols such as HTTP, DNS, and TCP/IP
- Knowledge of industry-based security vulnerabilities and remediation techniques
Preferred qualifications
- Experience with Machine Learning and Large Language Model fundamentals, including architecture, training/inference lifecycles, and optimization of model execution, or experience leading and influencing your team or organization
- Experience using AI to automate security assessment workflows, implement LLMs, and perform agentic threat detection and remediation
- Experience with AI-driven development and verification
- 2+ years of any combination of: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, and network security
- 2+ years of scripting, programming, or security code review in a common language such as Python, Java, or C++
- Experience with AWS products and services
- Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
Pay
Base salary range: $159,300 - $202,400 USD annually (Boston, MA and Seattle, WA). Final compensation determined based on factors including experience, qualifications, and location. Amazon package includes sign-on payments and restricted stock units (RSUs).
Benefits
- Health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance, and option for Supplemental life plans)
- Employee Assistance Program (EAP), Mental Health Support, and Medical Advice Line
- Flexible Spending Accounts
- Adoption and Surrogacy Reimbursement coverage
- 401(k) matching
- Paid time off
- Parental leave