Security Engineer II, Stores Security - HealthCare
Amazon · Seattle, WA · 2 wk ago
EngineeringFull-time
About the role
The Security Engineer II will design, build, and operate detection and monitoring capabilities that protect Amazon Health Services (AHS) across cloud infrastructure, applications, endpoints, and AI-powered systems. They will work closely with AHS engineering teams, peer security teams, and incident responders to ensure rapid threat detection and efficient investigation, while maintaining HIPAA compliance and Amazon's security bar.
Responsibilities
- Design, build, and maintain detection-as-code capabilities across cloud infrastructure (CloudTrail, GuardDuty, VPC Flow Logs), SaaS applications, endpoints, and identity systems, improving coverage and signal quality
- Develop and deploy detections and monitoring for agentic applications and AI services, including anomaly detection for LLM-powered tools, agent orchestration systems, and AI service APIs
- Build automated investigation and response workflows that replace manual runbooks, leveraging AI to scale triage, enrichment, containment, and remediation
- Develop and deploy AI/LLM-powered tooling to investigations, reduce alert fatigue, and extend team capacity beyond traditional headcount constraints
- Monitor telemetry data, alerting systems, and dashboards for signals of degradation, compromise, or abuse across AHS environments
- Triage and correlate alerts to identify patterns, reduce noise, and surface high-fidelity signals before impact escalates
- Lead and participate in incident response: detection, investigation, containment, and retrospectives, identifying root causes and driving long-term resilience improvements
- Partner cross-functionally with AHS engineering and platform teams to expand logging, improve observability, and embed detection capabilities into the development lifecycle
- Identify gaps in visibility or detection coverage and translate ambiguous threat landscapes into detection and response solutions
- Develop and maintain security documentation: detection coverage maps, threat models, runbooks, and monitoring architecture guidelines
Qualifications
- 5+ years of security-related professional experience
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience
- Experience directly working with cloud hosting technologies (AWS, Azure, etc.)
- Experience applying threat modeling or other risk identification techniques or equivalent
- Software engineering fundamentals with proficiency in Python, Go, Java, or similar languages, and experience working in production codebases
- Experience with log aggregation and analysis platforms (e.g., Splunk, OpenSearch, ELK, Datadog) and/or endpoint detection tools (e.g., SentinelOne, CrowdStrike)
Benefits
Amazon offers comprehensive benefits including health insurance, 401(k) matching, paid time off, and parental leave. For more information, visit here.