Sr Security Engineer, Perimeter Threat Research Team
About the Role
AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. We support all AWS data centers and all of the servers, storage, networking, power, and cooling equipment that ensure our customers have continual access to the innovation they rely on. We work on the most challenging problems, with thousands of variables impacting the supply chain. You'll join a diverse team of software, hardware, and network engineers, supply chain specialists, security experts, operations managers, and other vital roles. You'll collaborate with people across AWS to help us deliver the highest standards for safety and security while providing seemingly infinite capacity at the lowest possible cost for our customers. You'll experience an inclusive culture that welcomes bold ideas and empowers you to own them to completion.
The AWS Threat Research Team is responsible for publishing a rich source of AWS home-grown threat intelligence for AWS services and customers. We are looking for talented, creative and passionate Security Engineers to help us research threats in innovative ways to deliver actionable threat indicators and disrupt threats. The AWS Threat Research Team (TRT) is looking for a security engineer with deep expertise in application and network security who is passionate about research, advocacy, and protecting large-scale, production applications.
Key Job Responsibilities
- Learn how our products work today, and where we want to take them in the future
- Help craft and build out threat data gathering security systems at scale
- Stay on top of cyber security trends and mentor other engineers in the same
- Act as a technical lead, influencing other engineers' designs and coding deliverables
- Work in an agile development environment, collaborating closely with software engineers
- Have fun in a challenging but rewarding environment
- Demonstrate strong proficiency in malware reverse engineering, including the ability to analyze, disassemble, and deconstruct malicious software using industry-standard tools such as IDA Pro, Ghidra, and debuggers like x64dbg
- Apply static and dynamic analysis techniques to identify malware behavior, capabilities, and indicators of compromise
- Apply solid foundation in web application security, including expertise in identifying and mitigating vulnerabilities such as SQL injection, cross-site scripting (XSS), and authentication flaws
- Apply familiarity with OWASP methodologies and tools like Burp Suite
- Leverage hypothesis-driven approaches and behavioral analytics to proactively detect adversarial activity within enterprise environments
- Craft custom detection rules and queries across SIEM platforms
- Apply comprehensive understanding of network security with a strong emphasis on DDoS mitigation and botnet research
- Analyze botnet infrastructure, understand command-and-control communication protocols, and identify botnet propagation techniques
- Apply proficiency in traffic analysis, volumetric attack pattern recognition, and DDoS defense strategies
- Use packet capture tools such as Wireshark, Zeek, and NetFlow analysis platforms
- Research emerging botnet families and their evolving attack vectors
About the Team
The AWS Perimeter Protection Threat Research Team produces actionable threat intelligence that drives AWS security and networking services, including AWS Shield, AWS WAF, AWS Firewall Manager, and Network Firewall. Our diverse team of security researchers and engineers operates advanced deception technology and threat intelligence systems to identify, track, and analyze bad actors as they continuously evolve their tactics, techniques, and procedures. We proactively monitor emerging threats across some of the largest distributed networks in the world, transforming raw intelligence into meaningful insights that strengthen AWS defenses. If you're passionate about outsmarting adversaries and shaping the future of cloud security at scale, we'd love to have you join us.
Basic Qualifications
- Bachelor's degree
- 5+ years of IT Security experience
Preferred Qualifications
- Knowledge of network, system, and web application attacks and mitigations
- Experience in web security, or experience in managing firewalls and experience managing full application stacks from the OS up through custom applications
- Experience communicating technical concepts to a non-technical audience
- Experience in written and verbal communication with the ability to present complex technical information in a clear and concise manner to executives and non-technical leaders
- Experience in one or more scripting languages (e.g., Python, Ruby, Perl)
- Working knowledge of threat intelligence frameworks such as MITRE ATT&CK and familiarity with STIX/TAXII standards
Benefits
- Health insurance including medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans
- Employee Assistance Program (EAP), Mental Health Support, and Medical Advice Line
- Flexible Spending Accounts
- Adoption and Surrogacy Reimbursement coverage
- 401(k) matching
- Paid time off
- Parental leave
- Sign-on payments and restricted stock units (RSUs)
Pay
Base salary range: $178,400.00 - $226,700.00 USD annually (WA, Seattle). Final compensation determined based on factors including experience, qualifications, and location.
This response is AI-generated, for reference only.