Manager, Security Engineering, AWS Security Incident Response

Amazon Web Services (AWS)

Seattle (WA)

On-site

USD 175,100 - 236,900

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

RSUs
Health insurance
401(k) matching
Paid time off
Parental leave

Job summary

Amazon Web Services, Inc. is seeking a Security Manager to blend deep security operations expertise with leadership to transform a regional team of security engineers from human-driven investigations to AI-native security operations.

You will own operational excellence for a regional team, engage directly with customer security executives during high-severity incidents, and drive the response-to-automation flywheel that makes the service smarter with every investigation.

Qualifications

  • 5+ years of managing and developing teams.
  • 5+ years of progressive work within a software security team or related operating environment.
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Experience establishing credibility quickly with senior level executives across organizations.
  • Experience defining program requirements and using data and metrics to drive improvements; hands-on experience conducting or leading information security investigations during complex incidents.

Responsibilities

  • Own day-to-day operations across threat detection, triage, investigation, and incident response for a regional team of security engineers operating under defined SLOs.
  • Manage investigation queue health, enforce response time targets, and drive the team toward zero pending tickets at all times.
  • Engage directly with customer security executives — CISOs, VPs of Security, and their teams — to communicate findings, lead post-incident reviews, advise on security posture, and build long-term trust.
  • Serve as a senior escalation point for complex or high-severity incidents, taking direct ownership when investigations require leadership judgment or cross-team coordination.
  • Drive the response-to-automation flywheel: capture lessons from investigations to improve automation, enrich detection capabilities, and measure impact through metrics you define and own.
  • Oversee how your engineers work alongside AI investigation agents, maintaining human-in-the-loop guarantees and driving AI accuracy through feedback loops and quality controls.
  • Partner with peer managers across global time zones to maintain 24/7 coverage and ensure continuity across the follow-the-sun model.
  • Coach and develop security engineers, building a team culture that values root cause analysis over ticket count.

Skills

Team management
Security operations
Executive communication
Incident response leadership
Data-driven improvements

Education

Bachelor's degree in Computer Science or Information Security
Master's degree in Computer Science or related field

Job description

DescriptionAWS Security Incident Response is looking for a Security Manager who combines deep technical expertise in security operations with the leadership judgment to drive a team through a fundamental transformation — from human-driven investigation to AI-native security operations. You will own operational excellence for a regional team of security engineers, engage directly with customer security executives during high-severity incidents, and drive the response-to-automation flywheel that makes the service smarter with every investigation.

DescriptionAWS Security Incident Response is looking for a Security Manager who combines deep technical expertise in security operations with the leadership judgment to drive a team through a fundamental transformation — from human-driven investigation to AI-native security operations. You will own operational excellence for a regional team of security engineers, engage directly with customer security executives during high-severity incidents, and drive the response-to-automation flywheel that makes the service smarter with every investigation.

The AWS Security Incident Response team provides 24/7 security response through a follow-the-sun operating model. The service combines automated triage workflows, AI-powered investigation agents, and human security analysts to respond to threats across customer AWS environments at massive scale. Our AI systems autonomously resolve the majority of routine investigations within minutes, allowing engineers to focus on complex threat analysis, proactive hunting, and customer engagement. We treat every investigation as a confirmed security incident until the data proves otherwise.

Key job responsibilities
  • Own day-to-day operations across threat detection, triage, investigation, and incident response for a regional team of security engineers operating under defined Service Level Objectives (SLOs)
  • Manage investigation queue health, enforce response time targets, and drive the team toward zero pending tickets at all times
  • Engage directly with customer security executives — CISOs, VPs of Security, and their teams — to communicate findings, lead post-incident reviews, advise on security posture, and build long-term trust
  • Serve as a senior escalation point for complex or high-severity incidents, taking direct ownership when investigations require leadership judgment or cross-team coordination
  • Drive the response-to-automation flywheel: capture lessons from investigations to improve automation, enrich detection capabilities, and measure impact through metrics you define and own
  • Oversee how your engineers work alongside AI investigation agents, maintaining human-in-the-loop guarantees and driving AI accuracy through feedback loops and quality controls
  • Partner with peer managers across global time zones to maintain 24/7 coverage and ensure continuity across the follow-the-sun model
  • Coach and develop security engineers, building a team culture that values root cause analysis over ticket count

Due to the nature of the work performed within this team, candidates must be U.S. citizens and eligible to obtain a US Government security clearance.

A day in the life
  • Review queue health metrics and drive the team toward zero pending investigations
  • Coach engineers through complex investigations and review customer-facing communications for analytical depth
  • Step into high-severity incidents directly — get on a call with a customer's CISO to walk through findings and advise on remediation
  • Review AI investigation agent outputs and work with engineers to improve feedback loops
  • Coordinate with internal teams to mitigate customer security issues
  • Partner with peer managers across regions during handover calls
About The Team

The AWS Security Incident Response team provides 24/7 threat monitoring, investigation, and response for customer AWS environments. The team is in the early stages of a three-phase transformation: (1) operational excellence with defined SLOs and quality standards, (2) agentic AI transformation where AI agents conduct routine investigations autonomously, and (3) expansion into Amazon Dedicated Cloud (ADC), GovCloud, and internal AWS services. We respond to customer requests within minutes. Zero queue tolerance is the operating standard. We value engineers who solve root causes over those who close tickets. This is a unique opportunity to lead a team through a fundamental shift in how security operations are delivered.

Basic Qualifications
  • 5+ years of managing and developing teams experience
  • 5+ years of progressive work within a software security team or related operating environment experience
  • Bachelor's degree in Computer Science, Information Security, or a related field
  • Experience establishing credibility quickly with senior level executives across organizations
  • Experience defining program requirements and using data and metrics to drive improvementsHands-on experience conducting or leading information security investigations during complex incidents — not just managing from the sideline
Preferred Qualifications
  • information security professional certification (SANS GIAC, CISSP etc.)
  • Master's degree in Computer Science or a related field
  • Experience triaging and developing security alerts and response automation, conducting front-line analysis, and providing escalation support
  • Experience managing teams, or experience with Machine Learning and Large Language Model fundamentals, including architecture, training/inference lifecycles, and optimization of model execution
  • Experience working in a fast-paced, rapidly changing operations environment

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, WA, Seattle - 175,100.00 - 236,900.00 USD annually

Company

Amazon Web Services, Inc.

Job ID: A10432387

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Security Engineering, AWS Security Incident Response
Manager, Security Engineering, AWS Security Incident Response

Amazon • Seattle (WA)

On-site
USD 175,100 - 236,900
Health insurance
401(k) matching
Paid time off
+1
Security Engineering Manager - Incident Response, AWS
Security Engineering Manager - Incident Response, AWS

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 175,000 - 237,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Austin (TX)

On-site
USD 159,000 - 202,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Socket.dev • Austin (TX)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 159,000 - 202,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 202,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon • Arlington (VA)

On-site
USD 159,000 - 202,000
Security Engineer II, AWS Cloud Security Response
Security Engineer II, AWS Cloud Security Response

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 203,000
AWS Security Operations/Incident Response Engineer, US Amazon Dedicated Cloud Security
AWS Security Operations/Incident Response Engineer, US Amazon Dedicated Cloud Security

Socket.dev • Herndon (VA)

On-site
USD 136,000 - 184,000
Health insurance (including diverse覆盖)
401(k) matching
Paid time off
+1
AWS Security Operations/Incident Response Engineer, US Amazon Dedicated Cloud Security
AWS Security Operations/Incident Response Engineer, US Amazon Dedicated Cloud Security

Amazon • Herndon (VA)

On-site
USD 136,000 - 184,000