Principal Security Engineer, AWS Security

Amazon.com Services LLC

Maryland

On-site

USD 180,000 - 280,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Amazon.com Services LLC is seeking a Principal Security Engineer to define the technical direction for detecting and stopping sophisticated cyber threats across AWS. You will lead threat detection initiatives, prototype new detection approaches, and drive them to production with multiple teams, mentoring engineers along the way.

You will operate with high autonomy in ambiguous spaces, collaborate with software engineers, data scientists, and security professionals, and raise the technical bar

Qualifications

  • Experience performing security investigations, detection engineering, threat hunting, and/or incident response.
  • Experience with detection engineering and/or anomaly detection within security.
  • Understanding of Tactics, Techniques, and Procedures (TTPs) used by threat actors or groups.
  • Knowledge of security telemetry across 2+ domains (e.g., hosts, networks, cloud, physical security).
  • Ability to develop code with at least one modern language, such as Python.
  • Proven ability to provide technical and strategic leadership across multiple teams and/or within a large organization.
  • Experience communicating technical concepts to a non-technical audience.
  • Citizen within the EU.

Responsibilities

  • Serve as an org-wide technical lead, setting technical direction, shaping long-term strategy, and increasing each team's productivity and effectiveness
  • Identify and prioritize the highest-impact security detection problems across the org, driving clarity in ambiguous spaces
  • Design and prototype new detection approaches, then drive them to production through engineering teams
  • Stay connected to all critical projects across the org, auditing technical decisions and providing guidance on work led by others
  • Mentor engineers across multiple job families and help managers guide the career growth of their team members
  • Sponsor cross-org technical initiatives with partner teams across Amazon Security and AWS, driving decisions forward and unblocking teams to ensure delivery
  • Build consensus across teams on important security and technical trade-offs, driving closure and alignment toward coherent outcomes
  • Identify, evaluate, and advocate for new technologies to improve threat detection and mitigation capabilities
  • Clearly communicate security risks and technical trade-offs to business leaders and non-technical stakeholders

Skills

Security investigations
Threat hunting
Incident response
Detection engineering
Leadership
Cross-team collaboration
Communication
EU citizenship

Tools

Python
AWS

Job description

Come lead the technical strategy for how Amazon detects and stops the world's most sophisticated cyber threats!

We build and operate automated threat detection and mitigation systems that process over 1PB of security telemetry daily across host, network, identity, and physical security domains. As a Principal Security Engineer, you will define the technical direction for this work, identifying the hardest unsolved problems, designing and prototyping new cross-domain threat detection ideas, and driving these new initiatives to completion across multiple teams and organizations.

You will operate with high autonomy in ambiguous spaces where the problems are not handed to you. You will work alongside software development engineers, data scientists, and security engineers, mentoring across job families, building consensus across teams on technical and security trade-offs, and raising the technical bar for the org. Your work will directly protect every AWS customer worldwide and help preserve our customers' trust in us. The adversaries are real, the scale is unmatched, and our hardest problems are still unsolved.

Key job responsibilities
  • Serve as an org-wide technical lead, setting technical direction, shaping long-term strategy, and increasing each team's productivity and effectiveness
  • Identify and prioritize the highest-impact security detection problems across the org, driving clarity in ambiguous spaces
  • Design and prototype new detection approaches, then drive them to production through engineering teams
  • Stay connected to all critical projects across the org, auditing technical decisions and providing guidance on work led by others
  • Mentor engineers across multiple job families and help managers guide the career growth of their team members
  • Sponsor cross-org technical initiatives with partner teams across Amazon Security and AWS, driving decisions forward and unblocking teams to ensure delivery
  • Build consensus across teams on important security and technical trade-offs, driving closure and alignment toward coherent outcomes
  • Identify, evaluate, and advocate for new technologies to improve threat detection and mitigation capabilities
  • Clearly communicate security risks and technical trade-offs to business leaders and non-technical stakeholders
About the team

You will help define the technical strategy for how Amazon detects and stops advanced threats, with the autonomy to identify the problems worth solving and an engineering org behind you to help build the solutions. You will identify threats and security risks that are not readily apparent to traditional detection approaches, proactively taking action before those risks materialize. You will write new threat detectors and automated mitigations to catch actual threat actors. You will work across Amazon and have direct influence on how AWS protects its infrastructure and customers. In addition to identifying new problems, you will frame the solutions, demonstrate their feasibility, and drive buy-in with leadership to get them funded, staffed, and delivered. The problems are real, the adversaries are sophisticated, and the impact you can make is global and immediate.

Basic Qualifications:
  • Experience performing security investigations, detection engineering, threat hunting, and/or incident response
  • Experience with detection engineering and/or anomaly detection within security
  • Understanding of Tactics, Techniques, and Procedures (TTPs) used by threat actors or groups
  • Knowledge of security telemetry across 2+ domains (e.g., hosts, networks, cloud, physical security)
  • Ability to develop code with at least one modern language, such as Python
  • Proven ability to provide technical and strategic leadership across multiple teams and/or within a large organization
  • Experience communicating technical concepts to a non-technical audience
  • Citizen within the EU
Preferred Qualifications:
  • Experience using common cloud services (IAM, Lambda, EC2, VPC, S3) for security response and/or automation
  • Experience processing and analyzing security telemetry at scale
  • Experience using machine learning and/or statistical methods for anomaly detection in security
  • Experience with GenAI/LLMs applied to security workflows
  • Experience working with software developers, data scientists, and/or product management teams

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.

The base salary range for thi

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Security Engineer, AWS Security
Principal Security Engineer, AWS Security

Socket.dev • Maryland

On-site
USD 189,000 - 256,000
Principal Security Engineer, AWS Security
Principal Security Engineer, AWS Security

Amazon • Annapolis (MD), Northern (KY)

On-site
USD 189,000 - 256,000
RSUs
Health insurance
401(k) matching
+1
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Socket.dev • Austin (TX)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Arlington (VA)

On-site
USD 159,000 - 202,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Austin (TX)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
Security Engineer, AWS Security
Security Engineer, AWS Security

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
Restricted stock units (RSUs)
401(k) matching
+1
Network Security Engineering Manager, AWS Infrastructure Security
Network Security Engineering Manager, AWS Infrastructure Security

Amazon Web Services (AWS) • Minneapolis (MN)

On-site
USD 175,000 - 237,000
Health insurance
RSUs
401(k) matching
+2
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 202,000
Security Engineer – Sec Escalations, Security Escalations
Security Engineer – Sec Escalations, Security Escalations

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 178,000 - 227,000
Health insurance
401(k) matching
Paid time off
+1
Security Engineer, Correlation and Response, AWS Security Hub
Security Engineer, Correlation and Response, AWS Security Hub

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 202,000