Security Engineer, Correlation and Response, AWS Security Hub

Socket.dev

Boston (MA)

On-site

USD 159,300 - 202,400

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k) matching
Paid time off
Parental leave

Job summary

Amazon is seeking a highly motivated Security Engineer to advance threat detection, correlation, and response at scale for AWS Security Hub. You will research threats, develop markers, and build rules across large-scale data sources to improve visibility and defense for customers on AWS and other clouds.

You will work with security, engineering, and product teams to shape analysis, leverage ML/LLM capabilities, and automate responses.

Qualifications

  • 3+ years programming in Python, Ruby, Go, Java, Swift, .Net, C++ or similar
  • 2+ years scripting and security code review in a non-internship
  • 2+ years troubleshooting logs and automating tasks via command line

Responsibilities

  • Research emerging threats to develop new detection ideas
  • Build high-confidence markers and rules to correlate criticality across data sources
  • Collaborate with engineering and product teams to shape analysis and visibility into threats and vulnerabilities
  • Develop methods to analyze detections at scale

Skills

Python
Go
Java
Linux/Unix
Cloud concepts
Threat modeling
Scripting

Education

Bachelor's degree in computer science or equivalent
Bachelor's degree in STEM or IT Security related field
2+ years IT Security experience

Tools

AWS Developer Tools
Linux command line tools

Job description

Are you excited about advancing the state of threat detection, correlation and
response at scale to mitigate risk from an ever-evolving threat landscape for a
diverse range of customers?

The AWS Security Hub team is looking for a highly motivated Security Engineer to
join our team. In this role, you will research emerging threats to develop new
criticality and posture management ideas and build high-confidence markers and
rules that correlate criticality across a diverse set of conditions from
large-scale data sources. You will work closely with engineering and product
teams to shape the analysis, context and inference that drive visibility into
the most critical threats and vulnerabilities for AWS customers operating on AWS
and other cloud providers. You will also develop innovative methods utilizing
the latest techniques to analyze detections at scale. Your expertise will help
defend the data of Amazon's millions of customers against the most critical
threats.

Basic qualifications
  • Experience evaluating threats and vulnerabilities, assigning criticality based on impact, and developing response automation
  • Experience scripting with Python, Perl, Bash or PowerShell
  • Experience with software development for the cloud using java and AWS Developer Tools
  • Knowledge of web protocols, common attacks, and Linux/Unix tools and architecture
  • Knowledge of cloud computing concepts and design considerations for AWS, Azure and GCP
  • 2+ years of non academic experience in any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
Preferred qualifications
  • Experience with Machine Learning and Large Language Model fundamentals, including architecture, training/inference lifecycles, and optimization of model execution, or experience leading and influencing your team or organization
  • Experience using AI to automate security assessment work flows, implement LLMs and perform agentic threat detection and remediation
  • Experience with AI-driven development and verification
A day in the life

Most days you\'ll be heads-down building and tuning evaluations, digging into resource analysis and log data to figure out what data markers looks like and how to reliably assess impact. You\'ll spend time reading up on the latest threats and turning that research into something actionable. You\'ll also work on advancing how we assess threats, whether that\'s prototyping new approaches using machine learning or generative AI, improving enrichment pipelines, or finding ways to scale what we do. It\'s a mix of deep technical work and close collaboration with security teams across the organization.

About the team

At AWS Security Hub, security is central to maintaining customer trust and protecting customer cloud environments. Our organization is responsible for creating and maintaining a high bar for security analysis across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of customer environments. Basic Qualifications: - 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience - 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience - 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience - Bachelor\'s degree in computer science or equivalent - Bachelor\'s degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security - Bachelor\'s degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience - Knowledge of networking protocols such as HTTP, DNS and TCP/IP - Knowledge of industry-based security vulnerabilities and remediation techniques - Experience in scripting, programming, and security code reviewing in a common programming language (non-internship) - Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience) Preferred Qualifications: - 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience - 2+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience - Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks - Knowledge of networking protocols, to include HTTP(S), DNS, and TCP/IP - Experience with AWS products and services - Experience with programming languages such as Python, Java, C++ - Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C++ - Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you\u2019re applying in isn\u2019t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, MA, Boston - 159,300.00 - 202,400.00 USD annually USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Correlation and Response, AWS Security Hub
Security Engineer, Correlation and Response, AWS Security Hub

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,300 - 202,400
Health insurance
401(k) matching
Paid time off
+1
Security Engineer, Correlation and Response, AWS Security Hub
Security Engineer, Correlation and Response, AWS Security Hub

Amazon Web Services (AWS) • Boston (MA)

On-site
USD 159,300 - 202,400
Security Engineer, Correlation and Response, AWS Security Hub
Security Engineer, Correlation and Response, AWS Security Hub

Amazon • Boston (MA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Security Engineer, Correlation and Response, AWS Security Hub
Security Engineer, Correlation and Response, AWS Security Hub

Amazon • Seattle (WA)

On-site
USD 159,300 - 202,400
Sign-on payments
RSUs
Health insurance
+1
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 202,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Socket.dev • Austin (TX)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 159,000 - 202,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon • Arlington (VA)

On-site
USD 159,000 - 202,000
Security Engineer II, AWS Cloud Security Response
Security Engineer II, AWS Cloud Security Response

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 203,000
Security Engineer, AWS Security Hub, Security Services (S2)
Security Engineer, AWS Security Hub, Security Services (S2)

Amazon Web Services (AWS) • New York (NY)

On-site
USD 159,000 - 213,000