Security Engineer I, Threat Hunting, Security Incident Response Team (SIRT)

Amazon

Arlington (VA)

On-site

USD 136,000 - 184,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Paid time off
401(k) matching
RSUs
Sign-on bonus

Job summary

Amazon in Arlington, VA is seeking a Security Engineer I on the Threat Hunting team within SIRT to proactively identify and mitigate undetected threat activity at scale.

You will develop detection capabilities, work with incident response, and build scripts for petabyte-scale analysis. The role requires 2+ years of security experience and a BS in a related field; AWS experience preferred.

Qualifications

  • 2+ years of security experience with web protocols and remediation.
  • Bachelor’s degree in Engineering, CS, or related field.
  • Experience solving problems by writing code or scripts.

Responsibilities

  • Query large data stores to identify threat activities impacting customers.
  • Support investigations with incident response teams.
  • Analyze security logs to detect threat behaviors and devise hunting strategies.
  • Author scripts and build capabilities for petabyte-scale threat hunting.
  • Participate in on-call rotations and assist outside business hours.

Skills

Web protocols
Security remediation
Scripting

Education

Bachelor's degree in Engineering/CS

Tools

AWS

Job description

Security Engineer I, Threat Hunting, Security Incident Response Team (SIRT)

Security’s Threat Hunting team is looking for a Security Engineer who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role you will work alongside other Threat Hunting engineers to proactively identify and eliminate threats wherever they may exist. Our team hunts for adversarial activity using a variety of tools, methods, intelligence, and techniques, working hands‑on with security logs and encouraging creative development of innovative techniques to illuminate threat activities. With your technical expertise you will solve security challenges at scale and help protect the applications powering the most sophisticated e‑Commerce platform ever built.

Key Responsibilities
  • Query big data repositories to identify threat activities that pose a risk to Amazon customers and data.
  • Work alongside incident response teams and provide direct support to ongoing investigations and efforts to identify and contain security events.
  • Analyze security log data, identify threat behaviors, and develop custom threat detection and threat hunting strategies.
  • Author scripts and build custom capabilities to uncover threats and enable threat hunting operations at petabyte scale.
  • Participate in an on‑call rotation and provide ad hoc support to internal customers during non‑business hours.
A Day in the Life
  • Query, collate, and analyze machine‑generated data for indications of digital threat activities.
  • Develop database searches to extract security artifacts and threat signals from large and diverse datasets.
  • Work alongside other engineers to improve security and reduce operating risk for our customers.
  • Monitor cybersecurity media, blog posts, and other sources to maintain awareness of the threat landscape.
  • Assist in designing and developing innovative capabilities to identify cyber threat activities at scale.
  • Work individually and/or as a team on high‑priority security issues.
About the Team

Amazon’s Threat Hunting team is a component of the Security Incident Response Team (SIRT) and is responsible for proactively seeking out threat activities that pose a risk to our customers and business operations. Our threat hunters work alongside incident response engineers to support ongoing security investigations in a dynamic environment with shifting priorities.

Basic Qualifications
  • 2+ years of experience with web protocols, common security attacks, and remediation (non‑internship).
  • Bachelor’s degree in Engineering, Computer Science, or a related field.
  • Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent.
  • Experience solving basic problems by writing code or scripts with some assistance.
Preferred Qualifications
  • Experience with AWS services or other cloud offerings.

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit (https://amazon.jobs/content/en/how-we-hire/accommodations) for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is 136,000.00 – 184,000.00 USD annually. This package includes sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II, Security Incident Response Team (SIRT)
Security Engineer II, Security Incident Response Team (SIRT)

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
+2
Security Engineer, Enterprise Protection Program - Account Misuse Team
Security Engineer, Enterprise Protection Program - Account Misuse Team

Socket.dev • Arlington (VA)

On-site
USD 136,000 - 184,000
Security Engineer II, Security Incident Response Team (SIRT)
Security Engineer II, Security Incident Response Team (SIRT)

Amazon • Arlington (VA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
Security Engineer, Enterprise Protection Program - Account Misuse Team
Security Engineer, Enterprise Protection Program - Account Misuse Team

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
Sr Security Engineer, Perimeter Threat Research Team (AWS)
Sr Security Engineer, Perimeter Threat Research Team (AWS)

Amazon • Seattle (WA)

On-site
USD 178,400 - 226,700
Health insurance
RSUs
Security Engineer, Enterprise Protection Program - Account Misuse Team
Security Engineer, Enterprise Protection Program - Account Misuse Team

Amazon • Arlington (VA)

On-site
USD 136,000 - 184,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon • Arlington (VA)

On-site
USD 159,000 - 202,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Socket.dev • Austin (TX)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI

Amazon • Arlington (VA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
RSU program
Senior Security Engineer, Proactive Security
Senior Security Engineer, Proactive Security

Amazon • Austin (TX)

On-site
USD 178,000 - 227,000
Health insurance
401(k) matching
Paid time off
+1