Senior Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI

Amazon

Herndon (VA)

On-site

USD 143,300 - 247,600

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Benefits
Financial Benefits
Equity Options
Sign-on Payments

Job summary

An established industry player is seeking a Senior Security Intelligence Engineer to join their dynamic team. This role is pivotal in developing actionable intelligence on advanced cyber threats, supporting incident response teams and driving the enhancement of security capabilities. The ideal candidate will have a deep understanding of cyber threat actors and their methodologies, along with experience in scripting and automation. You will analyze indicators, create security techniques, and contribute to the organization's understanding of the threat landscape. Join a diverse and inclusive workplace where your expertise will make a significant impact on safeguarding company assets and employees.

Qualifications

  • 5+ years of experience in cyber threat analysis and incident response.
  • Strong scripting skills in Python and experience with SQL.

Responsibilities

  • Analyze malicious artifacts and uncover trends in large data sets.
  • Create security techniques and automation for high-speed operations.

Skills

Cyber Threat Analysis
Scripting and Automation (Python)
SQL and Database Querying
Digital Forensics
Network Security
Application Security
Malware Analysis

Education

Bachelor's in Computer Science
Master's in Computer Science

Tools

AWS Services
Threat Intelligence Platforms (TIPs)

Job description

Senior Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI

Job ID: 2866756 | Amazon.com Services LLC

We are open to hiring candidates to work out of one of the following locations:
Annapolis Junction, MD, USA | Arlington, VA, USA | Austin, TX, USA | Herndon, VA, USA | New York, NY, USA | Seattle, WA, USA

The Threat Intelligence for Global Enterprise Response (TIGER) team, part of Amazon Cyber Threat Intelligence (ACTI), is responsible for developing actionable intelligence on advanced cyber threats to Amazon employees and company assets. Our intelligence supports incident response teams, red teams, detections teams and teams working to prevent financial loss to the company. We obtain indicators and intelligence from a variety of internal and external sources and use that information to develop an understanding of sophisticated actors and their tools, techniques, and procedures. We then leverage that understanding to proactively identify and mitigate malicious activity.

The successful candidate will analyze indicators to generate actionable intelligence and insight into current threats. As a Security Intelligence Engineer, you will help enhance our capabilities by formulating new analytic techniques and working across teams to drive the supporting capabilities. A deep understanding of current cyber threat actors and TTPs as well as experience performing question-driven analysis is required. You will leverage your understanding of networking- and host-based indicators, digital forensics, and database querying as you investigate incidents and threats as well.

Key job responsibilities
  1. Perform deep dive analysis of malicious artifacts.
  2. Analyze large and unstructured data sets to discover new threats, uncover trends, and identify anomalies indicative of malicious activities.
  3. Create security techniques and automation for internal use that enable you and others to operate at high speed and broad scale.
  4. Contribute to Amazon's understanding of the current threat landscape and the techniques, tactics, and procedures associated with specific threats.
  5. Draft and publish finished written threat intelligence products based on findings.
  6. Periodic on-call responsibilities.
BASIC QUALIFICATIONS
  • BS degree in Computer Science, Management of Information Systems (MIS), Computer Engineering, or similar degree, or 5+ years equivalent technology experience without a degree
  • 5 years experience with tracking high-sophistication cyber threat groups
  • 5 years experience across system security, network security, application security, and/or digital forensics
  • 2 years experience building scripting and automation using Python or similar programming languages
  • 2 years experience with SQL or other relational database query languages.
PREFERRED QUALIFICATIONS
  • MS degree in Computer Science, Management of Information Systems (MIS), Computer Engineering, or similar degree.
  • Strong understanding of Windows, Linux, and or OS X internals
  • Experience with malware analysis, network flow analysis, and large scale data analysis.
  • Experience with modern threat intelligence platforms (TIPs), especially the Vertex Project's Synapse, and their APIs
  • Experience building and conducting analysis leveraging AWS services.
  • Experience building automated tools in the Python programming language.

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit this link for more information.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit this link.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI

Socket.dev • Austin (TX)

On-site
USD 159,000 - 202,000
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI

Amazon • Austin (TX)

On-site
USD 159,000 - 202,000
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI

Amazon • Herndon (VA)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
Senior Intelligence Analyst, Amazon Cyber Threat Intelligence
Senior Intelligence Analyst, Amazon Cyber Threat Intelligence

Amazon • Seattle (WA)

On-site
USD 119,000 - 209,000
Health insurance
401(k) matching
Paid time off
+1
Software Development Engineer II - Threat Intelligence Systems, ACTI Engineering
Software Development Engineer II - Threat Intelligence Systems, ACTI Engineering

Socket.dev • Austin (TX)

On-site
USD 144,000 - 194,000
Senior Intelligence Analyst, Amazon Cyber Threat Intelligence
Senior Intelligence Analyst, Amazon Cyber Threat Intelligence

Amazon • Maryland

On-site
USD 119,000 - 209,000
Health insurance
401(k) matching
Paid time off
Software Development Engineer II - Threat Intelligence Systems, ACTI Engineering
Software Development Engineer II - Threat Intelligence Systems, ACTI Engineering

Amazon • Herndon (VA)

On-site
USD 144,000 - 194,000
Software Development Engineer II - Threat Intelligence Systems, ACTI Engineering
Software Development Engineer II - Threat Intelligence Systems, ACTI Engineering

Amazon • Arlington (VA)

On-site
USD 144,000 - 194,000
RSUs
Software Development Engineer II - Threat Intelligence Systems, ACTI Engineering
Software Development Engineer II - Threat Intelligence Systems, ACTI Engineering

Amazon • Maryland

On-site
USD 144,000 - 194,000