Sr Security Engineer, Perimeter Threat Research Team (AWS)

Amazon

Seattle (WA)

On-site

USD 178,400 - 226,700

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
RSUs

Job summary

Amazon is seeking a Sr Security Engineer for the Perimeter Threat Research Team in Seattle to protect AWS global infrastructure. You will reverse engineer malware, craft security data systems, mentor engineers, and lead designs in an agile setting.

Expect collaboration with software, network, and security teams, plus advanced threat intelligence work. The role requires strong web security expertise, MITRE ATT&CK awareness, and experience with SIEMs.

Qualifications

  • Bachelor’s degree required.
  • 5+ years of IT Security experience.

Responsibilities

  • Learn how our products work today, and where we want to take them in the future.
  • Help craft and build out threat data gathering security systems at scale.
  • Stay on top of cyber security trends and mentor other engineers.
  • Act as a technical lead, influencing other engineers’ designs and coding deliverables.
  • Work in an agile development environment, collaborating closely with software engineers.
  • Have fun in a challenging but rewarding environment.

Skills

Malware reverse engineering
Threat hunting
Web application security
Scripting languages

Education

Bachelor’s degree

Tools

IDA Pro
Ghidra
x64dbg
Burp Suite
Wireshark
Zeek
NetFlow

Job description

Sr Security Engineer, Perimeter Threat Research Team

Job ID: 3186193 | Amazon Data Services, Inc.

AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. In other words, we’re the people who keep the cloud running. We support all AWS data centers and all of the servers, storage, networking, power, and cooling equipment that ensure our customers have continual access to the innovation they rely on. We work on the most challenging problems, with thousands of variables impacting the supply chain — and we’re looking for talented people who want to help.

You’ll join a diverse team of software, hardware, and network engineers, supply chain specialists, security experts, operations managers, and other vital roles. You’ll collaborate with people across AWS to help us deliver the highest standards for safety and security while providing seemingly infinite capacity at the lowest possible cost for our customers. And you’ll experience an inclusive culture that welcomes bold ideas and empowers you to own them to completion.

Key Responsibilities
  • Learn how our products work today, and where we want to take them in the future.
  • Help craft and build out threat data gathering security systems at scale.
  • Stay on top of cyber security trends and mentor other engineers.
  • Act as a technical lead, influencing other engineers’ designs and coding deliverables.
  • Work in an agile development environment, collaborating closely with software engineers.
  • Have fun in a challenging but rewarding environment.

The ideal candidate must demonstrate strong proficiency in malware reverse engineering, including the ability to analyze, disassemble, and deconstruct malicious software using industry-standard tools such as IDA Pro, Ghidra, and debuggers like x64dbg. Experience with static and dynamic analysis techniques is essential for identifying malware behavior, capabilities, and indicators of compromise.

A solid foundation in web application security is required, including expertise in identifying and mitigating vulnerabilities such as SQL injection, cross‑site scripting (XSS), and authentication flaws. Familiarity with OWASP methodologies and tools like Burp Suite is expected.

Candidates must possess advanced threat hunting capabilities, leveraging hypothesis‑driven approaches and behavioral analytics to proactively detect adversarial activity within enterprise environments. Proficiency in crafting custom detection rules and queries across SIEM platforms is essential.

A comprehensive understanding of network security is required, with a strong emphasis on DDoS mitigation and botnet research. The candidate must have experience analyzing botnet infrastructure, understanding command‑and‑control communication protocols, and identifying botnet propagation techniques. Proficiency in traffic analysis, volumetric attack pattern recognition, and DDoS defense strategies is essential. Hands‑on experience with packet capture tools such as Wireshark, Zeek, and NetFlow analysis platforms is expected, along with the ability to research emerging botnet families and their evolving attack vectors.

A working knowledge of threat intelligence frameworks such as MITRE ATT&CK and familiarity with STIX/TAXII standards is preferred.

About the Team

The AWS Perimeter Protection Threat Research Team produces actionable threat intelligence that drives AWS security and networking services, including AWS Shield, AWS WAF, AWS Firewall Manager, and Network Firewall. Our diverse team of security researchers and engineers operates advanced deception technology and threat intelligence systems to identify, track, and analyze bad actors as they continuously evolve their tactics, techniques, and procedures. We proactively monitor emerging threats across some of the largest distributed networks in the world, transforming raw intelligence into meaningful insights that strengthen AWS defenses.

Basic Qualifications
  • Bachelor’s degree.
  • 5+ years of IT Security experience.
Preferred Qualifications
  • Knowledge of network, system, and web application attacks and mitigations.
  • Experience in web security, or experience in managing firewalls and experience managing full application stacks from the OS up through custom applications.
  • Experience communicating technical concepts to a non‑technical audience.
  • Experience in written and verbal communication with the ability to present complex technical information in a clear and concise manner to executives and non‑technical leaders.
  • Experience in one or more scripting languages (e.g., Python, Ruby, Perl).

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is 178,400.00 - 226,700.00 USD annually. Your Amazon package will include sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Enterprise Protection Program - Account Misuse Team
Security Engineer, Enterprise Protection Program - Account Misuse Team

Socket.dev • Arlington (VA)

On-site
USD 136,000 - 184,000
Security Engineer, Enterprise Protection Program - Account Misuse Team
Security Engineer, Enterprise Protection Program - Account Misuse Team

Amazon • Arlington (VA)

On-site
USD 136,000 - 184,000
Application Security Engineer, AWS Proactive Security
Application Security Engineer, AWS Proactive Security

Amazon • Herndon (VA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
RSUs
+3
Security Engineer, Enterprise Protection Program - Account Misuse Team
Security Engineer, Enterprise Protection Program - Account Misuse Team

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon • Arlington (VA)

On-site
USD 159,000 - 202,000
Security Engineer, AppSec, Stores Security
Security Engineer, AppSec, Stores Security

Amazon • Seattle (WA)

On-site
USD 136,000 - 184,000
Senior Security Engineer, Proactive Security
Senior Security Engineer, Proactive Security

Amazon • Seattle (WA)

On-site
USD 178,000 - 227,000
Security Engineer, Correlation and Response, AWS Security Hub
Security Engineer, Correlation and Response, AWS Security Hub

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 202,000
Software Dev Engineer, Shield
Software Dev Engineer, Shield

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 144,000 - 194,000
Sign-on bonus & RSUs
Health insurance
Benefits package
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI
Security Intelligence Engineer, Incident Response Threat Intelligence, ACTI

Amazon • Herndon (VA)

On-site
USD 159,000 - 202,000
Health insurance
RSUs