Systems Engineer, AWS Incident Response

Amazon

Seattle (WA)

On-site

USD 105,000 - 160,000

Full time

3 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Amazon is seeking a Systems Engineer for AWS Incident Response to lead high-severity incident calls, triage failures across distributed systems, and coordinate resolver teams. You will drive mitigation in real time while obsessing over metrics, detection analysis, and dashboards to surface problems before customers notice.

You will gain breadth across AWS services, contribute to operational improvements, and explore coding projects to accelerate incident response and reduce toil.

Qualifications

  • 3+ years of systems engineering, or 3+ years in technical support
  • Experience communicating with technical and non-technical audiences, including senior leadership
  • Experience scripting in Bash or Python, or other modern languages
  • Understanding of Linux OS, networking fundamentals, and distributed systems
  • Experience with operational monitoring, alerting, and metrics (CloudWatch, Datadog, Grafana, or equivalent)
  • Proven ability to troubleshoot complex problems across multiple systems or services

Responsibilities

  • Lead high-severity incident response calls end to end with cross-team coordination
  • Own and run operational health reviews and build dashboards and metrics
  • Improve detection accuracy and speed through proactive mechanisms
  • Deep-dive operational data to identify systemic issues and measure response effectiveness
  • Identify gaps in processes and tooling to reduce time-to-detection and time-to-mitigation
  • Apply automation and AI to accelerate incident response and reduce toil
  • Collaborate with service teams to drive corrective actions to completion
  • Mentor peers in technical and operational areas

Skills

Incident response leadership
Cloud monitoring
Scripting (Bash/Python)
Linux & networking
Troubleshooting complex systems

Tools

CloudWatch
Datadog
Grafana
Bash
Python
Terraform/CloudFormation

Job description

Job ID: 10541981 | Amazon Development Center U.S., Inc.

As a Systems Engineer on AWS Incident Response, you will be on the front line of AWS incident response. You will lead high-severity calls, triage complex failures across distributed systems, coordinate resolver teams, and drive incidents to mitigation in real time while millions of customers depend on the outcome. Between incidents you will obsess over metrics and detection analysis, building dashboards and mechanisms that surface problems before customers notice, and you will drive operational improvements that make the incident management ecosystem faster and more accurate.

You will make real-time decisions under pressure, deep-diving the largest and most complex technical environment in the world. You will develop expertise across AWS services, networking, and infrastructure, building a breadth of knowledge that few roles offer. Your scope spans all of AWS rather than a single service. You will own operational processes end to end and use data to find the next improvement in how we detect and mitigate faster. You will also have the opportunity to grow your development skills by taking on coding projects that accelerate incident response and reduce toil.

This role includes participation in an on-call rotation covering weekdays, weekends, and holidays. On‑call shifts fall within your local daytime hours.

Key job responsibilities
  • Lead high‑severity incident response calls end to end: assess impact, coordinate resolvers across AWS service teams, communicate clearly under pressure, manage escalations, and drive the incident to mitigation with documentation throughout.
  • Own and run operational health reviews, and build and maintain the dashboards, metrics, and monitoring that surface trends before they become incidents.
  • Improve detection accuracy and speed. Identify patterns across events and build proactive mechanisms that prevent recurrence.
  • Deep‑dive operational data to find systemic issues, measure response effectiveness, and prioritize improvements against what the data shows is degrading.
  • Identify gaps in operational processes, documentation, and tooling, and build or improve mechanisms that reduce time‑to‑detection and time‑to‑mitigation.
  • Apply scripting, automation, and generative AI to accelerate incident response and reduce toil, including where AI can augment human judgment during an incident or surface insight from operational data at scale.
  • Work with service teams so that learnings from each incident drive corrective actions to completion, closing the loop between what broke and what gets fixed.
  • Mentor peers in your areas of technical and operational strength.
A day in the life

When you are on call, incidents take priority. You join the incident bridge, assess the scope of impact from real‑time metrics and dashboards, engage the resolver teams that own the affected services, and drive the event to mitigation, escalating when progress stalls. Off‑call, you work to reduce time‑to‑detection and time‑to‑mitigation: deep‑diving recent events for detection that lagged the impact or alarms that trigger without customer impact, correcting the signal behind them, leading operational health reviews, driving other teams' corrective actions to completion, and owning projects that strengthen AIR's detection and incident management, including automation you can build yourself.

About the team

AWS Incident Response (AIR), part of the AWS Resilience organization, ensures high availability of AWS. When major incidents hit, AIR leads the response, coordinating resolver teams across AWS and driving mitigation. We move fast, but not carelessly, obsessing over observability of the cloud and continuously improving our detection and response speed and accuracy. Each incident feeds improvements to our detection, processes, and tooling, making the next one shorter or preventing it entirely. This is a high‑visibility, high‑impact role with a global view of AWS health that few teams get to see.

Basic Qualifications
  • 3+ years of systems engineering, or 3+ years of technical support experience
  • Experience in written and verbal communication skills to communicate with technical and non‑technical audiences, including senior leadership
  • Experience scripting in one or more language (e.g. Bash, Python, Perl, Ruby), or experience scripting in modern programming languages
  • Understanding of operating systems (Linux), networking fundamentals, and distributed systems
  • Experience with operational monitoring, alerting, and metrics (CloudWatch, Datadog, Grafana, or equivalent)
  • Demonstrated ability to troubleshoot complex technical problems spanning multiple systems or services
Preferred Qualifications
  • Familiarity with incident management tooling and workflows in a large‑scale production environment
  • Experience with AWS services and cloud infrastructure
  • Experience using generative AI or automation to solve operational problems or accelerate workflows
  • Track record of authoring post‑incident analyses (post‑mortems) and driving corrective actions to completion
  • Experience building operational dashboards, runbooks, or automation that improved team efficiency
  • Knowledge of infrastructure‑as‑code and deployment tooling, such as CDK, CloudFormation, Terraform, Ansible, or similar
  • Experience coordinating across globally distributed teams and time zones
  • Comfort operating with ambiguity and incomplete information, and a self‑starting approach to identifying what needs doing

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, WA, Seattle - 104,500.00 - 160,000.00 USD annually

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Systems Engineer, AWS Incident Response
Systems Engineer, AWS Incident Response

Socket.dev • Seattle (WA)

On-site
USD 94,000 - 115,000
Senior Software Development Engineer, AWS Resilience, Incident Prevention
Senior Software Development Engineer, AWS Resilience, Incident Prevention

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 168,000 - 227,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
Incident Management Engineer - bilingual (Mandarin & English), AWS Incident Detection and Response
Incident Management Engineer - bilingual (Mandarin & English), AWS Incident Detection and Response

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 96,000 - 160,000
Software Dev Engineer, AWS Resilience Hub
Software Dev Engineer, AWS Resilience Hub

Amazon • Portland (OR)

On-site
USD 143,700 - 194,400
Health insurance
401(k) matching
Paid time off
+1
Sr Technical Incident Manager, Amazon Leo
Sr Technical Incident Manager, Amazon Leo

Socket.dev • Redmond (WA)

On-site
USD 149,000 - 201,000
Health insurance
RSUs
Security Engineer I, AWS Security Incident Response
Security Engineer I, AWS Security Incident Response

Socket.dev • Seattle (WA)

On-site
USD 136,000 - 184,000
Incident Management Engineer (Korean/English bilingual), Incident Detection and Response
Incident Management Engineer (Korean/English bilingual), Incident Detection and Response

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 96,000 - 160,000
Health insurance
RSUs and sign-on bonus
401(k) matching
Software Dev Engineer, AWS Resilience Hub
Software Dev Engineer, AWS Resilience Hub

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 144,000 - 194,000
Health insurance
401(k) matching
Paid time off
+1
Security Engineer I, AWS Security Incident Response
Security Engineer I, AWS Security Incident Response

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 136,000 - 184,000
Health insurance
401(k) matching
Paid time off
+2