Skip to main content
Back to results

Security Engineer I, AWS Security Incident Response

Amazon Web Services, Inc. · Seattle, WA · Systems Security Engineering

Full-time

About the role

As part of the AWS Applied AI Solutions organization, we have a vision to provide business applications, leveraging Amazon’s unique experience and expertise, that are used by millions of companies worldwide to manage day-to-day operations. We will accomplish this by accelerating our customers’ businesses through delivery of intuitive and differentiated technology solutions that solve enduring business challenges. We blend vision with curiosity and Amazon’s real-world experience to build opinionated, turnkey solutions. Where customers prefer to buy over build, we become their trusted partner with solutions that are no-brainers to buy and easy to use.

Are you passionate about protecting customers at scale? AWS Security Incident Response is growing to meet increasing customer demand, and we're looking for a Security Engineer I to join the team. In this role, you will investigate suspicious activity, drive security response efforts, and communicate technical findings to both technical and non-technical audiences. You take the lessons learned from security response to enhance existing automations. The team is actively building AI-augmented investigation tools and new forensic capabilities, making this a great time to join where your work directly improves secure outcomes for AWS customers.

Key job responsibilities
- Respond to threat findings that indicate unauthorized activity, performing triage and escalating issues as appropriate
- Identify, evaluate, and communicate security threats, risks, and vulnerabilities, and recommend remediation actions to reduce risk
- Contribute to security automation, scripting, and tooling efforts — including AI-augmented investigation tools — that improve the team's triage and response capabilities
- Track and report on the effectiveness of AWS detective controls such as Amazon GuardDuty and partner products such as CrowdStrike Falcon or Wiz Defend
- Develop and refine runbooks, processes, and policies that strengthen security response effectiveness

A day in the life
You will start your day reviewing alerts and triaging potential threats across customer environments, working alongside fellow security engineers, service partner teams, and Trust & Safety Abuse. You might spend the morning investigating a suspicious finding using AWS-native tools, then shift to documenting your analysis and coordinating remediation with the affected service team. Beyond daily response work, you may contribute to threat research, help improve triage using signals from security partners, or prepare threat intelligence briefings for customers.

About the team
AWS Security Incident Response is a team of security engineers and incident responders who provide 24/7 threat monitoring, investigation, and response for customers running workloads on AWS. The team takes signals from security partners and Trust & Safety Abuse to improve triage and prevent harm, protecting environments ranging from startups to large enterprises using services like Amazon GuardDuty and partner integrations. We are investing in AI-powered forensic tools and auto-remediation to keep pace with rapid customer growth. Team members regularly present at industry forums such as AWS re:Invent and deliver threat intelligence briefings to customers. You can grow through automation development, threat research, partner work, or contributing to internal AWS security tooling. If you want to join an inclusive team that is shaping how AWS customers stay secure, we'd love to hear from you.

Diverse Experiences

Amazon values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why AWS

Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that’s why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve in the cloud.

Inclusive Team Culture

Here at AWS, it’s in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity and AmazeCon conferences, inspire us to never stop embracing our uniqueness.

Mentorship and Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.

Basic qualifications

- 2+ years of web protocols, common security attacks, and remediation (non-internship) experience
- Bachelor's degree in Engineering, Computer Science, or a related field
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
- Experience with web protocols, common security attacks, and remediation (non-internship)
- Experience solving basic problems by writing code or scripts with some assistance

Preferred qualifications

- Experience with AWS services or other cloud offerings
- * Experience with AWS services in a security context (e.g., Amazon GuardDuty, AWS CloudTrail, AWS Security Hub, AWS IAM)
- * Familiarity with how AI/ML systems work, including concepts like confidence scoring, feedback loops, and training data
- * Experience contributing to detection engineering, security automation, or building tools that improve security operations

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.



USA, WA, Seattle - 136,000.00 - 184,000.00 USD annually