Description AWS Security Incident Response is looking for technical Security Engineers that are passionate about learning new concepts and work well within a team environment to keep customers secure. We value engineers that can work through ambiguity to identify suspicious activity, lead security response, and can explain technical security concepts to non-technical audiences. Key job responsibilities Hold or be able to attain an Australian Government Security Vetting Agency clearance (see Respond to threat findings that indicate unauthorized activity has occurred Identify and recommend solutions that improve or expand AWS SIR capabilities, security automation Providing security engineering solutions and support during customer-facing incidents, proactively considering the prevention of similar incidents from occurring in the future Working alongside and mentoring information security engineers to improve security, reduce and quickly address risk Identify, evaluate and communicate security threats, risks and vulnerabilities, and propose recommended remediation for security issues Track and report on the effectiveness of AWS detective controls such as Amazon GuardDuty and partner products such as CrowdStrike Falcon or Wiz Defend Develop processes and policies to increase security response effectiveness On‑call support: This role requires periodic on‑call responsibilities including weekends A day in the life As a Security Engineer in AWS Security Incident Response, your responsibilities include monitoring networks and systems for potential threats, performing triage for security alerts, documenting suspicious activity, and reporting issues so they can be adequately handled. You will work alongside our security engineers and partner teams to perform daily threat detection and incident response, using the full capability of AWS technologies and services to detect and mitigate cyber threats at a massive scale and help protect AWS Customers. You should also enjoy learning about the most up‑to‑date new technologies and procedures to protect information systems and data. About the team AWS Security Incident Response provides 24/7 threat monitoring, investigation, and response across customer’s AWS environments. The service enhances existing security capabilities by providing security monitoring for all native AWS services and supports vendor agnostic detective and protective controls to provide holistic security controls for customers. This is done by leveraging data on common attack techniques to enhance detective controls and incident response, then building auto‑remediation capabilities to minimise disruption to customer workloads. When a security event does happen, you will be there to provide guidance. Basic Qualifications 3+ years of troubleshooting systems issues, analysing logs, or automating basic tasks using command line tools (non‑internship) experience 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object‑oriented language experience 3+ years of any combination of the following: threat modelling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience Bachelor's degree in computer science or equivalent Knowledge of networking protocols such as HTTP, DNS and TCP/IP Knowledge of industry‑based security vulnerabilities and remediation techniques Experience in security operations, risk management, and incident response Preferred Qualifications Experience with AWS services or other cloud offerings Experience triaging security alerts, front‑line analysis, and escalation GCIH (GIAC Certified Incident Handler), GSEC (GIAC Security Essentials), Security+, CISSP, CISA, CISM or other security certification Experience with AI/ML technologies Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner. #J-18808-Ljbffr
Security Engineer, Aws Security Incident Response
AMAZON
council of the city of sydney, council of the city of sydney
Published 4 days ago
Report job
Similar jobs
Part Time Work From Home Focus Group Panelist. Call Centre Agent Experience Not Required
APEX FOCUS GROUP LLC
Permanent