Job ID: | Amazon Web Services Australia Pty Ltd Applicants must be Australian citizens and hold or be eligible to obtain an Australian Government Security Clearance, with the ability to successfully complete an Organisational Suitability Assessment. For more information regarding security clearances please visit Amazon Web Services (AWS) is the leading cloud service provider, providing virtualised infrastructure, storage, networking, messaging, and many other services to customers all over the world. AWS runs a globally distributed environment, operating at massive levels of scale. Businesses, from start-ups to enterprises to large government customers, run their operations and applications on AWS’ highly secure infrastructure. Key job responsibilities Hold or be able to attain an Australian Government Security Vetting Agency clearance (see Perform security event monitoring, incident management and response. Develop, tune, and maintain SIEM detections, dashboards, and correlation rules. Conduct proactive threat hunting and analysis to identify suspicious behaviour. Investigate, respond and be the escalation point for security alerts and incidents. Support the integration and optimisation of security data sources within SIEM platforms. Contribute to continuous improvement of SOC processes and automation initiatives, including authoring SOC SOPs and runbooks. Apply frameworks such as MITRE ATT&CK and NIST in concert with the ISM and PSPF to guide security operations. Perform on-call duties as required, out of business hours. A day in the life Responding to new detections: Monitor security alerts in real-time, investigate suspicious activities by analysing logs and network traffic, determine if incidents are legitimate threats or false positives, and coordinate immediate response actions including containment and remediation when threats are confirmed. Write security detections: Develop and implement custom detection rules based on emerging threat intelligence, tune existing security signatures to reduce false positives while maintaining coverage, and create automated alerts for specific attack patterns or indicators of compromise relevant to the organization's environment. Threat hunt: Proactively search through network logs, endpoint data, and system activities for signs of advanced persistent threats that may have evaded automated detection systems, using threat intelligence feeds and behavioural analysis to identify potential security breaches before they cause significant damage. Work with service teams on security issues: Collaborate with IT, network, and application teams to remediate identified vulnerabilities, coordinate security patches and system hardening efforts, provide security guidance during incident response, and ensure proper implementation of security controls across all infrastructure components. Generate metrics and dashboards: Create and maintain security performance indicators including incident response times, threat detection rates, and system availability metrics, develop executive-level reports summarizing security posture and trends, and build real-time dashboards for continuous monitoring of security operations effectiveness. Basic Qualifications 3+ years experience as a SOC Analyst or Defensive Cyber Role. Experience with SIEM tools (e.g., Splunk, Microsoft Sentinel, Sumo Logic, or similar). Good understanding of incident response, threat detection, and security monitoring. Good working knowledge of foundational systems and protocols e.g. HTTP, DNS, TCP/IP. Excellent analytical, problem-solving, and communication skills. Preferred Qualifications 5+ years experience as a SOC Analyst or Defensive Cyber Role. Demonstrated experience and application of incident response, threat detection, and security monitoring in high security environments. Strong technical working knowledge of key security domains, e.g. Cryptography, Identity & Access Management and Application Security. Experience with AWS products and services. Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legally protected status. #J-18808-Ljbffr
Security Engineer, Aws Security
AMAZON
council of the city of sydney, council of the city of sydney
Published 4 days ago
Report job
Similar jobs
Part Time Work From Home Focus Group Panelist. Call Centre Agent Experience Not Required
APEX FOCUS GROUP LLC
Permanent