DESCRIPTION
AWS Trust and Safety (T&S) Risk & Response (R&R) is seeking a motivated Security Engineer with a strong background in incident response, threat investigation, and developing solutions to security issues. As a Security Engineer in R&R, you will employ your technical skills to develop solutions to complex and ambiguous security-related events originating from AWS resources that threaten the confidentiality, integrity, and availability of other AWS customers, the AWS network, or external internet users. You will build proofs of concept and develop tooling/automation solutions that help T&S and AWS scale with the evolving threat landscape.
T&S is the primary organization within AWS responsible for mitigating customer resources that violate the AWS AUP. We work closely with AWS service teams to determine appropriate mitigation actions and act as the customer facing outreach team on their behalf.
Key job responsibilities:
You are a technical leader within the T&S organization. You must understand the mechanics of how security incidents occur in the cloud, understand the mitigation options, and provide guidance to frontline T&S employees in response to violations of the AUP.Use SQL and Python or similar scripting languages to automate tasks and retrieve data to identify trends in abuse.You will engage autonomously with AWS customers, programs, and services to create, build, and innovate security operations.Communicate ideas effectively, both verbally and in writing, to all types of audiences from front line employees to AWS VPs.Complete projects that contribute to the objectives and goals that strive to meet our strategic vision for the team.Partnering effectively with customers and stakeholders. You will help establish a roadmap and successfully deliver engineering solutions that drive towards accomplishing the team's mission.Work effectively with customers, leaders, and other engineering teams. You must foster a constructive dialogue, harmonize discordant views, and lead the resolution of contentious issues (influence and build consensus).Proactively identify risks and bring them to the attention of your manager, customers, and stakeholders with plans for mitigation before they become larger events.You will be Amazon's voice in technical security engagements with customers addressing abuse.Collect, analyze, and document information to author threat reports to drive scalable mitigation and remediation actions.Provide situational awareness on the current threat landscape and the TTPs associated with specific threats to our business, including ongoing malware campaigns.Collect data from intelligence communities, threat intelligence platforms, open source data repositories, and other sources to analyze TTPs and anomalies.Drive operational excellence and efficiency in everything you do, whether by researching new, or scaling up existing capabilities, creating effective mechanisms, and automating day-to-day tasks.Participate in scheduled 24/7 on-call duties. BASIC QUALIFICATIONS 5+ years' experience in areas such as cloud service infrastructure, cloud security, networking, computer engineering.3+ years' experience with focus in areas such as systems, network, web protocols, and/or application security AND 2+ years' experience with SQL or other query languages.Knowledge of current security trends, threats, and mitigation OR Previous experience on a Security Operations team, or experience coordinating responses to security incidents.Demonstrable proficiency in Python required. Other languages are a plus but not required (Go, Ruby, Shell/Bash scripting, Java, Javascript/TypeScript, Rust, etc).Understanding of industry standard threat frameworks (Lockheed Martin Cyber Kill Chain, Diamond Model, MITRE ATT&CK).Strong knowledge of web protocols and an in-depth knowledge of Linux/Unix tools and architecture.Strong knowledge of Computer Science fundamentals, including; data structures, object-oriented programming, design, and analysis of algorithms. PREFERRED QUALIFICATIONS A MS degree in Computer Science, MIS, Computer Engineering, or 8+ years' equivalent technology experience.5+ years global analysis and threat mitigation background.5+ years scripting/programming experience: Python, C, C++, Java, Ruby, and/or PowerShell.3+ years of experience building with and securing AWS cloud services such as Lambda, EC2, and S3.Experience with virtualization technologies, familiarity with AWS and GuardDuty services is highly valued in particular.One or more professional network and security certifications such as Security+, CEH, CCNA, GSEC, CISA or CISSP (or equivalent work experience).Extensive knowledge of internet security issues and threat landscape. Amazon is an equal opportunities employer, and we value your passion to discover, invent, simplify and build. We welcome applications from all members of society irrespective of age, sex, disability, sexual orientation, race, religion or belief.
#J-18808-Ljbffr