Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering undetected threat activities at petabyte scale. In this role, you will work alongside other Threat Hunting engineers to proactively identify and eliminate threats wherever they may exist.
Our Threat Hunting team hunts for adversarial activity using a variety of tools, methods, intelligence, and techniques. They work hands-on with security logs and are encouraged to be creative and develop innovative techniques to illuminate threat activities. With your technical expertise, you will be solving security challenges at scale and working to protect applications powering the most sophisticated e-Commerce platform ever built.
If you are someone who enjoys researching threats, diving deep into large datasets, and building innovative capabilities to solve everyday problems, we’d like to meet you. Your work will be essential to maintaining customer trust and delivering a delightful experience for our customers.
Key job responsibilities
- You will query and collate machine data to search for evidence of potentially damaging threat activities which pose a risk to Amazon customers and data.
- You will work alongside incident responders and support the investigation of ongoing security issues.
- You will reconstruct security events from log data and develop innovative approaches to identify threat actor tactics, techniques, and procedures (TTPs).
- You will build custom capabilities to uncover threats and enable threat hunting operations at scale.
- You will participate in an on-call rotation and provide ad hoc support to customers during non-business hours.
A day in the life
- Query, collate, and analyze machine-generated data for indications of cyber threat activities.
- Develop recurring database searches to extract security artifacts from large and diverse datasets.
- Work alongside other engineers to improve security and reduce operating risk for our customers.
- Monitor cybersecurity media, blog posts, and other sources to maintain awareness of the threat landscape.
- Assist in the development of innovative capabilities to identify cyber threats at scale.
- Work individually and/or as a team on high priority security issues.
About the team
Amazon’s Threat Hunting team is a component of the Security Incident Response Team (SIRT) and is charged with proactively seeking out threats which pose a risk to our customers and their data. Our threat hunters also work alongside incident response engineers to support ongoing security investigations. This team works in a dynamic environment with shifting priorities.
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training and Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
- BS in Computer Science, Cyber Security, or a related field of study or 6+ years of equivalent professional experience
- 3+ years of demonstrated experience in areas such as threat hunting, incident response, systems security, network security, or a related field.
- Proficiency in one or more scripting language (e.g. Python, Bash, PowerShell, Perl, etc.)
- 5+ years of demonstrated experience in areas such as threat hunting, incident response, systems security, network security, or a related field.
- Excellent written and verbal communication skills with the ability to adapt messaging to executive, technical, and non-technical audiences
- Technical depth in two or more specialties including: digital forensics, malware analysis, network security, application security, security intelligence, and security operations
- Experience triaging and developing security alerts and response automation, conducting front-line analysis, and providing escalation support.
- Familiarity/experience with AWS services and security concepts.
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.