Security Engineer, AWS Security Incident Response

Amazon.com Inc

Seattle, WA

JOB DETAILS
SKILLS
Amazon Web Services (AWS), Artificial Intelligence (AI), Artificial Intelligence (AI) Agents, Automation, Automation Systems, Coaching, Computer Security, Documentation, Follow Through, Forensic Science, Home Automation, Incident Response, Mentoring, On Call, Quality Management, Security Analysis, Security Attacks, Technical Leadership, Value Engineering
LOCATION
Seattle, WA
POSTED
30+ days ago

AWS Security Incident Response is looking for a Security Engineer who investigates with urgency, communicates with clarity, and turns every investigation into an opportunity to make the service smarter. You will perform hands-on security response for customers, work alongside AI-powered investigation agents daily, and feed what you learn back into the automation systems that protect all customers.

The AWS Security Incident Response team provides 24/7 security response through a follow-the-sun operating model. The service combines automated triage workflows, AI-powered investigation agents, and human security analysts to respond to threats across customer AWS environments at massive scale. Our AI systems autonomously resolve the majority of routine investigations within minutes. Every engineer on the team is expected to be fluent in how these AI systems work, provide feedback that improves their accuracy, and identify opportunities to extend their capabilities.

This is not a traditional security operations role. You will investigate security incidents hands-on, but equally important is what happens after the investigation: documenting patterns, proposing detection rules, providing structured feedback to AI agents, and building the automation that prevents the same issue from requiring human investigation again. We treat every investigation as a confirmed security incident until the data proves otherwise.

This position requires that the candidate selected be eligible to obtain a US Government security clearance.

Key job responsibilities

  • Investigate and respond to security findings and customer-reported security events using AI-powered investigation tools and manual forensic techniques
  • Perform CloudTrail forensics, log analysis, and threat intelligence correlation to determine the scope, impact, and root cause of security events in customer AWS environments
  • Get on calls with customers during active incidents to walk them through what was compromised and the specific containment steps to execute immediately
  • Work alongside AI investigation agents daily - review AI-generated conclusions, validate accuracy, and provide structured feedback that improves autonomous investigation quality
  • Turn every investigation into a service improvement: document reusable indicators, attack patterns, and false positive signals that feed directly into the team"s detection pipeline and AI training data
  • Identify gaps in existing detection rules and auto-remediation playbooks based on patterns observed during investigations, and propose improvements to senior engineers
  • Use AI-powered tools (including agentic AI assistants) to accelerate your own investigations, and share effective techniques with the team
  • Coordinate with internal teams to mitigate customer security issues
  • Participate in on-call rotations, including weekends

A day in the life

You review the investigation queue, pick up findings from AI agents and automated triage, and investigate using CloudTrail forensics and threat intelligence. When you confirm a threat, you get on a call with the customer to guide containment. After each investigation, you extract patterns into the automation pipeline and provide structured feedback to AI agents so they improve. You propose detection rules for recurring false positives and review AI-generated summaries for accuracy.

About the team

The AWS Security Incident Response team provides 24/7 threat monitoring, investigation, and response for customer AWS environments. The team is driving a strategic transformation - raising operational standards, building AI-powered investigation capabilities, and expanding coverage. We respond to customer requests within minutes. Zero queue tolerance is the operating standard. We value engineers who solve root causes over those who close tickets. Security engineers receive structured mentorship, regular coaching, and increasing ownership as they grow. Engineers on this team have grown into senior investigators, automation builders, and technical leads.

About the Company

A

Amazon.com Inc

At Amazon, we don’t wait for the next big idea to present itself. We envision the shape of impossible things and then we boldly make them reality. So far, this mindset has helped us achieve some incredible things. Let’s build new systems, challenge the status quo, and design the world we want to live in. We believe the work you do here will be the best work of your life.

Wherever you are in your career exploration, Amazon likely has an opportunity for you. Our research scientists and engineers shape the future of natural language understanding with Alexa. Fulfillment center associates around the globe send customer orders from our warehouses to doorsteps. Product managers set feature requirements, strategy, and marketing messages for brand new customer experiences. And as we grow, we’ll add jobs that haven’t been invented yet.

It’s Always Day 1
At Amazon, it’s always “Day 1.” Now, what does this mean and why does it matter? It means that our approach remains the same as it was on Amazon’s very first day – to make smart, fast decisions, stay nimble, invent, and stay focused on delighting our customers. In our 2016 shareholder letter, Amazon CEO Jeff Bezos shared his thoughts on how to keep up a Day 1 company mindset. “Staying in Day 1 requires you to experiment patiently, accept failures, plant seeds, protect saplings, and double down when you see customer delight,” he wrote. “A customer-obsessed culture best creates the conditions where all of that can happen.” You can read the full letter here

Our Leadership Principles
Our Leadership Principles help us keep a Day 1 mentality. They aren’t just a pretty inspirational wall hanging. Amazonians use them, every day, whether they’re discussing ideas for new projects, deciding on the best solution for a customer’s problem, or interviewing candidates. To read through our Leadership Principles from Customer Obsession to Bias for Action, visit https://www.amazon.jobs/principles
COMPANY SIZE
10,000 employees or more
INDUSTRY
Retail
FOUNDED
1994
WEBSITE
http://Amazon.com/militaryroles