Security Engineer I, AWS Security Incident Response
$136k - $184kAmazonWebServices
As part of the AWS Applied AI Solutions organization, we have a vision to provide business applications, leveraging Amazon’s unique experience and expertise, that are used by millions of companies worldwide to manage day-to-day operations. We will accomplish this by accelerating our customers’ businesses through delivery of intuitive and differentiated technology solutions that solve enduring business challenges. We blend vision with curiosity and Amazon’s real-world experience to build opinionated, turnkey solutions. Where customers prefer to buy over build, we become their trusted partner with solutions that are no-brainers to buy and easy to use.Are you passionate about protecting customers at scale? AWS Security Incident Response is growing to meet increasing customer demand, and we're looking for a Security Engineer I to join the team. In this role, you will investigate suspicious activity, drive security response efforts, and communicate technical findings to both technical and non-technical audiences. You take the lessons learned from security response to enhance existing automations. The team is actively building AI-augmented investigation tools and new forensic capabilities, making this a great time to join where your work directly improves secure outcomes for AWS customers.Key job responsibilities- Respond to threat findings that indicate unauthorized activity, performing triage and escalating issues as appropriate- Identify, evaluate, and communicate security threats, risks, and vulnerabilities, and recommend remediation actions to reduce risk- Contribute to security automation, scripting, and tooling efforts — including AI-augmented investigation tools — that improve the team's triage and response capabilities- Track and report on the effectiveness of AWS detective controls such as Amazon GuardDuty and partner products such as CrowdStrike Falcon or Wiz Defend- Develop and refine runbooks, processes, and policies that strengthen security response effectivenessA day in the lifeYou will start your day reviewing alerts and triaging potential threats across customer environments, working alongside fellow security engineers, service partner teams, and Trust & Safety Abuse. You might spend the morning investigating a suspicious finding using AWS-native tools, then shift to documenting your analysis and coordinating remediation with the affected service team. Beyond daily response work, you may contribute to threat research, help improve triage using signals from security partners, or prepare threat intelligence briefings for customers.About the teamAWS Security Incident Response is a team of security engineers and incident responders who provide 24/7 threat monitoring, investigation, and response for customers running workloads on AWS. The team takes signals from security partners and Trust & Safety Abuse to improve triage and prevent harm, protecting environments ranging from startups to large enterprises using services like Amazon GuardDuty and partner integrations. We are investing in AI-powered forensic tools and auto-remediation to keep pace with rapid customer growth. Team members regularly present at industry forums such as AWS re:Invent and deliver threat intelligence briefings to customers. You can grow through automation development, threat research, partner work, or contributing to internal AWS security tooling. If you want to join an inclusive team that is shaping how AWS customers stay secure, we'd love to hear from you.Diverse ExperiencesAmazon values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why AWSAmazon Web Services (AWS) is the world’s most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that’s why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve in the cloud.Inclusive Team CultureHere at AWS, it’s in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity and AmazeCon conferences, inspire us to never stop embracing our uniqueness.Mentorship and Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.Basic qualifications- 2+ years of web protocols, common security attacks, and remediation (non-internship) experience- Bachelor's degree in Engineering, Computer Science, or a related field- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent- Experience with web protocols, common security attacks, and remediation (non-internship)- Experience solving basic problems by writing code or scripts with some assistancePreferred qualification - Experience with AWS services or other cloud offerings- * Experience with AWS services in a security context (e.g., Amazon GuardDuty, AWS CloudTrail, AWS Security Hub, AWS IAM)- * Familiarity with how AI/ML systems work, including concepts like confidence scoring, feedback loops, and training data- * Experience contributing to detection engineering, security automation, or building tools that improve security operationsAmazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at .USA, WA, Seattle - 136,000.00 - 184,000.00 USD annually
$159.3k - $202.4k
...want to work on planetary scale incident response solutions in the cloud? Are you skilled at performing Security Incident Response activities... ...globally? As a member of the AWS Customer Incident Response... ...for an experienced security engineer with an ability to scale security...Amazon Web ServiceInternshipFlexible hours$159.3k - $202.4k
...interview process.About the RoleTwitch is looking for a Security Incident Response Engineer to join our SIRT. Reporting to the SIRT Manager, you'll be... ...handling security incidents in hybrid cloud environment (AWS, GCP) and conducting log dives on cloud telemetry like CloudTrailPassion...Amazon Web ServiceFlexible hours$132k - $198k
Security Engineer III _ Incident Response F5 Office of the CISO | Application Delivery, Security, and AI Resilience Position Summary We are seeking a Security... ...conducting AI and security investigations using eReady, AWS, CrowdStrike, model invocation, identity and access, API...Amazon Web ServiceWork at officeLocal area$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information... ...will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond... ...DNS, and TCP/IP- Experience with AWS products and services- Experience performing...Amazon Web ServiceInternshipFlexible hours$176k - $253k
...future of how work gets done.We are hiring a Senior Security Engineer, dedicated to Product Security Incident Response. In this role, you will lead and architect... ....Working knowledge of cloud-native environments (AWS, Azure, GCP) and the threat landscape specific to...Amazon Web Service- ...across the globe to create, secure, and run applications that enhance... ...can thrive.Security Engineer III _ Incident ResponseF5 Office of the CISO... ...serve as a dedicated incident response member within F5’s Office of... ...using eReady, AWS, CrowdStrike, model invocation...Amazon Web ServiceFull timeWork at officeLocal area
- ...organizations across the globe to create, secure, and run applications that enhance how... ...can thrive.Principal Security Engineer - Incident Response & Crisis ManagementOrganization: F5 Office... ...investigating complex telemetry across AWS/Azure/GCP, SIEMs, EDR platforms (e.g.,...Amazon Web ServiceFull timeWork at officeLocal area
$175.1k - $236.9k
AWS Security Incident Response is looking for a Security Manager who combines deep technical expertise in security operations with the leadership... ...own operational excellence for a regional team of security engineers, engage directly with customer security executives during...Amazon Web ServiceFlexible hoursShift work$175.1k - $236.9k
...looking for an experienced security leader to join the... ...managing a team of incident managers and... ...be expected to drive engineering teams to take the right... ...accountability is a must.Key job responsibilities- Build and lead a... ...stakeholders across AWS to ensure security...Amazon Web ServiceRemote workFlexible hoursShift workNight shift$180k - $220k
...About the Role As a Senior Security Engineer, Detection and Response you will develop, scale, and evolve... ...across sandbox, staging and production AWS accounts, the retention and cost posture... ...remaining third is investigation, incident response and threat hunting. Expect...Amazon Web ServiceFull timeWorldwide$168.2k - $310.1k
...skilled and experienced Staff Cyber Incident Responder. This senior role is pivotal in our incident response efforts, providing skilled... ...operating systems. Cloud Security: Extensive experience in administering... ...defending cloud environments (AWS, Azure, GCP). Log Analysis:...Amazon Web ServiceFull timeTemporary workLocal areaWorldwide$159.3k - $202.4k
We're looking for a Security Engineer to join the team that secures the... ...networking systems powering AWS — the systems behind EC2, Nitro... ...transforms.Key job responsibilities- Design, build, and maintain... ...rotations to support security incidents- Leverage AI tools and techniques...Amazon Web ServiceInternshipFlexible hours$159.3k - $202.4k
Amazon Healthcare Security's (HealthSec) Detections & Monitoring... ...is hiring a Security Engineer II to design, build,... ...investigation and response workflows, and extending... ...peer security teams, and incident responders, you will... ...hosting technologies (AWS, Azure, etc.)- Experience...Amazon Web ServiceFlexible hours$178.4k - $226.7k
The Ads Security organization at Amazon is dedicated to creating... ...a talented Senior Security Engineer to join our team, where you... ...design, vulnerability analysis, incident response, and defensive architecture.... ...security architecture (AWS preferred) including IAM, VPC...Amazon Web ServiceFlexible hours$168k - $210k
...money globally, providing secure, simple, and reliable... ...the Role As a Security Engineer on Remitly's Corporate... ...Partnering with IT, Detection & Response, Infrastructure... ...before they become incidents.Drive operational improvements... .../ZTNA.Experience w/ AWS or GCP you've been in a...Amazon Web ServiceFull timeWork at officeWorldwide- ...highest standards of data security and privacy protection... ...both the detection & response layer and the cloud... ...credential exposure across AWS/GCP production... ...SIEM Build & Detection Engineering — Deploy the SIEM platform... ...coverage fidelity. Incident Response — Own the IR...Amazon Web ServiceWorldwide
- Senior Security Engineer The Security Engineering team is responsible for protecting Sift's products, infrastructure, and data... ...security team. Participate in security incident response (on-call rotation or... ...cloud platform (e.g., GCP, AWS), including IAM, networking, logging...Amazon Web Service
- GRC Engineering Lead The Security Governance, Risk, and Compliance (GRC) team is part... ...-readable evidence. Responsibilities: Architect GRC's Engineering... ...Hands-on experience with AWS and cloud-native security... ...similar). Exposure to security incident response and triage....Amazon Web ServiceWork experience placementLocal areaShift work
$120k - $260k
Senior Staff Security Engineer At GEICO, we offer a rewarding career where... ...'s security posture. Key Responsibilities VM & OffSec Execution Lead... ...compliance, governance, and incident response teams to ensure alignment... ..., cloud services (AWS/Azure/GCP), container platforms...Amazon Web ServiceHourly payWork experience placementLocal area$132k - $198k
...the globe to create, secure, and run applications... ...environment. The Security Engineer position will execute... ...landscape. Primary Responsibilities Lead the engineering,... ...cloud assets (Azure, GCP, AWS) into the platform.... ...security tools. Assist in incident detection and response...Amazon Web ServiceLocal area$108k - $232k
...Overview This role mitigates security threats by... ...experience in Security Engineering or Cybersecurity Preferred... ...threat identification, response, assessment, and... ...automation scripts utilizing AWS resources and Python... ...penetration testing, incident response, threat hunting...Amazon Web ServiceTemporary workFlexible hours- ...role: We’re seeking a Staff Security Detection Engineer to build and mature SoFi’s... ...enrichment, correlation, and response playbook hooks (detection-... ...in root-cause and post-incident reviews to identify new signals... ...EDR, network/proxy, cloud (AWS/GCP/Azure), and SaaS audit...Amazon Web ServiceRemote work
$191k - $297k
...an accomplished Principal Security Engineer to serve within Nordstrom's... ...agents and automation.Key Responsibilities:Lead the design and architecture... ....Lead identity-related incident response efforts for critical... ...-native identity services (AWS IAM, Azure Entra ID, GCP...Amazon Web ServiceFull timeWork at office$143.7k - $194.4k
Join us in developing and scaling security solutions that protect Amazon's... ...a Security Software Development Engineer, you'll create innovative automations... ...the security posture of AWS and for our customers.Key job responsibilities• Drive operational excellence by...Amazon Web ServiceInternshipWorldwideFlexible hours$139k - $204k
...infrastructure — and threat actors know it. The Advanced Response Team exists to fight back. You'll lead our most critical incidents, hunt adversaries before they surface, and... ...to stay left of boom Work alongside security partners who hold a high bar and expect you to...Permanent employmentFull timeTemporary workCasual workWork at officeFlexible hours$148.5k - $237.6k
...matter.Your ImpactAs a Senior Security Operations Engineer II, you will play a key... ...Design, provision, and manage AWS infrastructure that... ...security and infrastructure incidents, perform root cause analysis... ...to strengthen detection and response.Maintain and improve internal...Amazon Web ServiceWork experience placementWork at officeRemote work$10 per hour
...and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write... ...team is paged when they fire. The security team is spread across the globe with a... ...here. Response & automation Own incident response: triage, contain, remediate,...Work at officeLocal areaImmediate startRelocationRelocation packageFlexible hours- Infrastructure Security Engineer Our Security Engineering team builds intelligent... ...on including multi-account AWS, Kubernetes clusters, the... ...new agentic detection and response workflows using AWS native... ...integrated with Datadog and our incident response playbooks. Set the...Amazon Web ServiceWork at officeMonday to FridayShift work
$217k - $255k
Staff Offensive Security Engineer Bellevue, WA; Menlo Park, CA; New York,... ...to strengthen detection and response capabilities. You will help... ...adversarial simulations and improve incident readiness Communicate... ...Kubernetes/Docker), cloud providers (AWS, GCP), etc and be able to...Amazon Web ServiceWork at officeShift work3 days per week- About the Team Security is at the foundation of OpenAI's mission to... ...About the Role As a Security Engineer you will join our OpenAI engineers... ...all aspects of Detection & Response but with a strong emphasis on... ...running and leading incidents. Proficiency with a scripting...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer I, AWS Security Incident Response. Be the first to apply!
- security engineering manager Seattle, WA
- security engineer intern Seattle, WA
- physical security engineer Seattle, WA
- senior security operations engineer Seattle, WA
- staff security engineer Seattle, WA
- security software engineer Seattle, WA
- entry level security engineer Seattle, WA
- network security engineer Seattle, WA
- sr information security engineer Seattle, WA
- cloud security engineer Seattle, WA


