Security Engineer, Threat Discovery and Detection

4 weeks ago


Seattle, United States Amazon Full time

Description

Are you passionate about protecting Amazon's customers from emerging cyber threats? Join our team to develop innovative detection capabilities that defend against sophisticated attacks at massive scale.

Key job responsibilities

As a Security Engineer on the Threat Discovery and Detection (TD2) team within Customer Service Security, you'll be instrumental in developing and implementing advanced threat detection mechanisms that safeguard Amazon's customer service operations. You'll work at the intersection of security research and detection engineering, leveraging modern security tools and techniques to identify and prevent potential security incidents.

You'll be responsible for designing, implementing, and optimizing detection rules and systems that monitor and analyze security-related activities across our infrastructure. Your expertise will be crucial in developing scalable detection solutions that enable proactive threat identification, behavioral analysis, and risk mitigation.

In this role, you'll collaborate closely with data engineers, data scientists, and incident responders to transform security requirements into effective detection capabilities. You'll utilize advanced security platforms and AWS services to build comprehensive detection frameworks that protect our customers and systems from evolving security risks.

A day in the life

  • Design and implement detection logic to identify sophisticated attack patterns and anomalous behaviors

  • Develop and optimize detection rules across multiple security monitoring platforms

  • Research and analyze emerging attack patterns and techniques to enhance detection capabilities

  • Collaborate with data teams to ensure detection systems effectively utilize available telemetry

  • Present detection strategies to stakeholders and incorporate feedback into implementations

  • Troubleshoot detection accuracy issues and tune rules to reduce false positives

About the team

The Threat Discovery and Detection (TD2) team is a critical component of the Customer Service Security organization. Our mission is to protect Amazon customer data and ensure operational integrity through advanced detection techniques and continuous monitoring. We develop innovative solutions that identify internal threats impacting Customer Service and establish a multi-layered defense strategy.

In the coming years, we're focused on expanding our detection coverage, implementing machine learning-based detection capabilities, and enhancing our ability to identify sophisticated threats in real-time. As a Security Engineer, you'll be at the forefront of these initiatives, helping to shape the future of threat detection at Amazon.

Basic Qualifications

  • 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience

  • Bachelor’s degree in Computer Science, Engineering, related discipline, or equivalent experience with 3+ years of security engineering experience

  • Experience performing secure code review and writing scripts to automate security functions & solve security problems with automation

  • Strong programming skills in SQL, Python, Java, or similar languages

Preferred Qualifications

  • Knowledge of threat hunting and incident response processes

  • Familiarity with cloud security and AWS security services

  • Experience with machine learning applications in security

  • Experience with SIEM platforms and security monitoring tools

  • Strong understanding of the MITRE ATT&CK framework and attack methodologies

  • Expertise in developing and implementing detection rules and logic

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits . This position will remain posted until filled. Applicants should apply via our internal or external career site.



  • Seattle, Washington, United States Amazon Full time

    Are you passionate about protecting Amazon's customers from emerging cyber threats? Join our team to develop innovative detection capabilities that defend against sophisticated attacks at massive scale.Key job responsibilitiesAs a Security Engineer on the Threat Discovery and Detection (TD2) team within Customer Service Security, you'll be instrumental in...


  • Seattle, Washington, United States Amazon Full time

    Are you passionate about protecting Amazon's customers from emerging cyber threats? Join our team to develop innovative detection capabilities that defend against sophisticated attacks at massive scale.Key job responsibilitiesAs a Security Engineer on the Threat Discovery and Detection (TD2) team within Customer Service Security, you'll be instrumental in...


  • Seattle, Washington, United States Reddit Full time

    Reddit is a community of communities. It's built on shared interests, passion, and trust and is home to the most open and authentic conversations on the internet. Every day, Reddit users submit, vote, and comment on the topics they care most about. With 100,000+ active communities and approximately 82M+ daily active unique visitors, Reddit is one of the...


  • Seattle, Washington, United States Amazon Full time

    Come and build innovative services that protect our cloud from advanced security threatsAs a Security Engineer on our team, you'll help build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon's infrastructure, including advanced persistent threats. You'll work with data scientists, software development...


  • Seattle, Washington, United States UKG (Ultimate Kronos Group) Full time

    Achieving Excellence in CybersecurityAs a Threat Detection Specialist, you'll play a vital role in shaping UKG's cybersecurity strategy. Our Global Security Detection Engineering team is dedicated to protecting our customers' sensitive data and preventing sophisticated cyber threats. Your expertise will help us stay at the forefront of threat detection and...


  • Seattle, Washington, United States Amazon Full time

    Come and build innovative services that protect our cloud from advanced security threatsAs a Senior Security Engineer on our team, you'll help build and manage services that detect and automate the mitigation of cybersecurity threats across Amazon's infrastructure, including advanced persistent threats. You'll work with data scientists, software development...


  • Seattle, Washington, United States Reddit Full time

    **About the Role:**We are seeking a highly skilled Cybersecurity Threat Detection Specialist to join our Security Intelligence Center team. As a key member of our team, you will be responsible for analyzing security threats, building detections, and responding to security events.The ideal candidate will have a strong coding background and experience in...


  • Seattle, Washington, United States Reddit Full time

    About UsReddit is a community-driven platform where users submit, vote, and comment on topics they care about. With over 100,000 active communities and approximately 82 million daily active unique visitors, Reddit is one of the internet's largest sources of information. Our SPACE team is dedicated to defending employees and computer assets to maintain trust...


  • Seattle, Washington, United States Gemini Full time

    About the CompanyGemini is a global crypto and Web3 platform founded by Tyler Winklevoss and Cameron Winklevoss in 2014. Gemini offers a wide range of crypto products and services for individuals and institutions in over 70 countries.Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build...


  • Seattle, Washington, United States Galvanick Full time

    Galvanick protects the industrial world against cyber attacks, ensuring the security and integrity of critical infrastructure. Our threat detection platform for factories safeguards the modern world against SCADA and ICS threats.About UsWe are a startup with a team of driven individuals committed to solving cybersecurity's big problems.5+ years experience in...


  • Seattle, United States Rippling Full time

    About Rippling Rippling is the first way for businesses to manage all of their HR & IT-payroll, benefits, computers, apps, and more-in one unified workforce platform. By connecting every business system to one source of truth for employee data, businesses can automate all of the manual work they normally need to do to make employee changes. Take onboarding,...


  • Seattle, United States Rippling Full time

    About Rippling Rippling is the first way for businesses to manage all of their HR & IT-payroll, benefits, computers, apps, and more-in one unified workforce platform. By connecting every business system to one source of truth for employee data, businesses can automate all of the manual work they normally need to do to make employee changes. Take onboarding,...


  • Seattle, WA, United States Rippling Full time

    About Rippling Rippling is the first way for businesses to manage all of their HR & IT-payroll, benefits, computers, apps, and more-in one unified workforce platform. By connecting every business system to one source of truth for employee data, businesses can automate all of the manual work they normally need to do to make employee changes. Take...


  • Seattle, United States Amazon Full time

    Description We are looking for an experienced Front-End Engineer who is excited about leading the technical vision and architecture for our next-generation UI products. This role will be instrumental in delivering a best-in-class user experience for our customers while ensuring an efficient and scalable developer experience for our growing team. Since we are...


  • Seattle, Washington, United States Amazon Full time

    We are looking for an experienced Front-End Engineer who is excited about leading the technical vision and architecture for our next-generation UI products. This role will be instrumental in delivering a best-in-class user experience for our customers while ensuring an efficient and scalable developer experience for our growing team. Since we are just...


  • Seattle, Washington, United States Amazon Full time

    Are you inspired by the prospect of work that has a tangible impact on customers, teams, and businesses worldwide? Is your expertise in dissecting complex systems, ranging from embedded software to cloud services, matched by a zeal for uncovering product vulnerabilities? If the thrill of automating vulnerability detection and scaling its reach excites you...


  • Seattle, Washington, United States Galvanick Full time

    About GalvanickGalvanick protects the industrial world against cyber attacks, safeguarding critical infrastructure from criminals and nation-states. Our threat detection platform for factories defends the modern world against SCADA and ICS threats.Job OverviewThis is an opportunity to work in a startup environment with driven individuals committed to solving...


  • Seattle, Washington, United States Reddit Full time

    Reddit is a community of communities. Every day, Reddit users submit, vote, and comment on the topics they care most about. With 100,000+ active communities and approximately 82M+ daily active unique visitors, Reddit is one of the internet's largest sources of information. The SPACE (Security, Privacy, And Compliance Engineering) team defends Reddit's...


  • Seattle, Washington, United States UKG (Ultimate Kronos Group) Full time

    Company OverviewWith 80,000 customers across 150 countries, UKG is the largest U.S.-based private software company in the world. And we're only getting started. Ready to bring your bold ideas and collaborative mindset to an organization that still has so much more to build and achieve? Read on.At UKG, you get more than just a job. You get to work with...


  • Seattle, Washington, United States Amazon Full time

    Job DescriptionWe are seeking a highly skilled Security Engineer to join our Detection Engineering team. As a key member of our team, you will design and develop automated detection capabilities to identify and mitigate security risks throughout the Software Development Life Cycle (SDLC). Your expertise in threat modeling, code reviews, security testing,...