Prepin
Log in
Amazon

engineering opportunity

Security Engineer I, AWS Security Incident Response

The role involves investigating suspicious activity, driving security response efforts, and communicating technical findings to various audiences. You will also contribute to security automation, scripting, and the development of AI-augmented investigation tools to enhance response capabilities.

Seattle, Washington, United StateshybridFULL_TIME

Posted

About the role

What will you do at Amazon?

As part of the AWS Applied AI Solutions organization, we have a vision to

provide business applications, leveraging Amazon’s unique experience and

expertise, that are used by millions of companies worldwide to manage day-to-day

operations. We will accomplish this by accelerating our customers’ businesses

through delivery of intuitive and differentiated technology solutions that solve

enduring business challenges. We blend vision with curiosity and Amazon’s

real-world experience to build opinionated, turnkey solutions. Where customers

prefer to buy over build, we become their trusted partner with solutions that

are no-brainers to buy and easy to use.

Are you passionate about protecting customers at scale? AWS Security Incident

Response is growing to meet increasing customer demand, and we're looking for a

Security Engineer I to join the team.

In this role, you will

  • investigate
  • suspicious activity, drive security response efforts, and communicate technical
  • findings to both technical and non-technical audiences. You take the lessons
  • learned from security response to enhance existing automations. The team is
  • actively building AI-augmented investigation tools and new forensic
  • capabilities, making this a great time to join where your work directly improves
  • secure outcomes for AWS customers.
  • Key job responsibilities
  • - Respond to threat findings that indicate unauthorized activity, performing
  • triage and escalating issues as appropriate
  • - Identify, evaluate, and communicate security threats, risks, and
  • vulnerabilities, and recommend remediation actions to reduce risk
  • - Contribute to security automation, scripting, and tooling efforts — including
  • AI-augmented investigation tools — that improve the team's triage and response
  • capabilities
  • - Track and report on the effectiveness of AWS detective controls such as Amazon
  • GuardDuty and partner products such as CrowdStrike Falcon or Wiz Defend
  • - Develop and refine runbooks, processes, and policies that strengthen security
  • response effectiveness
  • A day in the life
  • You will start your day reviewing alerts and triaging potential threats across
  • customer environments, working alongside fellow security engineers, service
  • partner teams, and Trust & Safety Abuse. You might spend the morning
  • investigating a suspicious finding using AWS-native tools, then shift to
  • documenting your analysis and coordinating remediation with the affected service
  • team. Beyond daily response work, you may contribute to threat research, help
  • improve triage using signals from security partners, or prepare threat
  • intelligence briefings for customers.

About the team

AWS Security Incident Response is a team of security engineers and incident

responders who provide 24/7 threat monitoring, investigation, and response for

customers running workloads on AWS. The team takes signals from security

partners and Trust & Safety Abuse to improve triage and prevent harm, protecting

environments ranging from startups to large enterprises using services like

Amazon GuardDuty and partner integrations. We are investing in AI-powered

forensic tools and auto-remediation to keep pace with rapid customer growth.

Team members regularly present at industry forums such as AWS re:Invent and

deliver threat intelligence briefings to customers. You can grow through

automation development, threat research, partner work, or contributing to

internal AWS security tooling. If you want to join an inclusive team that is

shaping how AWS customers stay secure, we'd love to hear from you.

Diverse Experiences

Amazon values diverse experiences. Even if you do not meet all of the preferred

qualifications and skills listed in the job description, we encourage candidates

to apply. If your career is just starting, hasn’t followed a traditional path,

or includes alternative experiences, don’t let it stop you from applying.

Why AWS

Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted

cloud platform. We pioneered cloud computing and never stopped innovating —

that’s why customers from the most successful startups to Global 500 companies

trust our robust suite of products and services to power their businesses.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the

expense of sacrifices at home, which is why flexible work hours and arrangements

are part of our culture. When we feel supported in the workplace and at home,

there’s nothing we can’t achieve in the cloud.

Inclusive Team Culture

Here at AWS, it’s in our nature to learn and be curious. Our employee-led

affinity groups foster a culture of inclusion that empower us to be proud of our

differences. Ongoing events and learning experiences, including our

Conversations on Race and Ethnicity and AmazeCon conferences, inspire us to

never stop embracing our uniqueness.

Mentorship and Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s

Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and

other career-advancing resources here to help you develop into a better-rounded

professional.

Basic

Qualifications

  • - 2+ years of web protocols, common security attacks, and
  • remediation (non-internship) experience
  • - Bachelor's degree in Engineering, Computer Science, or a related field
  • - Knowledge of system security vulnerabilities and remediation techniques,
  • including penetration testing and the development of exploits or equivalent
  • - Experience with web protocols, common security attacks, and remediation
  • (non-internship)
  • - Experience solving basic problems by writing code or scripts with some
  • assistance

Preferred Qualifications

  • - Experience with AWS services or other
  • cloud offerings
  • - * Experience with AWS services in a security context (e.g., Amazon GuardDuty,
  • AWS CloudTrail, AWS Security Hub, AWS IAM)
  • - * Familiarity with how AI/ML systems work, including concepts like confidence
  • scoring, feedback loops, and training data
  • - * Experience contributing to detection engineering, security automation, or
  • building tools that improve security operations
  • Amazon is an equal opportunity employer and does not discriminate on the basis
  • of protected veteran status, disability, or other legally protected status.
  • Our inclusive culture empowers Amazonians to deliver the best results for our
  • customers. If you have a disability and need a workplace accommodation or
  • adjustment during the application and hiring process, including support for the
  • interview or onboarding process, please visit
  • https://amazon.jobs/content/en/how-we-hire/accommodations
  • [https://amazon.jobs/content/en/how-we-hire/accommodations] for more
  • information. If the country/region you’re applying in isn’t listed, please
  • contact your Recruiting Partner.
  • The base salary range for this position is listed below. Your Amazon package
  • will include sign-on payments and restricted stock units (RSUs). Final
  • compensation will be determined based on factors including experience,
  • qualifications, and location. Amazon also offers comprehensive benefits
  • including health insurance (medical, dental, vision, prescription, Basic Life &
  • AD&D insurance and option for Supplemental life plans, EAP, Mental Health
  • Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy
  • Reimbursement coverage), 401(k) matching, paid time off, and parental leave.
  • Learn more about our benefits at https://amazon.jobs/en/benefits
  • [https://amazon.jobs/en/benefits].
  • USA, WA, Seattle - 136,000.00 - 184,000.00 USD annually

Which skills does this role require?

Security Incident ResponseThreat InvestigationSecurity AutomationScriptingWeb ProtocolsVulnerability RemediationPenetration TestingCloud SecurityAWS ServicesAmazon GuardDutyAWS CloudTrailAWS Security HubAWS IAMForensic AnalysisThreat IntelligenceDetection EngineeringSecurity EngineerIncident ResponseAutomationAI-augmentedForensicsCrowdStrike FalconWiz DefendVulnerability ManagementSecurity OperationsTrust & SafetyRisk AssessmentRemediationIncident HandlingSystem SecurityTechnical DocumentationRunbooksSecurity ControlsData AnalysisMachine Learning

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.