We’re looking for talented software and systems professionals with a passion for security who thrive in dynamic environments to help us continue to raise the security bar for cloud computing.
Successful candidates should:
* be able to assess technical vs. business risks and consistently drive internal engineering teams to take the right actions in the appropriate time frames to mitigate risks.
* have a good mix of broad and deep technical knowledge and a demonstrated background in information security.
* be technically proficient in the fields of network and operating system security, cryptography, software security, security operations, incident response, and emergent security intelligence.
* possess a combination of troubleshooting, technical, and communication skills, as well as the ability to manage a mix of disparate tasks which may include small-project and software development work.
* be comfortable challenging and escalating to senior leadership to always ensure the best outcome for customers.
An ideal candidate should be able to conduct most of the following:
* Triage/assess security issues and engage with internal service teams to ensure prompt remediation of issues, escalating internally as necessary to ensure the right level of urgency and engagement.
* Participate in efforts to promote security throughout the Company and build good working relationships within the team and with others across Amazon.
* Demonstrate high ability and tolerance for extreme context switching and interruptions while staying productive and effective.
* Develop pragmatic solutions that achieve business requirements while keeping an acceptable level of risk.
* Help with recruiting activities and administrative work.
* Mentoring of junior staff and proactive knowledge sharing within the team and across the company.
* Fulfill regular on-call responsibilities.
Key job responsibilities
* Supply oversight of in-flight security issues.
* Triage new incoming issues to determine the level of risk they present to AWS, and then accordingly prioritize its remediation in conjunction with the impacted service team.
* Communicate the state of these issues to various audiences, both technical and non-technical, at various levels of seniority (up to and including AWS’ Chief Information Security Officer).
* Escalate issues to senior AWS leadership if you feel your issues are not being treated at the correct pace due to their impact to ensure that we are putting customers first.
* Explore building and improving our tooling to make your own life easier, and at the same time, sharing that benefit with all our engineers globally.
A day in the life
As part of our "follow-the-sun rotation", you will receive a handoff from global peers and be delegated ownership of various security issues presently in-flight. The issues could relate to any of our 200+ products, so you will often need to learn on-the-fly.
You will engage various stakeholders, such as the internal service team who owns the service and it's mitigation, along with AWS Security Leadership, Legal, and the leadership of the involved service team.
As the day progresses, new issues will be automatically assigned to you based on your workload and you will be responsible for triaging them, determining their level of impact, and work towards resolving them at the appropriate pace.
At the end of the day, you will have documented your work to allow the incoming shift to continue driving issues to resolution.
About the team
Cloud Response is a team within AWS Security Operations. This team is broadly responsible for the 'AWS' side of the Shared Responsibility Model, and provides oversight of security issues from their identification through to resolution.
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
Cloud Response operates with a "follow-the-sun model", with teams based around four different geographical locations.
We work with other AWS teams to ensure security issues are resolved with the right level of urgency whilst ensuring that our stakeholders are informed.
BASIC QUALIFICATIONS
- BS degree in Computer Science, Computer Engineering, Electrical Engineering, or 3+ years’ equivalent technology experience.
- 3+ years or more of proven experience with a focus in areas such as systems, network, and/or application security.
- 2+ years of scripting/coding experience in any language (including Bash/PowerShell scripting). Previous experience in Python scripting would be ideal.
PREFERRED QUALIFICATIONS
- Understanding and experience with implementation of best practices across multiple security disciplines/domains.
- Strong, proven knowledge of virtualization technologies (AWS preferred), web protocols, common attacks, and Linux/Unix tools and architecture.
- Demonstrated ability to collaborate/develop partnerships with partner teams, work autonomously with a Bias for Action, and employ critical and creative thinking.
- Maturity, judgment, negotiation/influence skills, analytical skills, and leadership skills.
- Ability to prioritize multiple tasks and projects in a dynamic environment.
- Effective written and oral communication with multiple levels of leadership involving both business and technical sides of the business.
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.