Demo

Security Engineer, AWS Security Incident Response

Amazon Web Services (AWS)
Seattle, WA Full Time
POSTED ON 6/7/2026
AVAILABLE BEFORE 7/14/2026
Description

AWS Security Incident Response is looking for a Security Engineer who investigates with urgency, communicates with clarity, and turns every investigation into an opportunity to make the service smarter. You will perform hands-on security response for customers, work alongside AI-powered investigation agents daily, and feed what you learn back into the automation systems that protect all customers.

The AWS Security Incident Response team provides 24/7 security response through a follow-the-sun operating model. The service combines automated triage workflows, AI-powered investigation agents, and human security analysts to respond to threats across customer AWS environments at massive scale. Our AI systems autonomously resolve the majority of routine investigations within minutes. Every engineer on the team is expected to be fluent in how these AI systems work, provide feedback that improves their accuracy, and identify opportunities to extend their capabilities.

This is not a traditional security operations role. You will investigate security incidents hands-on, but equally important is what happens after the investigation: documenting patterns, proposing detection rules, providing structured feedback to AI agents, and building the automation that prevents the same issue from requiring human investigation again. We treat every investigation as a confirmed security incident until the data proves otherwise.

This position requires that the candidate selected be eligible to obtain a US Government security clearance.

Key job responsibilities

  • Investigate and respond to security findings and customer-reported security events using AI-powered investigation tools and manual forensic techniques
  • Perform CloudTrail forensics, log analysis, and threat intelligence correlation to determine the scope, impact, and root cause of security events in customer AWS environments
  • Get on calls with customers during active incidents to walk them through what was compromised and the specific containment steps to execute immediately
  • Work alongside AI investigation agents daily — review AI-generated conclusions, validate accuracy, and provide structured feedback that improves autonomous investigation quality
  • Turn every investigation into a service improvement: document reusable indicators, attack patterns, and false positive signals that feed directly into the team's detection pipeline and AI training data
  • Identify gaps in existing detection rules and auto-remediation playbooks based on patterns observed during investigations, and propose improvements to senior engineers
  • Use AI-powered tools (including agentic AI assistants) to accelerate your own investigations, and share effective techniques with the team
  • Coordinate with internal teams to mitigate customer security issues
  • Participate in on-call rotations, including weekends

A day in the life

You review the investigation queue, pick up findings from AI agents and automated triage, and investigate using CloudTrail forensics and threat intelligence. When you confirm a threat, you get on a call with the customer to guide containment. After each investigation, you extract patterns into the automation pipeline and provide structured feedback to AI agents so they improve. You propose detection rules for recurring false positives and review AI-generated summaries for accuracy.

About The Team

The AWS Security Incident Response team provides 24/7 threat monitoring, investigation, and response for customer AWS environments. The team is driving a strategic transformation — raising operational standards, building AI-powered investigation capabilities, and expanding coverage. We respond to customer requests within minutes. Zero queue tolerance is the operating standard. We value engineers who solve root causes over those who close tickets. Security engineers receive structured mentorship, regular coaching, and increasing ownership as they grow. Engineers on this team have grown into senior investigators, automation builders, and technical leads.

Basic Qualifications

  • 2 years of web protocols, common security attacks, and remediation (non-internship) experience
  • Bachelor's degree in Engineering, Computer Science, or a related field
  • Experience with coding/scripting in one or more languages (e.g., Python, C, C , Java, Ruby, or PowerShell)
  • Experience (non-internship) in industry-based security vulnerabilities identification, attack patterns, and remediation techniques
  • Knowledge of operating systems, hardware, storage, network, security, database administration and cloud infrastructure
  • Knowledge of one or more of the following domains: access-control system and methodology, network security, application- and system-development security, security architecture and models, cryptography, and operations security

Preferred Qualifications

  • Experience with AWS services or other cloud offerings
  • GCIH (GIAC Certified Incident Handler) or GSEC (GIAC Security Essentials) or Security

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, WA, Seattle - 136,000.00 - 184,000.00 USD annually


Company - Amazon Web Services, Inc.

Job ID: A10421277

Salary.com Estimation for Security Engineer, AWS Security Incident Response in Seattle, WA
$86,039 to $116,347
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Engineer, AWS Security Incident Response?

Sign up to receive alerts about other jobs on the Security Engineer, AWS Security Incident Response career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Amazon Web Services (AWS)

  • Amazon Web Services (AWS) Sparks, NV
  • Description How would you like to be a part of Earth’s most customer-centric company? You would work with teams of front-line responders who support the op... more
  • 3 Days Ago

  • Amazon Web Services (AWS) Sparks, NV
  • Description Join our dynamic AWS team and become a critical guardian of global cloud infrastructure! You'll play a pivotal role in maintaining the heartbea... more
  • 3 Days Ago

  • Amazon Web Services (AWS) Las Vegas, NV
  • DESCRIPTION The United States Air Force is at an inflection point. As it modernizes warfighting capabilities, accelerates data-driven decision-making, and ... more
  • 3 Days Ago

  • Amazon Web Services (AWS) Canton, MS
  • Description AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. In other words, we’re the peop... more
  • 3 Days Ago


Not the job you're looking for? Here are some other Security Engineer, AWS Security Incident Response jobs in the Seattle, WA area that may be a better fit.

  • Amazon Seattle, WA
  • Description AWS Security Incident Response is looking for a Security Engineer who investigates with urgency, communicates with clarity, and turns every inv... more
  • 27 Days Ago

  • Amazon Seattle, WA
  • Description AWS Security Incident Response is looking for a Security Manager who combines deep technical expertise in security operations with the leadersh... more
  • 15 Days Ago

AI Assistant is available now!

Feel free to start your new journey!