Security Intelligence Engineer, Amazon Cyber Threat Intelligence
Core
Develop actionable intelligence on advanced cyber threats to Amazon ecosystems (AWS, Ads, LEO) by analyzing actor TTPs and generating insights to proactively identify and mitigate malicious activity.
Role type
Security Intelligence Engineer
Builds
Actionable threat intelligence products and internal security automation
Domain
Cybersecurity / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Python, Ruby, Go, Swift, Java, .Net, C++, troubleshooting systems issues, log analysis, automation, command line tools, tracking high-sophistication cyber threat groups, database querying, statistical analysis
Preferred skills
threat modeling, secure coding, identity management, authentication, software development, cryptography, system administration, network security, malware analysis, network flow analysis, large scale data analysis, modern threat intelligence platforms (TIPs)
Technologies
AWS products and services, HTTP(S), DNS, TCP/IP
Responsibilities
Perform deep dive analysis of malicious artifacts, Analyze large and unstructured data sets to identify trends and anomalies indicative of malicious activities, Create security techniques and automation for internal use, Contribute to Amazon's understanding of the current threat landscape, Draft and publish finished written threat intelligence products based on findings, Periodic on-call responsibilities
Seniority
Mid-level, hands-on IC