Security Intelligence Engineer, Amazon Cyber Threat Intelligence
Core
Develop actionable intelligence on advanced cyber threats to Amazon ecosystems (AWS, Ads, LEO) by analyzing actor TTPs, identifying new data sources, and generating insights from expansive datasets.
Role type
Security Intelligence Engineer
Builds
Actionable threat intelligence products and internal security automation
Domain
Cybersecurity / Threat Intelligence
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Python, Ruby, Go, Swift, Java, .Net, C++, command line tools, log analysis, database querying, statistical analysis, malware analysis, network flow analysis, threat intelligence platforms (TIPs)
Preferred skills
threat modeling, secure coding, identity management, cryptography, system administration, network security, SDLC security activities, AWS products, modern threat intelligence platforms
Technologies
Python, Ruby, Go, Swift, Java, .Net, C++, AWS, HTTP(S), DNS, TCP/IP
Responsibilities
Perform deep dive analysis of malicious artifacts; Analyze large and unstructured data sets to identify trends and anomalies; Create security techniques and automation for internal use; Contribute to Amazon's understanding of the current threat landscape; Draft and publish finished written threat intelligence products; Periodic on-call responsibilities
Seniority
Mid-Senior, hands-on IC
