Security Engineer, Correlation and Response, AWS Security Hub
Core
Research emerging threats to develop criticality and posture management ideas, build high-confidence markers and rules correlating criticality across large-scale data sources, and analyze detections at scale to defend customer data.
Role type
Senior IC security engineer (threat detection and response)
Builds
High-confidence threat correlation rules, posture management markers, and automated response mechanisms for AWS Security Hub
Domain
Cloud security, threat intelligence, and automated response systems
Deliverable
production ML models | product features
Required skills
Threat evaluation and vulnerability assessment, response automation, Python/Perl/Bash/PowerShell scripting, Java development, cloud architecture design, web protocols knowledge, Linux/Unix tools, network security
Preferred skills
Machine Learning and LLM fundamentals, AI-driven security workflows, agentic threat detection, generative AI prototyping, security code review, threat modeling, secure coding, identity management, cryptography
Technologies
AWS Developer Tools, Python, Java, C++, Go, Ruby, Swift, .Net, Linux/Unix, HTTP, DNS, TCP/IP
Responsibilities
Research emerging threats and develop criticality management ideas, build and tune evaluation rules for threat correlation, analyze resource and log data to assess impact, prototype new approaches using ML or generative AI, improve enrichment pipelines, collaborate with engineering and product teams on security analysis
Seniority
Senior, hands-on IC