Role at a glance
- Salary
- $159.3K – $202.4K/yr
- Location
- Seattle, Washington, United States
- Work arrangement
- On-site
- Employment
- Full-time
- Experience
- 5+ years of security-related professional experience
- Education
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience
Spotted an issue?
We’ll check it against the original posting.
Role Summary
The Security Engineer II will design, build, and operate detection and monitoring capabilities for Amazon Health Services across cloud infrastructure, applications, endpoints, identity systems, and AI-powered applications. As part of Amazon Healthcare Security’s Detections & Monitoring team, the role supports rapid threat detection and efficient investigation while extending AI-powered tooling and monitoring coverage for healthcare workloads.
What You'll Do
- Design, build, and maintain detection-as-code capabilities across cloud infrastructure, SaaS applications, endpoints, and identity systems.
- Develop and deploy detections and monitoring for agentic applications and AI services, including anomaly detection for LLM-powered tools...
- Build automated investigation and response workflows for triage, enrichment, containment, and remediation.
- Monitor telemetry data, alerting systems, and dashboards for degradation, compromise, or abuse across Amazon Health Services environments.
- Triage and correlate alerts from multiple sources to reduce noise and identify high-fidelity signals.
- Lead and participate in incident response, including detection, investigation, containment, and retrospectives.
Generated from the employer's posting. Verify important details before applying.
View full postingQualifications
Required
- 5+ years of security-related professional experience
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience
- Experience demonstrating software engineering skills in a previous intership, work experience, coding competitions, or publications, or experience with programming/scripting (Batch, VB, PowerShell, Java, C#, Chef, Perl, Ruby and/or PHP)...
- Experience directly working with cloud hosting technologies (AWS, Azure, etc.)
- Experience applying threat modeling or other risk identification techniques or equivalent
- Experience with log aggregation and analysis platforms (e.g., Splunk, OpenSearch, ELK, Datadog) and/or endpoint detection tools (e.g., SentinelOne, CrowdStrike)
Preferred
- Experience in Linux/RHEL, or experience in Kubernetes, Docker or containers ecosystem
- Knowledge of security and compliance standards including HIPAA and GDPR
- Experience in automation or monitoring frameworks, deployment or development
- Experience building detection-as-code frameworks or custom detection pipelines
- Experience building AI/LLM-powered security tooling or applying AI to detection, triage, or investigation workflows
- Understanding of generative AI technologies, large language models, and AI agents, with ability to identify security risks in agentic architectures
- Experience with threat intelligence, threat hunting, or attacker tradecraft frameworks such as MITRE ATT&CK
- Experience with automated response/SOAR platforms or building investigation automation
Original job description
Content provided by the employer
Original job description
Content provided by the employer
Working closely with AHS engineering teams, peer security teams, and incident responders, you will ensure that threats targeting healthcare workloads are detected rapidly and investigated efficiently, while maintaining HIPAA compliance and Amazon's security bar. You will also leverage AI/LLM-powered tooling to scale detection, triage, and response beyond traditional approaches.
Key job responsibilities
Design, build, and maintain detection-as-code capabilities across cloud infrastructure (CloudTrail, GuardDuty, VPC Flow Logs), SaaS applications, endpoints, and identity systems, improving coverage and signal quality
Develop and deploy detections and monitoring for agentic applications and AI services, including anomaly detection for LLM-powered tools, agent orchestration systems, and AI service APIs
Build automated investigation and response workflows that replace manual runbooks, leveraging AI to scale triage, enrichment, containment, and remediation
Develop and deploy AI/LLM-powered tooling to accelerate investigations, reduce alert fatigue, and extend team capacity beyond traditional headcount constraints
Continuously monitor telemetry data, alerting systems, and dashboards for early signals of degradation, compromise, or abuse across AHS environments
Triage and correlate alerts from multiple sources to identify patterns, reduce noise, and surface high-fidelity signals before impact escalates
Lead and participate in incident response, including detection, investigation, containment, and retrospectives, identifying root causes and driving long-term resilience improvements
Partner cross-functionally to expand logging, improve observability, and embed detection capabilities into the development lifecycle
Proactively identify gaps in visibility or detection coverage and translate ambiguous threat landscapes
Develop and maintain security documentation including detection coverage maps, threat models, runbooks, and monitoring architecture guidelines
About the team
The HealthSec Detections & Monitoring team protects Amazon's healthcare services by building and operating detection and monitoring capabilities at scale. We detect threats across cloud infrastructure, applications, endpoints, and AI systems—and we build AI-powered tooling to make our detections smarter and our response faster. Amazon Security offers talented security professionals the chance to accelerate their careers with opportunities across cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
Basic Qualifications
- 5+ years of security-related professional experience- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience
- Experience demonstrating software engineering skills in a previous intership, work experience, coding competitions, or publications, or experience with programming/scripting (Batch, VB, PowerShell, Java, C#, Chef, Perl, Ruby and/or PHP) and experience that includes strong analytical skills, attention to detail, and effective communication abilities
- Experience directly working with cloud hosting technologies (AWS, Azure, etc.)
- Experience applying threat modeling or other risk identification techniques or equivalent
- Experience with log aggregation and analysis platforms (e.g., Splunk, OpenSearch, ELK, Datadog) and/or endpoint detection tools (e.g., SentinelOne, CrowdStrike)
Preferred Qualifications
- Experience in Linux/RHEL, or experience in Kubernetes, Docker or containers ecosystem- Knowledge of security and compliance standards including HIPAA and GDPR
- Experience in automation or monitoring frameworks, deployment or development
- Experience building detection-as-code frameworks or custom detection pipelines
- Experience building AI/LLM-powered security tooling or applying AI to detection, triage, or investigation workflows
- Understanding of generative AI technologies, large language models, and AI agents, with ability to identify security risks in agentic architectures
- Experience with threat intelligence, threat hunting, or attacker tradecraft frameworks such as MITRE ATT&CK
- Experience with automated response/SOAR platforms or building investigation automation
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually
About the company
amazon
Large Enterprise
Amazon is a global leader in e-commerce and cloud computing, founded in 1994 by Jeff Bezos. Initially starting as an online bookstore, it has since expanded its offerings to include a vast range of products and services, including electronics, fashion, and digital content. With Amazon Web Services (AWS), the company also provides powerful cloud solutions to businesses around the world. Known for its innovation, customer-centric approach, and commitment to operational efficiency, Amazon continues to shape the future of retail and technology, consistently seeking new ways to enhance customer experiences.
Amazon is a global leader in e-commerce and cloud computing, founded in 1994 by Jeff Bezos. Initially starting as an online bookstore, it has since expanded its offerings to include a vast range of products and services, including electronics, fashion, and digital content. With Amazon Web Services (AWS), the company also provides powerful cloud solutions to businesses around the world. Known for its innovation, customer-centric approach, and commitment to operational efficiency, Amazon continues to shape the future of retail and technology, consistently seeking new ways to enhance customer experiences.