Haystack
← Back to Jobs
Full time
Technology

Security Engineer, AWS Security Incident Response

AmazonSydney, New South Wales🇦🇺AustraliaPosted 21 Jul 2026

Why This Role Stands Out

This role offers a dynamic opportunity to safeguard AWS infrastructure at a massive scale, developing cutting-edge automation and response strategies alongside a world-class security team. You'll thrive here if you possess a keen eye for threat detection, a passion for continuous learning, and enjoy collaborative problem-solving in a hybrid environment. Apply to join Amazon's renowned security operations and make a significant impact on global cloud security.

Quick Overview

Work Type
Hybrid
Schedule
Full Time
Level
Mid Senior

Job Description

Security Engineer, AWS Security Incident Response

Job ID: Amazon Web Services Australia Pty Ltd

Key job responsibilities
  • Hold or be able to attain an Australian Government Security Vetting Agency clearance (see )
  • Respond to threat findings that indicate unauthorized activity has occurred
  • Identify, evaluate and communicate security threats, risks and vulnerabilities, and propose recommended remediation for security issues.
  • Contribute to the development of security automation and security posture improvements.
  • Track and report on the effectiveness of AWS detective controls such as Amazon GuardDuty and partner products such as CrowdStrike Falcon or Wiz Defend
  • Develop processes and policies to increase security response effectiveness.
  • On-call support: This role requires periodic on-call responsibilities including weekends.
A day in the life

As a Security Engineer in AWS Security Incident Response, your responsibilities include monitoring networks and systems for potential threats, performing triage for security alerts, documenting suspicious activity, and reporting issues so they can be adequately handled. You will work alongside our security engineers and partner teams to perform daily threat detection and incident response, using the full capability of AWS technologies and services to detect and mitigate cyber threats at a massive scale and help protect AWS Customers. You should also enjoy learning about the most up-to-date new technologies and procedures to protect information systems and data.

About the team

AWS Security Incident Response provides 24/7 threat monitoring, investigation, and response across customers' AWS environments. The service enhances existing security capabilities by providing security monitoring for all native AWS services and supports vendor agnostic detective and protective controls to provide holistic security controls for customers. This is done by leveraging data on common attack techniques to enhance detective controls and incident response, then building auto remediation capabilities to minimize disruption to customer workloads. When a security event does happen, you will be there to provide guidance.

Basic Qualifications
  • Bachelor's degree in Engineering, Computer Science, or a related field
  • Experience with web protocols, common security attacks, and remediation (non internship)
  • Knowledge of system, network and OS
  • Experience solving basic problems by writing code or scripts with some assistance
Preferred Qualifications
  • Experience with AWS services or other cloud offerings
  • Experience triaging security alerts, front line analysis, and escalation
  • GCIH (GIAC Certified Incident Handler) or GSEC (GIAC Security Essentials) or Security+
Equal Opportunity Statement

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Skills

AWS

Similar jobs