Level

Amazon

Security Engineer, AWS Cloud Response

AI in this role

Design agentic systems and automated frameworks that let AI reason over security context for cloud incident response.

pythonaws
incident-responsecloud-securityautomationagentic-systemstriage
AWS is looking for a Security Engineer to join the Cloud Response team in Australia.

The team manages the security and availability of AWS Cloud services. We operate on the "AWS" side of the Shared Responsibility Model to ensure "Security of the Cloud" and to protect our customers. This role requires engineers to work tactically with both internal and external stakeholders to solve security challenges at massive scale, and to think strategically to develop and implement changes to drive automation, scalability and continuous progress for the organization.

Key job responsibilities
A successful candidate will need a combination of troubleshooting, technical, and communication skills, as well as the ability to handle a mix of disparate tasks which may include projects in addition to managing incident response activities. This role will provide career growth opportunities as you gain new security skills in the course of your duties.

Successful candidates will be expected to:
Triage new incoming issues to determine the level of risk they present to AWS, and then accordingly prioritize its remediation in conjunction with the impacted service team.
Communicate the state of these issues to various audiences, both technical and non-technical, at various levels of seniority (up to and including the AWS Chief Information Security Officer).
Participate in efforts to promote security throughout the company and build good working relationships with partner security teams and service teams across Amazon
Demonstrate high capacity for managing priorities appropriately while remaining productive and effective, with tolerance for context switching and interruptions
Escalate issues early and often, expressing a high degree of security judgement when issues are not progressing at the correct pace based on impact to ensure we are putting customers first.
Design and build automation that reduces manual toil in incident response, from triage to remediation tracking.
Design agentic systems and frameworks that let AI reason over security context and take action safely within incident response.
Explore and embrace the Amazon builder culture, identifying mechanisms and methods to improve tools and processes to simplify and drive issues at the scale and speed necessary to benefit our global team of engineers.
Fulfill regular on-call responsibilities during the team's working hours and in support of the global team's on-call weekend rotation

A day in the life
This position supports AWS with security operations and incident response activities. You will be responsible for coordinating and facilitating security response activities for all AWS products and services. You will drive security related issues to resolution across numerous service teams and engineer scalable solutions to automate incident response activities.

Each day, your team picks up the shift from the region that worked before you, starting by reviewing what's open and setting priorities for the day, before handing the shift on to the next region at the end of the day. You'll drive response on the issues you pick up, digging in until you understand the real risk rather than settling for the first plausible read, and when a decision carries real weight, you'll walk it through with your manager before committing to a path. You'll write clearly and precisely as you go, since the next person picking up an issue is relying entirely on what you left behind. Alongside the daily grind, you'll also be chipping away at your own project work, whether that's building a tool to cut down on manual toil or automating a piece of the incident response process that used to take up half your day. Shifts are aligned to the US Pacific time (PST/PDT, accounting for daylight savings across summer and winter).

About the team
Cloud Response is a team inside AWS Security Operations. This team is broadly responsible for the 'AWS' side of the Shared Responsibility Model, and provides oversight of security issues from their identification through to resolution. Cloud Response operates follow-the-sun with teams based around four different geographical locations.

We work with AWS security and service teams to ensure security issues are addressed and resolved with the right level of urgency, while keeping our key stakeholders informed and engaged as necessary throughout the issue lifecycle. We also optimize our own operations by building tools and automation that let the team scale response capacity faster than incident volume grows.

We don't settle for a surface-level read on a security issue. We dig in until we understand the real risk, bring the right security expertise to the table, and partner with service teams to land on a clear path to resolution, whether that's a quick fix or a longer-term remediation. As our understanding of a class of issue matures, we push ownership back to the service teams best placed to own it long-term, while staying closely engaged wherever ambiguity remains.

The team is in the middle of a significant transformation, rebuilding how we work around AI and agentic frameworks that reason over security context and take action alongside our engineers. This is reshaping what the job looks like day to day, and there's real room to shape that direction rather than just adopt it.

Basic qualifications

- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- Bachelor's degree in computer science or equivalent
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP

Preferred qualifications

- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Experience with AWS products and services
- Experience with programming languages such as Python, Java, C++
- Experience building or working with AI/LLM-based agents, automation frameworks, or applying AI to security and operational workflows

Acknowledgement of country:
In the spirit of reconciliation Amazon acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.

IDE statement:
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

How we rate this

Security Engineer, AWS Cloud Response at Amazon rates 65 out of 100 for how much of the daily work is AI. That makes it Works on AI (AI Level 3 of 4). The level is about AI in the job, not seniority.

Classification

Works on AI. The daily work is on AI products, without building the model.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Incident ResponseCloud SecurityAutomationAgentic SystemsTriagePythonAWS

Questions you could be asked

  1. Tell me about a project where incident response was part of your work. What did you do?
  2. Tell me about a project where cloud security was part of your work. What did you do?
  3. Tell me about a project where automation was part of your work. What did you do?
  4. Tell me about a project where agentic systems was part of your work. What did you do?
  5. Tell me about a project where triage was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: Incident Response, Cloud Security, Automation, Agentic Systems, and Triage. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
  • Show where AI is part of your daily process, not a one-off project — this role expects it to be a running habit.

Want your resume actually rewritten for this job?

The free preview above is everything we have today. A full resume rewrite is not live yet and has no price set. Join the waitlist and we will email you if we open it.

Get new AI jobs (Works on AI ●●●○ or higher) by email

One email a week with the new AI jobs (Works on AI ●●●○ or higher), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that work on AI, at other companies.

Databricks

Belgium; Finland; Remote - Denmark; Remote - France; Remote - Germany; Remote - Italy; Remote - Netherlands; Remote - Spain; Remote - Sweden; Remote - United Kingdom; SwitzerlandRemote3d

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Amazon

Related searches

Same AI level