Security Engineer I, AWS Security Incident Response

Company: Amazon
Apply for the Security Engineer I, AWS Security Incident Response
Location: Manchester
Job Description:

Overview

In this role you protect AWS customers by detecting and responding to security incidents at scale. You will work with cross-functional teams to triage threats, document findings, and guide remediation while leveraging AWS security tooling. The position emphasizes automation development and strengthening detective controls, with on-call responsibilities and UK security clearance. You’ll operate in a fast-paced, collaborative environment that values continuous learning and clear communication of complex concepts.

Pay / Benefits

  • flexible work hours
  • on-call responsibilities
  • mentorship and career growth resources
  • inclusive culture
  • work-life balance
  • opportunity to work on security at scale

Responsibilities

  • Respond to threat findings indicating unauthorized activity
  • Identify, evaluate and communicate threats, risks and vulnerabilities, and propose remediation
  • Contribute to security automation and posture improvements
  • Track and report on effectiveness of detective controls (e.g., GuardDuty, partner products)
  • Develop processes and policies to increase security response effectiveness
  • On-call support including weekends
  • Maintain UK Government Security Clearance
  • Monitor networks and systems, perform triage for security alerts, and document suspicious activity
  • Collaborate with security engineers and partner teams to perform daily threat detection and incident response
  • Leverage AWS technologies to detect and mitigate cyber threats at scale
  • Build auto-remediation capabilities to minimize disruption to customer workloads
  • Provide guidance during security events

Key requirements

  • Experience with web protocols, common security attacks, and remediation
  • Experience solving basic problems by writing code or scripts
  • Knowledge of system, network and OS
  • Experience with AWS services or other cloud offerings
  • Experience triaging security alerts, front-line analysis, and escalation
  • GCIH (GIAC Incident Handler) or GSEC (GIAC Security Essentials) or Security+
  • Ability to explain technical security concepts to non-technical audiences
  • Works well in a team and through ambiguity
  • Strong problem-solving and analytical thinking
  • AWS services or other cloud offerings
  • Security incident response
  • Threat hunting and triage

…

Posted: September 25th, 2026