All jobs

Security Engineer II, Stores Security - HealthCare

Amazon.com Services LLC5h ago
United StatesHybridFull-timeMid Level5+ yrs exp
H-1B verified · 2310 LCAs

Top focus

Security EngineerCloud Security Engineer
  • Amazon Healthcare Security's (HealthSec) Detections & Monitoring team is hiring a Security Engineer II to design, build
  • operate detection and monitoring capabilities that protect Amazon Health Services (AHS) across cloud infrastructure, applications, endpoints
  • AI-powered systems. You will work at the intersection of detection engineering and security operations—building detection-as-code pipelines, developing automated investigation and response workflows
  • extending monitoring coverage to emerging AI and agentic application architectures. Working closely with AHS engineering teams, peer security teams
  • incident responders, you will ensure that threats targeting healthcare workloads are detected rapidly and investigated efficiently
  • maintaining HIPAA compliance and Amazon's security bar. You will also leverage AI/LLM-powered tooling to scale detection, triage
  • response beyond traditional approaches. Key job responsibilities Design, build
  • maintain detection-as-code capabilities across cloud infrastructure (CloudTrail, GuardDuty, VPC Flow Logs), SaaS applications, endpoints
  • identity systems, improving coverage and signal quality Develop and deploy detections and monitoring for agentic applications and AI services, including anomaly detection for LLM-powered tools, agent orchestration systems
  • AI service APIs Build automated investigation and response workflows that replace manual runbooks, leveraging AI to scale triage, enrichment, containment
  • remediation Develop and deploy AI/LLM-powered tooling to accelerate investigations, reduce alert fatigue
  • extend team capacity beyond traditional headcount constraints Continuously monitor telemetry data, alerting systems
  • dashboards for early signals of degradation, compromise
  • abuse across AHS environments Triage and correlate alerts from multiple sources to identify patterns, reduce noise
  • surface high-fidelity signals before impact escalates Lead and participate in incident response, including detection, investigation, containment
  • retrospectives, identifying root causes and driving long-term resilience improvements Partner cross-functionally to expand logging, improve observability
  • embed detection capabilities into the development lifecycle Proactively identify gaps in visibility or detection coverage and translate ambiguous threat landscapes Develop and maintain security documentation including detection coverage maps, threat models, runbooks
  • monitoring architecture guidelines About the team The HealthSec Detections & Monitoring team protects Amazon's healthcare services by building and operating detection and monitoring capabilities at scale. We detect threats across cloud infrastructure, applications, endpoints
  • AI systems—and we build AI-powered tooling to make our detections smarter and our response faster. Amazon Security offers talented security professionals the chance to accelerate their careers with opportunities across cloud, devices, retail, entertainment, healthcare, operations
  • physical stores. Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path
  • includes alternative experiences, don’t let it stop you from applying. Why Amazon Security? At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations
  • physical stores. Inclusive Team Culture In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives
  • voices. Training & Career Growth We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training
  • other career-advancing resources here to help you develop into a better-rounded professional. Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home
  • is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
  • 5+ years of security-related professional experience - Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics)
  • 2+ years of IT Security experience - Experience demonstrating software engineering skills in a previous intership, work experience, coding competitions
  • experience with programming/scripting (Batch, VB, PowerShell, Java, C#, Chef, Perl, Ruby and/or PHP) and experience that includes strong analytical skills, attention to detail
  • effective communication abilities - Experience directly working with cloud hosting technologies (AWS, Azure, etc.) - Experience applying threat modeling or other risk identification techniques or equivalent - Experience with log aggregation and analysis platforms (e.g., Splunk, OpenSearch, ELK, Datadog) and/or endpoint detection tools (e.g., SentinelOne, CrowdStrike)
  • Experience in Linux/RHEL
  • experience in Kubernetes, Docker or containers ecosystem - Knowledge of security and compliance standards including HIPAA and GDPR - Experience in automation or monitoring frameworks, deployment or development - Experience building detection-as-code frameworks or custom detection pipelines - Experience building AI/LLM-powered security tooling or applying AI to detection, triage
  • investigation workflows - Understanding of generative AI technologies, large language models
  • AI agents, with ability to identify security risks in agentic architectures - Experience with threat intelligence, threat hunting
  • attacker tradecraft frameworks such as MITRE ATT&CK - Experience with automated response/SOAR platforms or building investigation automation Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability
  • other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications
  • location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off
  • parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits . USA, WA, Seattle - 159,300.00 - 202,400.00 USD annually

Required skills

AWSCloudTrailGuardDutyVPC Flow LogsAILLManomaly detectionautomationmonitoringLinuxKubernetesDockerSplunkOpenSearchELK
Posted on JobRush — the end-to-end AI job-search platform.