Security Intelligence Engineer Incident Response Threat Intelligence ACTI
Overview
Threat Intelligence Engineer leading proactive defense against advanced cyber threats for Amazon employees and assets. This role drives incident response, develops analytic techniques, and collaborates across teams to mitigate malicious activity. Candidates must analyze large datasets, create automation, and contribute to threat intelligence.
What You'll Do11
- 1Analyze large unstructured data sets to identify malicious activity trends
- 2Create automation for rapid threat detection and mitigation
- 3Contribute to Amazon threat landscape understanding
- 4Perform deep dive analysis of malicious artifacts
- 5Draft and publish threat intelligence reports
- 6Lead on-call rotations for incident response
- 7Collaborate with cross-functional teams to improve defenses
- 8Develop security techniques operating at high scale
- 9Investigate root causes through forensic analysis
- 10Maintain up-to-date knowledge of TTPs and actor behaviors
- 11Drive continuous improvement of detection and response processes
Requirements10
- 15+ years building ETL pipelines with Spark and Airflow
- 23+ years scripting programming and security code review
- 32+ years troubleshooting systems logs or automating tasks
- 4Bachelor's degree in STEM field or 3+ years IT Security experience
- 5Knowledge of HTTP DNS TCP/IP networking protocols
- 6Experience with AWS products and services
- 7Familiarity with Python Java C++ programming languages
- 8Understanding of command line tools for protocol analysis
- 9Exposure to AWS security features
- 10Demonstrated ability to work in collaborative team environments
Salary Insight
$159 - $202k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

TexcelVision Inc.
VerifiedOnsite Cybersecurity Threat Intelligence Analyst Austin TX
Lead the development and execution of threat intelligence programs that protect enterprise assets. Own the end-to-end pipeline from data ingestion to actionable insights. Drive security posture through proactive analysis and stakeholder collaboration.
Robert Half
VerifiedSecurity Analyst, Cloud Security Operations
You will own threat detection and incident response for cloud-based workloads at a growing fintech. You will triage alerts, hunt for malicious activity, and tune detections across AWS and Azure. You will partner with engineering and IT to reduce risk and improve response workflows. This role stands out for its emphasis on building detection content and automating response with Python and Splunk.
Risk Management Foundation
VerifiedSecurity Engineer Boston
The Cybersecurity Engineer reports to the Chief Information Security Officer and leads security engineering and operations. This role owns security technologies and processes protecting organizational information assets. It involves assessing risks implementing safeguards supporting GRC and AI security initiatives. The position differs by focusing on AI governance and cross-functional collaboration.
anavationllc
VerifiedSecurity Infrastructure & Exposure Engineer
Design and scale attack surface management and threat exposure detection capabilities. Engineer internal tools and automated pipelines that proactively map assets and model attack paths to eliminate security blind spots. This role focuses on building robust defenses across cloud and on-premise environments.
Take-Two Interactive Software, Inc.
VerifiedThreat Intelligence Engineer, Cybersecurity & SIEM
Threat Intelligence Engineer at Take-Two Interactive, defending global gaming systems. You will operate the cyber threat intelligence (CTI) program, manage threat feeds, and parse IOCs to protect Rockstar Games, 2K, and Zynga. You'll partner with the GSOC, Detection Engineering, and Incident Response teams to integrate intelligence into SIEM, EDR, and firewalls. This role offers direct impact on security posture in a high-profile entertainment company.
020 Cisco Systems, Inc.
VerifiedSecurity Engineer at Cisco Systems
Join the Talos Security Operations Team as a Security Engineer to protect assets and systems in a fast‑paced environment. You will own security automation and drive improvements across hybrid infrastructures. This role offers a chance to work with industry leaders and make a tangible impact on global security.