Job summary The AWS Cloud Response Team manages the security and availability of AWS Cloud services. We operate on the ‘AWS’ side of the Shared Responsibility Model to ensure “Security of the Cloud” and to protect our customers. This role requires engineers to work tactically with both internal and external stakeholders to solve security challenges at massive scale, and to think strategically to develop and implement changes to drive automation, scalability and continuous progress for the organization. We’re looking for talented software and systems professionals with a passion for security who thrive in high pressure environments to help us continue to raise the security bar for cloud computing. This role is available in either Sydney OR Melbourne, at the candidate’s preference. Successful candidates should:
be able to assess technical vs. business risks and consistently drive internal engineering teams to take the right actions in the appropriate time frames to mitigate risks.
have a good mix of broad and deep technical knowledge and a demonstrated background in information security.
be technically proficient in the fields of network and operating system security, cryptography, software security, security operations, incident response, and emergent security intelligence.
possess a combination of troubleshooting, technical, and communication skills, as well as the ability to manage a mix of disparate tasks which may include small-project and software development work.
be comfortable challenging and escalating to senior leadership to always ensure the best outcome for customers.
An ideal candidate should be able to conduct most of the following:
Triage/assess security issues and engage with internal service teams to ensure prompt remediation of issues, escalating internally as necessary to ensure the right level of urgency and engagement.
Participate in efforts to promote security throughout the Company and build good working relationships within the team and with others across Amazon.
Demonstrate high ability and tolerance for extreme context switching and interruptions while staying productive and effective.
Develop pragmatic solutions that achieve business requirements while keeping an acceptable level of risk.
Help with recruiting activities and administrative work.
Mentoring of junior staff and proactively share knowledge sharing within the team and across the company.
Fulfill regular on-call responsibilities.
#SecOps Key job responsibilities
Supply oversight of in-flight security issues.
Triage new incoming issues to determine the level of risk they present to AWS, and then accordingly prioritise its remediation in conjunction with the impacted service team.
Communicate the state of these issues to various audiences, both technical and non-technical, at various levels of seniority (up to and including AWS’ Chief Information Security Officer).
Escalate issues to senior AWS leadership if you feel your issues are not being treated at the correct pace due to their impact to ensure that we are putting customers first.
Explore building and improving our tooling to make your own life easier, and at the same time, sharing that benefit with all our engineers globally.
A day in the life In the morning you will take handover from the previous site and be delegated ownership of various security issues presently in-flight. The issues could relate to any of our 200+ products, so you will often need to learn on the go. You will engage various stakeholders, such as the internal service team who actually needs to fix the issue, along with AWS Security Leadership, Legal, and the leadership from the impacted service team. As the day progresses, new issues will be automatically assigned to you based on your workload and you will be responsible for triaging them, determining their level of impact, and work towards resolving them at the appropriate pace. At the end of the day, you will document all the issues you are tracking so they can be taken over by the site relieving you. About the team Cloud Response is a team inside AWS Security Operations. This team is broadly responsible for the 'AWS' side of the Shared Responsibility Model, and provides oversight of security issues from their identification through to resolution. Cloud Response operates follow-the-sun with teams based around four different geographical locations. We work with other AWS teams, to ensure security issues are resolved with the right level of urgency, whilst ensuring that our stakeholders are kept into the loop.