{"schemaVersion":"jobsearcher.job.v1","id":"8975777b96b116e7816daf32","url":"https://jobsearcher.com/jobs/8975777b96b116e7816daf32","canonicalUrl":"https://jobsearcher.com/jobs/8975777b96b116e7816daf32","title":"Security Incident Response, Security Engineer, US Amazon Dedicated Cloud Security","description":"Overview\nIn this role you will detect, investigate, and respond to threats against a secure, air-gapped government program building a classified AI Factory. You’ll work closely with detection engineers, SOC analysts, forensics, and government counterparts to keep a high-value system defensible around the clock. You drive incidents through containment, eradication, and recovery, and translate learnings into improved detections and playbooks. This position offers hands-on incident response in a mission-focused, privacy- and security-critical environment with meaningful impact.\n\nCompensation / Benefitshealth insurance (medical, dental, vision)401(k) matchingpaid time offparential leaveRSUssign-on payments\nResponsibilitiesMonitor security telemetry, triage alerts, and investigate incidents on the disconnected platformDrive full incident lifecycle from containment to recovery and after-actionDevelop and tune detection content and response playbooks from incident learningsCoordinate incident reporting and handoffs with ISSM and Government counterparts\nKey requirementsExperience triaging and developing security alerts and response automationFundamentals of networking, security, databases (relational or NoSQL), and operating systems (Unix, Linux, Windows)3+ years of incident response, SOC, or security operations experienceCurrent, active TS/SCI security clearance with Polygraphcollaboration with cross-functional teamscommunication under pressureproblem-solving and initiativeincident response and alert handlingsecurity operations center (SOC) practicesdetection content development and tuning","company":"Amazon","rawCompany":"amazon","city":"McLean","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-09-15T03:23:14.993Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"518210","title":"Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services","slug":"computing-infrastructure-providers-data-processing-web-hosting-and-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Incident Response, Security Engineer, US Amazon Dedicated Cloud Security","description":"Overview\nIn this role you will detect, investigate, and respond to threats against a secure, air-gapped government program building a classified AI Factory. You’ll work closely with detection engineers, SOC analysts, forensics, and government counterparts to keep a high-value system defensible around the clock. You drive incidents through containment, eradication, and recovery, and translate learnings into improved detections and playbooks. This position offers hands-on incident response in a mission-focused, privacy- and security-critical environment with meaningful impact.\n\nCompensation / Benefitshealth insurance (medical, dental, vision)401(k) matchingpaid time offparential leaveRSUssign-on payments\nResponsibilitiesMonitor security telemetry, triage alerts, and investigate incidents on the disconnected platformDrive full incident lifecycle from containment to recovery and after-actionDevelop and tune detection content and response playbooks from incident learningsCoordinate incident reporting and handoffs with ISSM and Government counterparts\nKey requirementsExperience triaging and developing security alerts and response automationFundamentals of networking, security, databases (relational or NoSQL), and operating systems (Unix, Linux, Windows)3+ years of incident response, SOC, or security operations experienceCurrent, active TS/SCI security clearance with Polygraphcollaboration with cross-functional teamscommunication under pressureproblem-solving and initiativeincident response and alert handlingsecurity operations center (SOC) practicesdetection content development and tuning","datePosted":"2026-09-15T03:23:14.993Z","dateModified":"2026-09-15T03:23:14.993Z","hiringOrganization":{"@type":"Organization","name":"Amazon","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"McLean","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"8975777b96b116e7816daf32"},"url":"https://jobsearcher.com/jobs/8975777b96b116e7816daf32"}}