Amazon · Seattle, WA

Salary
$159,300–$202,400from the description
Posted
Jul 2, 2026
Location
Seattle, WA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A detection and monitoring engineering role within Amazon's healthcare security organization, focused on building detection-as-code pipelines, automated investigation and response workflows, and monitoring coverage across cloud infrastructure, SaaS applications, endpoints, and AI/agentic systems. The work involves triaging alerts, leading incident response, and integrating AI/LLM tooling to improve detection quality and reduce manual effort. Suits engineers with a background in cloud security, detection engineering, and scripting.

Senior level · 5+ years · Seattle-Tacoma-Bellevue, WA · Full-time

Advertised as Mid, but the requirements read as Senior.

Must have (6)
AWS, Azure or GCPPython, Go or JavaSplunk, Opensearch or MonitoringSentinelOne or CrowdstrikeGuardDutythreat modeling
Nice to have (6)
Kubernetes or Dockerdetection-as-codeLLMsMITRE ATT&CKSOARHIPAA

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 80 people in the Seattle-Tacoma-Bellevue, WA area plausibly meet what this posting asks for (information security analysts). range 35–150

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Python51%Splunk45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $165,338 (middle half $132,613–$190,632). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The role is titled 'Security Engineer II', which Amazon uses as a mid-level designation (hence the level advertised in the title Mid), but the actual requirements — 5+ years of security experience, production codebase ownership, cloud detection engineering, incident response leadership, and cross-functional partnership — support a Senior-level scope.

This role sits at the boundary between Information Security (detection engineering, incident response, threat modeling) and Software Development (building detection-as-code pipelines, automated response workflows, AI/LLM tooling in production codebases). The primary day-to-day work leans toward security analysis and detection operations, so 15-1212 was chosen; 15-1252 is a credible runner-up given the significant software engineering component.

The Bachelor's degree requirement is in a STEM field 'or 2+ years of IT Security experience', making it substitutable with experience — the degree requirement is therefore set to None.

CloudTrail and GuardDuty are called out explicitly in the required responsibilities section as the cloud telemetry sources the role must work with; they are listed as required skills accordingly.

SentinelOne and CrowdStrike appear together as interchangeable examples of endpoint detection tools under Basic Qualifications; SentinelOne is listed as the primary with CrowdStrike as an alternative.

VPC Flow Logs appears in the job responsibilities narrative rather than the qualifications section and was not extracted as a standalone required skill.

Detection-as-code, LLMs, MITRE ATT&CK, SOAR, and HIPAA all appear under Preferred Qualifications and are marked accordingly.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗