1 day ago
Bellevue, WA, USAMid Level
H1B sponsor
Base Salary
$159k - $202k/yr
Responsibilities
- Own the end-to-end design, implementation, maintenance, and expansion of AI-powered threat-hunting capabilities.
- Conduct hypothesis-driven hunts across large attack surfaces using AI for signal correlation, lead triage, and anomaly discovery.
- Develop agentic workflows that generate hypotheses, gather evidence, and investigate leads with human oversight.
- Build evaluation and feedback frameworks to improve accuracy, recall, reliability, and detection coverage while reducing false negatives and alert fatigue.
- Operationalize hunt findings, respond to identified threats, and convert findings into durable, high-fidelity detections.
- Map hunting coverage and findings to MITRE ATT&CK and relevant adversary tradecraft.
- Partner with teams to adapt models for anomaly detection, log analysis, and natural-language security queries.
- Define technical roadmaps, author design documents and threat models, mentor engineers, and establish operational standards for AI hunting systems.
- Participate in Ads Security, threat-hunting, and detection-services on-call rotations and support incidents and service degradation.
- Contribute to planning, team development, code reviews, technical mentoring, career coaching, and ad-hoc security initiatives.
Requirements
- Bachelor's degree in computer science or equivalent.
- At least 3 years of programming experience in Python, Ruby, Go, Swift, Java, .NET, C++, or a similar object-oriented language.
- At least 3 years of threat hunting, threat detection, incident response, or threat intelligence experience, including hypothesis-driven hunting across large-scale log and telemetry data.
- At least 2 years of experience applying AI/ML to threat hunting, including prompt engineering, LLM integration, or ML pipeline development.
- Hands-on experience with MITRE ATT&CK, adversary tradecraft, and translating hunt findings into detections.
- Proficiency querying and analyzing large security datasets, including SIEM, data lakes, or log analytics platforms.
- Experience with cloud security architecture, preferably AWS, including IAM, VPC, KMS, and security monitoring services.
- Preferred qualifications include CCSP, CEH, CFR, Cloud+, CySA+, GCED, GICSP, or PenTest+ certifications.
- Preferred experience includes generative AI or agentic systems for security operations, autonomous investigation pipelines, Amazon Bedrock, SageMaker, RAG architectures, open-source security tools, published AI-security research, APT detection, and advanced threat hunting.
- An advanced degree in computer science, machine learning, cybersecurity, or a related field and AWS certifications are preferred.
Benefits
- Flexible work hours and arrangements are supported.
- Benefits include medical, dental, vision, prescription, life and AD&D insurance, supplemental life-plan options, EAP, mental-health support, a medical advice line, flexible spending accounts, adoption and surrogacy reimbursement, 401(k) matching, paid time off, and parental leave.
- The role includes participation in on-call rotations.
- The position is based in Bellevue, Washington.
About Amazon
Amazon builds and operates a global e-commerce marketplace, logistics network, and consumer devices, and provides cloud computing via AWS for businesses and developers. The company earns revenue from online retail, third‑party seller services, subscriptions like Prime, advertising, and AWS usage. Founded in 1994 and headquartered in Seattle, it is publicly traded on NASDAQ (AMZN) and serves customers in dozens of countries.
