Acti Cyber Threat Exploitation Engineer, Amazon Cyber Threat Intelligence

5 giorni fa


Lazio, Italia Amazon A tempo pieno

Job ID: ******* | Amazon.com Services LLC We are open to hiring candidates to work out of one of the following locations:Annapolis Junction, MD, USAArlington, VA, USAAustin, TX, USAHerndon, VA, USANew York, NY, USASeattle, WA, USAAmazon is seeking an innovative Senior Security Engineer to join the Amazon Cyber Threat Intelligence (ACTI) team as a Cyber Threat Exploitation Engineer where you will leverage your in-depth knowledge and analysis of emergent exploits, exploit frameworks, and vulnerabilities to identify novel threat actors, discover attacks against Amazon, AWS and its customers.ACTI is responsible to identify, curate, and report timely, accurate, and actionable threat intelligence.ACTI delivers cyber threat intelligence to Amazon and AWS leadership, service teams, partners, and both internal and external customers.In the Cyber Threat Exploitation Engineer role you will formulate new analytic techniques and work across teams to drive the supporting capabilities.A deep understanding of advanced actor tactics, techniques, and procedures (TTPs) is required, as well as how those TTP's will present themselves in network-based and host-based logs derived from software, operating systems, networks, cloud infrastructure, networking equipment, and web applications.In addition, you will script and help automate recurring tasks to improve the overall effectiveness of the intelligence and how it is utilized throughout Amazon and AWS.Beyond direct technical work on exploits, vulnerability research, and threat intelligence, the Cyber Threat Exploitation Engineer will steer strategic direction in the secure design of AWS services, drive tactical results from red and blue team engagements, coordinate takedowns of malicious infrastructure, and drive effective technical countermeasures.Key job responsibilitiesIdentify, research, and analyze novel vulnerabilities discovered in threat intelligence data, applications, devices, and networksInterface with ACTI reverse engineers to provide reversing requirements as well as be able to independently triage malware, analyze exploit samples, and study attack techniques to understand how vulnerabilities are being weaponizedPursue actionable intelligence on current exploits, perform deep dive analysis of malicious artifacts related to software exploits, and use that data to identify attacks against Amazon, AWS, and its customersAnalyze large and unstructured data sets to identify trends and anomalies indicative of malicious activitiesCreate security techniques and automation for internal use that enable the team to operate at high speed and broad scaleProvide situational awareness on the current threat landscape and the techniques, tactics, and procedures associated with specific threatsAccurately document ongoing investigations, craft consumable threat intelligence products, and clearly present and communicate emerging threats and high-risk vulnerabilities in operating systems and software libraries, cloud, network devices, and web applications to key stakeholdersPeriodic on-call responsibilitiesA day in the lifeThe Amazon Cyber Threat Intelligence (ACTI) - Vulnerability & Exploitation team is responsible for developing actionable intelligence on exploits and vulnerabilities utilized by advanced cyber threats against Amazon, AWS, and customers.We obtain indicators and intelligence from a variety of internal and external sources and use that information to develop an understanding of sophisticated, emerging actors, and their tools, techniques, and procedures.We then leverage that understanding to proactively identify and mitigate malicious activity.About the teamDiverse ExperiencesAmazon Security values diverse experiences.Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply.If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences.Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services.We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it's in our nature to learn and be curious.Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness.Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe're continuously raising our performance bar as we strive to become Earth's Best Employer.That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony.Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture.When we feel supported in the workplace and at home, there's nothing we can't achieve.Basic QualificationsBS degree in computer science, computer engineering, or related field, or 5+ years of technical work experience5+ years of industry-based experience in security vulnerabilities identification, attack patterns, and remediation techniques (non-internship) experience5+ years of any combination of the following: application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing experience5+ years of automation scripting using Python, Bash, Shell and/or Perl experience5+ years of SQL experienceKnowledge of and experience with cloud infrastructure technologiesPreferred QualificationsMaster's degree in computer science, computer engineering, or related field, or MS degree5+ years experience Threat Intelligence research and analysis related to software exploits and the creation of corresponding detections and/or countermeasuresExperience with malware analysis, network flow analysis, and large scale data analysisExperience with firmware reverse engineering, and analysis of ARM, MIPS, and x***** binaries.Experience fuzzing software for correctness and triaging crashes, Web application enumeration and attack surface analysisStrong understanding of Windows, Linux, and or OS X internals, web, and common software vulnerabilities, to include, functional understanding of stack, heap exploitation along with general web application exploitation (SQLi, XSS, command injection, authentication bypass)Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.Our inclusive culture empowers Amazonians to deliver the best results for our customers.If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information.If the country/region you're applying in isn't listed, please contact your Recruiting Partner.Our compensation reflects the cost of labor across several US geographic markets.The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market.Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.Amazon is a total compensation company.Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits.For more information, please visit .This position will remain posted until filled.Applicants should apply via our internal or external career site.#J-*****-Ljbffr



  • Lazio, Italia Amazon A tempo pieno

    A leading e-commerce and tech company is seeking a Senior Security Engineer to join their Cyber Threat Intelligence team.This role involves identifying vulnerabilities and enhancing threat intelligence strategies.The ideal candidate should have a strong background in security vulnerabilities, automation scripting, and data analysis.Responsibilities include...


  • Lazio, Italia Gruppo Maggioli A tempo pieno

    Un'azienda nel settore della sicurezza informatica cerca un esperto in Cyber Threat Intelligence per gestire l'implementazione di programmi, condurre analisi strategiche e gestire incidenti di sicurezza.Richiesta esperienza consolidata di almeno 5 anni in Cyber Threat Intelligence e Digital Forensics, oltre a competenze presales.Vantaggi includono buoni...


  • Lazio, Italia Gruppo Maggioli A tempo pieno

    Un'azienda di cybersicurezza cerca un esperto in Cyber Threat Intelligence con almeno 5 anni di esperienza.Responsabile della gestione di programmi di Cyber Threat Intelligence e Incident Response, richiede forti competenze in Digital Forensics, eccellenti capacità comunicative in italiano e inglese, e una certificazione professionale.L'azienda offre buoni...

  • Cyber Threat Intelligence

    1 settimana fa


    Lazio, Italia Altro A tempo pieno

    Dinova è il luogo in cui la trasformazione digitale si fonde con la passione e l'innovazione.Creiamo ecosistemi unici in cui tecnologie all'avanguardia, talenti eccezionali, dati avanzati e processi dinamici si fondono in una simbiosi perfetta.Se sogni di contribuire a rendere le aziende posti migliori in cui lavorare e vivere, allora potresti essere la...

  • Cyber Threat Intelligence

    1 settimana fa


    Lazio, Italia Gruppo Maggioli A tempo pieno

    Dinova è il luogo in cui la trasformazione digitale si fonde con la passione e l'innovazione.Creiamo ecosistemi unici in cui tecnologie all'avanguardia, talenti eccezionali, dati avanzati e processi dinamici si fondono in una simbiosi perfetta. Se sogni di contribuire a rendere le aziende posti migliori in cui lavorare e vivere, allora potresti essere la...


  • Lazio, Italia Gruppo Maggioli A tempo pieno

    Una azienda innovativa nel settore digitale in Italia cerca un professionista esperto in Cyber Threat Intelligence e Digital Forensics.Richiesti almeno 5 anni di esperienza in questo ambito, eccellenti capacità comunicative in italiano e inglese, oltre al possesso di certificazioni tecniche riconosciute.La posizione prevede responsabilità nella gestione di...

  • Threat Content Developer

    2 settimane fa


    Lazio, Italia Integrity360 A tempo pieno

    Join to apply for the Threat Content Developer role at Integrity3601 week ago Be among the first 25 applicantsAbout UsIntegrity360 is the largest independent cyber security provider in Europe, with a growing international presence spanning the UK, Ireland, mainland Europe, Africa and the Caribbean.With over 700 employees, across 12 locations, and six...


  • Lazio, Italia Canonical A tempo pieno

    A leading tech company is seeking a Threat Intelligence Lead to develop and execute a threat intelligence strategy, focusing on understanding cyber threats targeting software supply chains.The ideal candidate will collaborate with internal teams and the cybersecurity community, utilizing OSINT tools and analytical skills.This role provides unique...


  • Lazio, Italia Agap2 Italia A tempo pieno

    Consulente Cyber Security con esperienza senior in sicurezza OT, focalizzato su protezione di infrastrutture critiche e ambienti industriali ICSS/SCADA.1. Il tuo ruoloOpererai come Cyber Security Consultant specializzato in ambienti OTSupporterai clienti enterprise e industriali su progetti di sicurezza avanzataContribuirai all'analisi di minacce cyber su...

  • Cyber Security Consultant

    2 settimane fa


    Lazio, Italia Agap2 Italia A tempo pieno

    Cyber Security Consultant OT – Roma Consulente Cyber Security con esperienza senior in sicurezza OT, focalizzato su protezione di infrastrutture critiche e ambienti industriali ICS/SCADA.1. Il tuo ruoloOpererai come Cyber Security Consultant specializzato in ambienti OTSupporterai clienti enterprise e industriali su progetti di sicurezza...