Sr. Security Engineer, Global Services Security
Arlington, Virginia, USA
Full Time Senior-level / Expert USD 143K - 247K
Amazon.com
Free shipping on millions of items. Get the best of Shopping and Entertainment with Prime. Enjoy low prices and great deals on the largest selection of everyday essentials and other products, including fashion, home, beauty, electronics, Alexa...
Global Services Security is looking for a Security Engineer to inspect, design, develop, and implement security guidance, mechanisms, and processes to improve the overall security posture of AWS interactions with our internal and external customers. You will build and automate security mechanisms and manual processes that help us inspect, monitor, and alert on the activities and interactions AWS Global Services have when working hand-in-hand with our customers.
A Security Engineer at AWS is expected to be strong in multiple domains and provide significant contributions to the teams within AWS Global Services, Security and to multiple groups throughout Amazon. Security engineers are expected to develop elegant solutions to complex business problems and apply appropriate technologies while following security engineering best practices. You are also expected to mentor more junior engineers and be a security thought leader for the organization.
A Security Engineer must foster constructive dialogue and seek resolution when confronted with discordant views. Engineers in this role are expected to participate fully in the planning of the security team's work and constantly seek opportunities for process improvement. They should also have a deep understanding of at least one specialty for which they are a sought out resource (both within AWS IT Security and by groups throughout Amazon), while having an understanding of the application of Information Security in a broad range of technical areas.
You will have the combination of troubleshooting, technical, and communication skills, as well as the ability to handle a mix of disparate tasks which may include project and software development work. This role will provide career growth opportunities as you gain new security skills in the course of your duties.
Key job responsibilities
• Security tool automation and development
• Application security reviews
• Secure architecture design
• Threat modeling
• Projects and research work as needed
• Security training and outreach to internal development teams
• Security guidance documentation
• Security metrics delivery and improvements
• Assistance with recruiting activities and administrative work
A day in the life
You will enhance existing automation to improve operational efficiency, building new insights from existing data. Identify, evaluate, and prioritize opportunities for automating mechanisms across diverse landscapes of tools, systems, and architectures. Meet with other teams across Global Services to collaborate on security mechanisms, like partner security, improving reviews of security plans, reducing sales to delivery timelines, and improving scoping for high-risk datatypes. Contribute to security training, best practices documentation, and security policies tailored for internal teams engaging with regulated data. You will implement scalable processes and tooling solutions to facilitate regular audits of security controls, guidance,
and compliance standards.
About the team
Diverse Experiences
AWS values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why AWS?
Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that’s why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.
Inclusive Team Culture
Here at AWS, it’s in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences, inspire us to never stop embracing our uniqueness.
Mentorship & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve in the cloud.
- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Knowledge of commonly found software security vulnerabilities (like OWASP top 10) and remediation techniques
- 2+ years of programming in one of the following or similar: Python, Typescript, Ruby, Go, Java, .Net, C++. Our code is a mixture of Python, Typescript, shell, and CloudFormation.
- Experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security
- Experience with Security Engineering (building tools) and Assurance methodologies e.g. fuzzing, static and dynamic code analysis
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.
A Security Engineer at AWS is expected to be strong in multiple domains and provide significant contributions to the teams within AWS Global Services, Security and to multiple groups throughout Amazon. Security engineers are expected to develop elegant solutions to complex business problems and apply appropriate technologies while following security engineering best practices. You are also expected to mentor more junior engineers and be a security thought leader for the organization.
A Security Engineer must foster constructive dialogue and seek resolution when confronted with discordant views. Engineers in this role are expected to participate fully in the planning of the security team's work and constantly seek opportunities for process improvement. They should also have a deep understanding of at least one specialty for which they are a sought out resource (both within AWS IT Security and by groups throughout Amazon), while having an understanding of the application of Information Security in a broad range of technical areas.
You will have the combination of troubleshooting, technical, and communication skills, as well as the ability to handle a mix of disparate tasks which may include project and software development work. This role will provide career growth opportunities as you gain new security skills in the course of your duties.
Key job responsibilities
• Security tool automation and development
• Application security reviews
• Secure architecture design
• Threat modeling
• Projects and research work as needed
• Security training and outreach to internal development teams
• Security guidance documentation
• Security metrics delivery and improvements
• Assistance with recruiting activities and administrative work
A day in the life
You will enhance existing automation to improve operational efficiency, building new insights from existing data. Identify, evaluate, and prioritize opportunities for automating mechanisms across diverse landscapes of tools, systems, and architectures. Meet with other teams across Global Services to collaborate on security mechanisms, like partner security, improving reviews of security plans, reducing sales to delivery timelines, and improving scoping for high-risk datatypes. Contribute to security training, best practices documentation, and security policies tailored for internal teams engaging with regulated data. You will implement scalable processes and tooling solutions to facilitate regular audits of security controls, guidance,
and compliance standards.
About the team
Diverse Experiences
AWS values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why AWS?
Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that’s why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.
Inclusive Team Culture
Here at AWS, it’s in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences, inspire us to never stop embracing our uniqueness.
Mentorship & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve in the cloud.
Basic Qualifications
- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Knowledge of commonly found software security vulnerabilities (like OWASP top 10) and remediation techniques
- 2+ years of programming in one of the following or similar: Python, Typescript, Ruby, Go, Java, .Net, C++. Our code is a mixture of Python, Typescript, shell, and CloudFormation.
Preferred Qualifications
- Experience with AWS products and services- Experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security
- Experience with Security Engineering (building tools) and Assurance methodologies e.g. fuzzing, static and dynamic code analysis
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.
Job stats:
0
0
0
Category:
Security Engineering Jobs
Tags: Application security Audits Automation AWS C Cloud Code analysis Compliance Cryptography Java Network security OWASP Python Ruby TypeScript Vulnerabilities
Perks/benefits: Career development Conferences Equity / stock options Health care Startup environment Team events
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Specialist jobsSecurity Operations Engineer jobsSenior Security Analyst jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsCybersecurity Editor jobsCybersecurity Content Editor jobsSenior Information Security Analyst jobsInformation Security Manager jobsCyber Security Specialist jobsSenior Network Security Engineer jobsIT Security Analyst jobsSenior Information Security Engineer jobsChief Information Security Officer jobsSecurity Consultant jobsInformation System Security Officer (ISSO) jobsSenior Product Security Engineer jobsIT Security Engineer jobsSecurity Specialist jobsInformation Systems Security Engineer jobsCyber Threat Intelligence Analyst jobsSenior Cyber Security Engineer jobsSenior Software Engineer jobsSecurity Operations Analyst jobsSenior IT Auditor jobs
EDR jobsSaaS jobsCEH jobsEncryption jobsJava jobsSplunk jobsThreat detection jobsTop Secret jobsSDLC jobsTerraform jobsMalware jobsIDS jobsRMF jobsIPS jobsSQL jobsSOC 2 jobsFinance jobsDocker jobsForensics jobsCompTIA jobsOWASP jobsIntrusion detection jobsActive Directory jobsVPN jobsITIL jobs
HIPAA jobsAnsible jobsGIAC jobsClearance Required jobsCRISC jobsIT infrastructure jobsTCP/IP jobsDoDD 8570 jobsOSCP jobsMITRE ATT&CK jobsSOAR jobsZero Trust jobsBanking jobsSOX jobsIndustrial jobsData Analytics jobsJira jobsDNS jobsCCSP jobsNIST 800-53 jobsGCIH jobsCISO jobsArtificial Intelligence jobsUNIX jobsJavaScript jobs