Are you motivated to protect customers at scale by building security into every third-party interaction? The Secure Third Party Tools (S3T) team within Amazon Security is shifting how we safeguard customer trust - moving from reactive assessments to proactive, automated protection. As a Security Engineer on this team, you will combine technical review expertise with a builder's mindset to evaluate third-party services, identify risks, and contribute to tooling that codifies security decisions into repeatable automation. You'll collaborate closely with service teams and senior security engineers, communicating risk clearly and driving resolution. This is a role for someone who is curious, adaptable, and eager to grow their security engineering craft while strengthening how Amazon manages vendor risk.
Key job responsibilities
- Perform technical security reviews of third-party services - including AI/ML integrations, cloud architectures, and services handling sensitive customer data - identifying gaps in security controls and recommending mitigations.
- Trace data flows through complex systems, threat model third-party use cases, and evaluate vendor penetration test reports to surface risks and drive proportionate remediation decisions.
- Contribute to AI-powered security tooling and automation that scales review decisions across the organization, scripting solutions and improving existing runbooks.
- Communicate identified risks and recommendations in written and verbal form to service teams and leadership, escalating where appropriate to drive resolution.
- Author and refine security decision rubrics and implementation patterns so that future engineers can build upon your findings.
A day in the life
You start by picking up a new third-party engagement, reviewing the architecture diagrams and data-flow documentation the service team has provided. You apply threat modeling to identify where sensitive data crosses trust boundaries, then draft your findings and discuss them with a senior engineer during a checkpoint. After lunch you might write a script to automate a repetitive validation step, or update the team's internal tooling with a new decision pattern you've identified. Your work feeds directly into the automation that makes the next review faster and more consistent.
BASIC QUALIFICATIONS
- 2+ years of web protocols, common security attacks, and remediation (non-internship) experience
- Bachelor's degree in Engineering, Computer Science, or a related field
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
- Experience with web protocols, common security attacks, and remediation (non-internship)
- Experience solving basic problems by writing code or scripts with some assistance
PREFERRED QUALIFICATIONS
- Experience with AWS services or other cloud offerings
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, TX, Austin - 136,000.00 - 184,000.00 USD annually