Full Job Description
The Ads Security organization at Amazon is dedicated to creating innovative technical solutions that detect, assess, and mitigate security risks within Amazon's Advertising businesses. Our vision is to accelerate the development velocity of the Advertising business by ensuring that our products are inherently secure. We are seeking a talented engineer to join our team, where you will have the opportunity to contribute to securing web applications and services critical to delivering exceptional customer and partner experiences at scale in Amazon Ads.
The ideal candidate background in product security engineering, experience in establishing security standards for AI security, cross-cloud deployments, and a deep understanding of cloud security, particularly within AWS platforms. You will conduct independent security reviews, conduct penetration tests as necessary, and provide guidance to stakeholders on remediation strategies and best practices for integrating security into their application platforms. Your role will be pivotal in ensuring the protection of customer data and critical infrastructure within the Ads organization.
Key job responsibilities
As a Security Engineer within Amazon's Ads Security team, you will play a crucial role in ensuring that applications across numerous Ads platforms are designed and executed with the highest security standards to maintain customer trust. You will tackle a diverse array of security challenges, ranging from novel threats in Ads services to selecting and implementing scalable and secure features such as key management solutions and encrypted storage. Additionally, you will serve as a subject matter expert, providing guidance to developers on building secure products and fostering a security-conscious culture within the organization.
* Collaborate directly with service and platform owners to advise on security best practices and tool implementation.
* Perform comprehensive security assessments on SaaS implementations, data management systems, and reporting frameworks being used internally by Amazon Ads teams or externally by Amazon Ads customers.
* Coordinate and oversee penetration testing activities for platforms and tools.
* Identify security risks, report findings, and recommend solutions for complex security issues by leveraging existing set of detections and/or design new detections within Amazon's various security detection frameworks.
* Contribute to fostering a strong security culture at Amazon through knowledge sharing and collaboration.
* Engage in cross-team projects aimed at enhancing the security posture of Amazon and customer data throughout its lifecycle.
A day in the life
Activities in this role include:
• Identifying security issues and risks, review & approve mitigation plans for Ads products.
• Influencing product teams and senior leadership to implement practices that maintain a high security bar.
• Advising teams developing products on the correct components that deliver security features like key management, authentication, encryption, etc.
• Proposing, collaborating & obtaining buy-in on strategic security initiatives.
• Recommending and developing security-focused tools that help product teams prevent security misconfigurations & vulnerabilities in the design & implementation of features.
• Developing and interpreting security policies and procedures to form security requirements.
• Developing training that promotes general security awareness and informs developers on how to discover & mitigate security vulnerabilities in their products.
• Deciding which new security tooling and strategies should be pursued for scalable security in service development.
• Supporting incident response activities as a security subject matter expert.
About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.
BASIC QUALIFICATIONS
- Bachelor's degree in computer science or equivalent
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- 5+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Experience implementing security solutions at the business division level or equivalent
PREFERRED QUALIFICATIONS
- Experience with security in service-oriented architectures and web services
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
- Knowledge of network and web related protocols such as TCP/IP, UDP, IPSEC, HTTP or equivalent
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, Sunnyvale - 166,600.00 - 212,800.00 USD annually
USA, WA, BELLEVUE - 159,300.00 - 202,400.00 USD annually