Full Job Description
We are seeking a Security Engineer to join the AppSec organization and support Application Ranking AppRank (application criticality measurement) - a critical initiative to identify Amazon's most critical applications and criteria. In this role, you will leverage your application architecture excellence to engineer scalable, innovative solutions to assess application criticality criteria for the identification of systemic patterns across business units. Your work will directly impact the security posture of Amazon's most strategic lines of business.
You will collaborate closely with software engineering teams, product managers, and security leadership to ensure the most critical applications are identified early in the software development lifecycle at scale.
The ideal candidate blends strong technical execution with security intuition, and thrives in environments where they can influence, automate, and scale security impact. You should be comfortable translating complex application architecture into actionable insights and driving adoption of security best practices across a large and distributed engineering organization.
Key job responsibilities
Engineer AI-driven solutions to assess and classify security findings across business units
Identify root causes of recurring vulnerabilities and develop systemic remediation strategies
Design and build internal tools to analyze patterns in security findings and prevent recurrence
Collaborate with application teams to implement preventative security controls earlier in the development lifecycle (Shift-Left)
Develop automated workflows to integrate security insights into developer pipelines
Perform targeted code reviews and static/dynamic analysis to validate findings and guide mitigations
Contribute to the creation of security dashboards and metrics for visibility into finding trends and remediation velocity
Partner with security leadership and engineering stakeholders to define and prioritize high-impact prevention efforts
Investigate and eradicate classes of vulnerabilities through scalable solutions
Guide teams through remediations by providing technical mentorship and secure design best practices
Maintain deep awareness of emerging threats, and proactively adapt tooling and processes to address them
A day in the life
You split your time between building, investigating, and advising. Some mornings you're deep in the risk-prioritization engine; refining how it classifies and scores risk so application reviews are focused on what actually matters. Other days you may be fielding questions, helping teams understand their risk posture and working through disagreements with technical depth.
You collaborate as much as you code; pairing with application teams to help understand and resolve risk for their applications at scale.
BASIC QUALIFICATIONS
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
- Knowledge of industry-based security vulnerabilities and remediation techniques
- Experience in scripting, programming, and security code reviewing in a common programming language (non-internship)
- Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience)
- 4+ years of any combination of the following: application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing experience
- Knowledge of one or more of the following domains: access-control system and methodology, network security, application- and system-development security, security architecture and models, cryptography, and operations security
- Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or equivalent work experience
PREFERRED QUALIFICATIONS
- Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
- Experience with AWS products and services
- Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, TX, Austin - 159,300.00 - 202,400.00 USD annually