Key job responsibilities
- Lead a strategic security initiative end to end - scoping, design, implementation, testing, deployment, and maintenance - while guiding other engineers along the way.
- Build security automation and AI-powered tooling that scales beyond one-off reviews: prevention rules, secure defaults, and paved paths that stop vulnerabilities before they reach production.
- Review application architecture and designs, leading security design reviews and steering builders toward secure-by-default solutions.
- Consult directly with development teams, resolving findings and giving fast, actionable guidance that meets or exceeds the security bar.
- Find opportunities to centralize controls so many teams can adopt one solution instead of each building their own, reusing what already exists wherever possible.
- Dig into ambiguous, high-impact risks, spot patterns across a large application footprint, and fix root causes with reproducible mechanisms that are simple, maintainable, and built to last.
- Communicate risk and recommendations clearly to engineers, partner security teams, and business stakeholders, and speak up for the right outcome even when it isn't the popular one.
- Coach and mentor teammates to raise the bar on how the team works and the value it delivers.
A day in the life
Most days you'll split your time between the strategic project you own and the builders who need you. You might start by advancing your project - designing a piece of automation or AI tooling - then jump into a design review to help a team ship securely, or dig into a tricky consult where the right answer isn't obvious. You'll partner closely with development teams across our operations and grocery businesses, and with other security teams whose work connects to yours. When an urgent security issue comes up, you'll help contain it and make sure the fix sticks.
BASIC QUALIFICATIONS
- 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
- Experience owning and leading significant projects from concept to deployment
- Experience communicating security risk to technical and non-technical stakeholders in writing
- 3+ years of application security engineering experience (security design reviews, threat modeling, code-level vulnerability analysis)
- Experience carrying a builder-facing security consult load (intake, triage, guidance, resolution tracking)
PREFERRED QUALIFICATIONS
- Experience in a logistics/operations environment
- Experience in root cause analysis and error correction, identifying changes to procedures and systems to implement long-term fixes and avoid repeating issues
- Experience in mentoring, leading, or managing more junior engineers
- Experience with cloud security in AWS (IAM, VPC, KMS, CloudTrail, or equivalent services)
- Experience building automated security controls or shifting security left in CI/CD pipelines
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, Irvine - 159,300.00 - 202,400.00 USD annually