Full Job Description
AWS Security is looking for a Senior Application Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You will be responsible for analyzing the security of applications and services, discovering and addressing security issues, building security automation, and quickly reacting to new threat scenarios. You will have the opportunity to learn from, and be mentored by, those who are building and securing our leading-edge services.
A Security Engineer at Amazon is expected to be strong in multiple domains and provide significant contributions to the AWS IT Security team and to multiple groups throughout Amazon. Security engineers are expected to develop elegant solutions to complex business problems and apply appropriate technologies while following security engineering best practices. You are also expected to mentor more junior engineers and be a security thought leader for the organization.
A Security Engineer must foster constructive dialogue and seek resolution when confronted with discordant views. Engineers in this role are expected to participate fully in the planning of the AWS IT Security team's work and constantly seek opportunities for process improvement. They should also have a deep understanding of at least one specialty for which they are a sought out resource (both within AWS IT Security and by groups throughout Amazon), while having an understanding of the application of Information Security in a broad range of technical areas.
A successful candidate will need a combination of troubleshooting, technical, and communication skills, as well as the ability to handle a mix of disparate tasks which may include project and software development work. This role will provide career growth opportunities as you gain new security skills in the course of your duties.
Responsibilities:
* Application security reviews
* Deeply Threat Modeling AWS services
* Continuous improvement and research work as needed
* Security training and outreach to internal development teams
* Security guidance documentation
* Security tool development
* Security metrics delivery and improvements
* Assistance with recruiting activities and administrative work
Note:
A clearance is not required for this position, however being able to pass program background check(s) is required to be read on to customer programs.
Key job responsibilities
* Application security reviews
* Deeply Threat Modeling AWS services
* Continuous improvement and research work as needed
* Security training and outreach to internal development teams
* Security guidance documentation
* Security tool development
* Security metrics delivery and improvements
* Assistance with recruiting activities and administrative work
A day in the life
Participate in workshops threat modeling leading AWS services. Innovate on how to deliver security outcomes to customers, including novel uses of AI tools to maximize outcomes and free time for high-judgement human decisions.
BASIC QUALIFICATIONS
- 4+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience
- Experience (non-internship) in industry-based security vulnerabilities identification, attack patterns, and remediation techniques
- Experience as a mentor, tech lead or leading an engineering team
- BS degree in computer science or equivalent, or 4+ years of technical work experience
- 5+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
PREFERRED QUALIFICATIONS
- Experience applying threat modeling or other risk identification techniques or equivalent
- Experience with security in service-oriented architectures/microservices and web services
- Experience implementing security solutions at the business division level or equivalent
- Knowledge of networking protocols, to include HTTP(S), DNS, and TCP/IP
- Experience with web services and related technologies
- Experience in more than one major programming language (C++, Java, or related) and at least one scripting language (Perl, Python, or equivalent)
- Experience using English communication skills, both written and verbal, to foster seamless interaction with stakeholders at all levels
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, VA, Arlington - 178,400.00 - 226,700.00 USD annually