The AmSec Endpoint Security Capabilities and Prevention Engineering team build and operate first and third party services for the monitoring and response to malicious activity on the Amazon internal devices. We collect data from all parts of Amazon's environment worldwide.
We seek a Sr Security Engineer who is excited about leading a talented team to solve challenging problems by developing our own solutions, while operating a mission critical service that protects Amazon and our customer data. Our challenges are broad and deep -- we build flexible, secure, scalable, high-performance and robust tools and services. These services enable our security engineers and analysts to detect and respond to malicious activity on our infrastructure. In Amazon Security we operate multiple large scale data query platforms to allow security engineers to detect anomalies and facilitate threat hunting. You will lead a group of engineers to operate these services to the highest operational level while building new tools and services to improve the customer experience and make it easier/faster/cheaper for the customer to get what they need.
In AmSec, we obsess over our customers, and their trust is our first priority. Trust is earned by building a highly respected security team to tackle new challenges at a large scale. In this role, you will lead a key software development team to deliver high quality, scalable products that are deployed to our internal services around the world. You will collaborate with product owners and customers to deliver the best features, using resources and technologies efficiently. You will work with stakeholders to define solutions that scale and satisfy a wide variety of security needs. You will assign responsibilities, identify appropriate resources, and build schedules to ensure timely completion of project milestones. You will also assess risks, anticipate bottlenecks, and balance business needs against technical constraints to maximize business benefit. You bring a technical background, are detail driven and have excellent problem solving abilities. The successful candidate is passionate about delivering extensible, on-time solutions and has experience developing high-performance teams through goal-setting, attention to performance metrics, continuous process improvement and mentorship.
Key job responsibilities
- Creating, updating, and maintaining threat models for a wide variety of web applications hosted on cloud
- Manual and Automated Secure Code Review, primarily in Java, Python and Javascript
- Development of security automation tools
- Adversarial security analysis using the latest tools to augment manual effort
- Provide Security training and outreach for internal development teams
- Provide Security architecture and design guidance to application development teams
- Independently solve systemic, complex security problems that require novel methods or approaches
- Influence your team’s and partners’ process, priorities, strategy and choices by using data to improve security outcomes
- Provide technical and strategic guidance to senior leaders and stakeholders through effective oral and written communications
A day in the life
As a Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing novel services. In a given day, you might be inspecting an application’s code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service.
The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security specialist with one or more areas of deep expertise within application security. They will clearly articulate risks to technical and non-technical audiences alike. Successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions. They will shape the strategy of the Product Security Team and influence systemic security improvements across our service organizations. They will guide and mentor other engineers on the team.
About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
- 5+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience
- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
- 5+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
- Experience as a mentor, tech lead or leading an engineering team
- Experience applying threat modeling or other risk identification techniques or equivalent
- Experience with security in service-oriented architectures/microservices and web services
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit
https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, San Luis Obispo - 178,400.00 - 226,700.00 USD annually
USA, WA, Seattle - 178,400.00 - 226,700.00 USD annually