As a member of the Application Security Testing Automation team, you will help provide automated security testing solutions for all of Amazon.
Our team’s goal is to empower both development and security teams with accurate security detections at the highest standards of quality in order to identify and eliminate risk across Amazon’s application portfolio.
As a Senior Security Engineer on our team, you will solve interesting security challenges that arise when Amazon invents new technologies.
You will lead the team to prototype and build tools that enable developers to understand their vulnerabilities and how to effectively mitigate them.
You will identify and apply opportunities to build new security services, improve existing ones and update our standards and documentation to have the widest possible impact for our customers.
You will work proactively and autonomously with partner orgs to develop advanced security detection capabilities to solve complex Application Security challenges at scale.
You will lead by example, proactively improve the consistency of team processes, and help guide the technical direction of the team.
Be active mentor for all team members and act as the voice for the team. You will work independently across multiple teams and organizations, build consensus on the direction of security automation and inform decisions made by senior security leaders.
This role will routinely challenge your technical background and critical thinking. You will be expected to collaborate with our team’s stakeholders in a fast-paced environment across many technology stacks and services to deliver scalable solutions.
Acceptable office locations :
New York, NY
Key job responsibilities
- Define and drive strategy, act as a technical lead for the team
- Develop, curate, and improve application security detections (static and dynamic) to identify vulnerabilities in Web applications and Application Programming Interface (API) at scale
- Drive security tool evaluation, development and deployment
- Perform dynamic and static application security assessments to ensure the highest quality standard for our detection development and release process
- Risk assessment and Threat Modeling
- Develop, enhance, and interpret security standards and guidance
- Demonstrate and promote security best practices, drive improvements of Amazon’s overall security architecture
A day in the life
- Educate developers on security issue remediation and best practices
- Researching prevalent vulnerabilities with other security teams
- Collaborate with multiple stakeholders to collectively raise the security posture of Amazon
- Review code, running endpoints, APIs, and other platforms to identify security issues
- Presenting findings and discussing security risk with technical and non-technical stakeholders
- Reporting on automation breadth and depth metrics while improving internal processes
- Use technical depth to provide wide coverage for the team and also be able to deep dive into specific work areas to help unblock other team members
About the team
Our team's vision is to eliminate security threats from entering the production landscape of Amazon developed applications.
We strive to reduce manual security testing efforts through automation across all web and API application portfolio and inject continuous non-disruptive security testing methodologies across Amazon's SDLC phases to provide service owners actionable and useful security feedback.
About Amazon Security
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply.
If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services.
We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness.
Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work / Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture.
When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
BASIC QUALIFICATIONS
- Bachelor's degree
- Broad and deep knowledge across application security domains
- 8+ years of Application Security or Development experience
- Experience with the application of threat modeling or other risk identification techniques.
- Scripting skills (e.g., python, java)
PREFERRED QUALIFICATIONS
- MS in Computer Science or Cybersecurity
- Development experience in Python and / or Java.
- Secure software development lifecycle experience.
- Knowledge of distributed systems and security protocols.