Search jobs > Newark, NJ > Information security

Security Engineer, Business Information Risk

Amazon.com
NEWARK, NJ, US
Full-time

At Audible, we believe stories have the power to transform lives. It’s why we work with some of the world’s leading creators to produce and share audio storytelling with our millions of global listeners.

We are dreamers and inventors who come from a wide range of backgrounds and experiences to empower and inspire each other.

Imagine your future with us.

ABOUT THIS ROLE

As a Security Engineer II at Audible you will advocate for information security throughout all our software development and business processes.

You will work with other Security Engineers, Application Developers and System Engineers to protect our customers and Audible’s business.

ABOUT THE TEAM

Audible Information Security team is looking for an experienced Security Engineer to join our world class team. We are obsessed with protecting customer trust.

We are a hands-on team working to protect our computer networks, servers, applications and data assets. This role will be focused on managing risk across our business functions.

True to Audible’s People Principles, we are committed to the success of our people and supporting the communities in which we work.

Our leadership team is dedicated to mentoring and coaching to help each individual identify their career goals, flourish, and achieve their potential.

Our environment encourages everyone to participate. Our diverse team depends on differing backgrounds and perspectives to foster robust conversations that lead us to the right solutions for our customers.

As a Security Engineer, you will...

  • Perform third party security risk assessment and due diligence, including managing questionnaire response, evidence verification, and report preparation
  • Assess and secure third-party integrations, services, solutions and partnerships, ensuring controls are implemented to the highest security standards
  • Assess, identify and develop recommendations regarding data protection, insider threat, data sharing, identity and access management
  • Execute internal security and confidential information usage security assessments, audits, and investigations
  • Assess and prioritize security assessment findings and recommend appropriate mitigations.
  • Respond to security violations, vulnerabilities, and incident detections
  • Provide guidance on risk, compliance, and policy to technical and non-technical internal customers, including security training and outreach to internal teams and external supply chain partners
  • Apply your security and business knowledge to drive secure and pragmatic improvements to Audible people, process, and assets, while guiding technical trade-offs between short versus long term security and business goals
  • Contribute to / provide feedback on the development of security standards and control requirements
  • Strong organizational and communication skills, with a demonstrated ability to work in a multi-tasking dynamic environment while maintaining a high level of ownership and accountability

ABOUT AUDIBLE

Audible is the leading producer and provider of audio storytelling. We spark listeners’ imaginations, offering immersive, cinematic experiences full of inspiration and insight to enrich our customers daily lives.

We are a global company with an entrepreneurial spirit. We are dreamers and inventors who are passionate about the positive impact Audible can make for our customers and our neighbors.

This spirit courses throughout Audible, supporting a culture of creativity and inclusion built on our People Principles and our mission to build more equitable communities in the cities we call home.

BASIC QUALIFICATIONS

  • Bachelor's degree in computer science or equivalent
  • Experience with AWS products and services
  • Experience applying threat modeling or other risk identification techniques or equivalent
  • 5+ years of any combination of the following : threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • Experience with the information security principles and the Common Body of Knowledge (CBK) domains and core technologies (CIA, encryption, identity, authN / authZ, SSO, web protocols, and privacy)
  • Experience in advocating security best practices for third party integrations (e.g. with SAAS solutions, third-party libraries, etc.)

PREFERRED QUALIFICATIONS

  • Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units
  • MS in Cybersecurity, Computer Science, or other relevant degree
  • Current knowledge around web and mobile application vulnerabilities, attacks, and mitigation methods
  • Experience with developing and maintaining relevant security assessment risk metrics
  • Experience using GRC tools and technologies
  • Proficient in at least one programming language Java preferred
  • AWS certifications such as AWS Certified Security Specialty, AWS Certified Cloud Practitioner, or other security related certifications (e.

g., CISSP, SANS / GIAC or GSEC, CISA, OSCP / OSWA / OSWE)

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

For individuals with disabilities who would like to request an accommodation, please visit https : / / www.amazon.jobs / en / disability / us .

17 hours ago
Related jobs
Promoted
Amazon.com
Woodbridge Township, New Jersey

As a Security Engineer II at Audible you will advocate for information security throughout all our software development and business processes. You will work with other Security Engineers, Application Developers and System Engineers to protect our customers and Audible’s business. Audible Informatio...

Promoted
Deloitte
Jersey City, New Jersey

The Information System Security Engineer (ISSE) will be responsible for creating and maintaining RMF artifacts and shall implement security controls, patch vulnerabilities on network devices, and resolve system security engineering concerns to ensure cyber compliance and readiness for a Government F...

Promoted
Amazon.com
Newark, New Jersey

Play a leadership role in Audible InfoSec & Security Engineer org and work closely with the Audible business and product community, setting direction for security of key assets, data, and business processes; serving as a subject matter expert resource for security engineers, security champions, and...

Promoted
Gilder Search Group
Clifton, New Jersey

Contribute to all System Security Engineering activities pertaining to CDRLs, trade studies, security requirements analysis, secure architecture development, management & compliance with security controls, design review milestones (SRR, SDR, PDR, CDR), and security test/verification activities. ...

Promoted
Barclays
Hanover, New Jersey

Join Barclays as a Business Information Security Officer, where you’ll spearhead the transformation of our digital security landscape and drive innovation. Collaborate with other areas of work, for business aligned support areas to keep up to speed with business activity and the business strategies....

Promoted
NICE
Hoboken, New Jersey

The purpose of this role is to support security stakeholders within the business by addressing increasing security and compliance requirements from our customers. Reporting to the DevOps Manager and working closely with the Engineering Manager and Security Manager, your duties will range from answer...

Promoted
Open Systems Technologies
Jersey City, New Jersey

Knowledge and understanding of security engineering, system and network security, authentication and security protocols, incident management. Collaborate with business units and corporate partners to ensure solutions are built in consistent with the organization's policies, programs, architectural r...

L3Harris Technologies
Clifton, New Jersey

Strong understanding of engineering processes, concepts and information security systems engineering principles (NIST SP 800-160 Vol1). Information Security Systems Engineer. Applies current Systems Security Engineering methods, practices, and technologies to the architecture, design, development, e...

Open Systems Technologies
Jersey City, New Jersey

Knowledge and understanding of security engineering, system and network security, authentication and security protocols, incident management. Collaborate with business units and corporate partners to ensure solutions are built in consistent with the organization's policies, programs, architectural r...

L3Harris Technologies
Clifton, New Jersey

Strong understanding of engineering processes, concepts and information security systems engineering principles (NIST SP 800-160 Vol1). Job Title: Senior Information Security Systems Engineer. Applies current Systems Security Engineering methods, practices, and technologies to the architecture, desi...