Data Center IT Technician, Data Centre Operations
About the role
Project Leo is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world. The Leo Security team owns the security of product and operations of Project Leo end-to-end. We provide the necessary infrastructure and mechanisms to ensure the security of our satellite constellation and to protect the integrity and confidentiality of our customer data. Our team drives the research & development, deployment and operation of several mission-critical security systems and mechanisms. You will work in a start-up like environment, backed by Amazon’s infrastructure to bootstrap security mechanisms, and help instill the security culture in the organization.
Export Control Requirement
Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Responsibilities
- Establish product-specific security bar, threat models, and security priorities to aide builders in ensuring consistent security execution across the business.
- Identify design & implementation defects.
- Support product development processes by providing consultation services on difficult security decisions.
- Collaborate with business leaders to define security priorities.
- Support product leaders by acting as a trusted advisor and providing direction that makes security easy.
- Help leaders measure their org's security execution.
- Guide teams towards outcomes that produce products that safely handle customer data.
- Collaborate with builder teams to assess technical debt and risk.
- Provide strategic direction that addresses vulnerabilities and fortifies our products.
- Lead the burn down of long-term risk.
- Guide teams towards solutions that are secure by default; if secure-by-default solutions don't exist, invent & propose them.
- Leverage support from automation teams that find discoverable vulnerabilities.
- Advocate for the creation & deployment of new testing tools, and detection mechanisms.
- Enable builder teams to become proactive & self-sufficient on security.
- Work with builder teams to understand their build processes and ensure they use appropriate security linting & static analysis tools.
- Help builders find security solutions that reduce security operations costs over time.
- Instill a security culture in builder teams.
- Mentor builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours.
- Assist Red Teams in identifying security testing priorities, scope penetration tests, and help deep-dive on these engagements.
- Investigate emerging security issues, root cause them, and devise mechanisms to prevent them.
- Propose a security vision for the business that delivers security that protects our customers.
- Hack bleeding edge technology.
A day in the life
In this highly dynamic role, you'll be accountable for deciding where your time investments provide the most value. You will have a blend of proactive and reactive work. Teams will reach out for ideas on how to handle a wide variety of security problems. You can anticipate implementation questions like "What's the right way to handle authentication tokens in service to service communications?" "We need to define security requirements for a confidential new product launch." "We've experienced an incident and need to perform 5 why's analysis to identify and correct the problem that produced the incident." When you're not working on responding to the questions of your builder teams, you will be evaluating overall org performance to identify architectural defects and proposing new security initiatives to correct problems in the org. You will help Amazon maintain a high bar for customer security.
Basic Qualifications
- 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
- Experience as a mentor, tech lead or leading an engineering team
- Bachelor's degree in CS, CE, or related field, or equivalent work experience
- 8+ years delivering security assessments or reviews
- 5+ years experience assessing the security of distributed software systems in Python, Java, Rust, GoLang or C/C++
- 3+ years experience in delivering security for cloud-native environments and embedded environments
Preferred Qualifications
- Experience dealing effectively with customers during problem resolution and operating efficiently under pressure