Jobs · Engineering · New York

Security Engineer, AWS Security Hub, Security Services (S2)

Amazon Web Services (AWS) · New York, NY · 1 wk ago
EngineeringFull-time

AWS Security Hub is the security and compliance center for AWS customers, providing automated checks against cloud security best practices, industry standards, and regulatory frameworks.

About the role

The AWS Security Hub team is seeking a security engineer focused on compliance and security best practices for AWS, Azure, and GCP services. In this role, you will lead efforts to define security best practices across multiple cloud providers, implement security controls for compliance assessments, develop remediations for non-compliant events, and map controls to industry standards and regulatory frameworks such as CIS Benchmarks.

You will collaborate with a broad network of stakeholders, including AWS service owners, security experts, and customers, to raise the bar for security and compliance across AWS. This role requires experience defining technical requirements for compliance and security best practices, translating them into automated checks and remediation procedures, and implementing those checks in Python or a supported language.

Responsibilities

  • Define security best practices for AWS, Azure, and GCP services.
  • Implement security controls to assess compliance with industry standards and regulatory frameworks.
  • Develop remediations for non-compliant events across cloud providers.
  • Create multi-cloud controls that evaluate Azure and GCP resource configurations through AWS Config.
  • Translate security controls into automated checks using Python or a supported language.
  • Collaborate with AWS service owners, security experts, and customers to improve security and compliance.
  • Serve as a leading voice in raising the bar for security and compliance across AWS.

Requirements

  • 3+ years of programming experience in Python, Ruby, Go, Swift, Java, .Net, C++, or a similar object-oriented language.
  • 2+ years of scripting, programming, or security code review experience in a common programming language (non-internship).
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating tasks using command-line tools (non-internship).
  • Bachelor’s degree in Computer Science, a STEM field, or equivalent experience in IT Security.
  • Knowledge of networking protocols such as HTTP, DNS, and TCP/IP.
  • Knowledge of industry-based security vulnerabilities and remediation techniques.

Preferred Qualifications

  • 2+ years of experience in threat modeling, secure coding, identity management, authentication, software development, cryptography, system administration, or network security.
  • Experience with AWS products and services.
  • Experience performing security activities across phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing.
  • Proficiency in scripting or programming languages such as Python, Java, or C++.

Benefits

  • Comprehensive health insurance (medical, dental, vision, prescription, Basic Life & AD&D, and optional supplemental life plans).
  • Employee Assistance Program (EAP) and mental health support.
  • Medical Advice Line and Flexible Spending Accounts.
  • Adoption and surrogacy reimbursement coverage.
  • 401(k) matching.
  • Paid time off and parental leave.
  • Sign-on payments and restricted stock units (RSUs).

Pay

Base salary range: $159,300 - $212,800 USD annually (location: USA, NY, New York). Final compensation will be determined based on experience, qualifications, and location.

Schedule

Flexible schedule to support work-life balance, with a focus on productivity rather than hours worked.

Similar jobs