Senior Security Engineer, AWS Marketplace , AWS Marketplace
About the role
This position is part of the AWS Specialist and Partner Organization (ASP). Specialists own the end-to-end go-to-market strategy for their respective technology domains, providing the business and technical expertise to help our customers succeed. Partner teams own the strategy, recruiting, development, and growth of our key technology and consulting partners. Together they provide our customers with the expertise and scale needed to build innovative solutions for their most complex challenges.
Responsibilities
- Own the security strategy for the AWS Marketplace 3P catalog, including ingestion, scanning, vulnerability management, and ongoing posture monitoring of seller-provided artifacts (AMIs, containers, SaaS, data products, ML models).
- Identify systemic risks across the catalog and lead remediation campaigns that span multiple teams and orgs.
- Investigate and respond to security findings, vulnerabilities, and incidents involving Marketplace services and 3P content.
- Partner with AppSec to drive threat modeling, secure design reviews, and code reviews for Marketplace services.
- Define and raise security standards for sellers and Marketplace internal teams. Influence policy, tooling, and automation so the security bar rises without slowing the business down.
- Mentor engineers across the org on secure development practices, cloud security, and threat modeling.
- Represent Marketplace security in cross-AWS forums, working with AWS Security, service teams, and partner orgs.
Qualifications
- 4+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience
- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
- 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
- Experience working in identifying security issues and risks, and developing mitigation plans
Preferred Qualifications
- Experience applying threat modeling or other risk identification techniques or equivalent
- Experience with security in service-oriented architectures/microservices and web services
- Experience as a mentor, tech lead or leading an engineering team
- Experience (non-internship) in industry-based security vulnerabilities identification, attack patterns, and remediation techniques
- Experience (non-internship) in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools
- Experience (non-internship) in scripting, programming, and security code reviewing in a common programming language
Benefits
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance, 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.