Senior Security Engineer, AWS Marketplace , AWS Marketplace
Amazon Web Services (AWS) · Austin, TX · Yesterday
EngineeringFull-time
About the role
This role is part of the AWS Specialist and Partner Organization (ASP). The Senior Security Engineer will own the security strategy for the AWS Marketplace 3P catalog, including ingestion, scanning, vulnerability management, and ongoing posture monitoring of seller-provided artifacts.
Responsibilities
- Own the security strategy for the AWS Marketplace 3P catalog, including ingestion, scanning, vulnerability management, and ongoing posture monitoring of seller-provided artifacts (AMIs, containers, SaaS, data products, ML models).
- Identify systemic risks across the catalog and lead remediation campaigns that span multiple teams and orgs.
- Investigate and respond to security findings, vulnerabilities, and incidents involving Marketplace services and 3P content.
- Partner with AppSec to drive threat modeling, secure design reviews, and code reviews for Marketplace services.
- Define and raise security standards for sellers and Marketplace internal teams.
- Influence policy, tooling, and automation so the security bar rises without slowing the business down.
- Mentor engineers across the org on secure development practices, cloud security, and threat modeling.
- Represent Marketplace security in cross-AWS forums, working with AWS Security, service teams, and partner orgs.
Requirements
- 4+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience.
- 5+ years of work in identifying security issues and risks, and developing mitigation plans.
- 4+ years of (non-internship) scripting, programming, and security code review in common programming languages.
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go.
- Experience applying threat modeling or other risk identification techniques or equivalent.
- Experience with security in service-oriented architectures/microservices and web services.
- Experience as a mentor, tech lead or leading an engineering team.
- Experience (non-internship) in industry-based security vulnerabilities identification, attack patterns, and remediation techniques.
- Experience (non-internship) in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools.
- Experience (non-internship) in scripting, programming, and security code reviewing in a common programming language.
Qualifications
- Basic Qualifications: 4+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience; 5+ years of work in identifying security issues and risks, and developing mitigation plans; 4+ years of (non-internship) scripting, programming, and security code review in common programming languages; Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go; Experience applying threat modeling or other risk identification techniques or equivalent; Experience with security in service-oriented architectures/microservices and web services; Experience as a mentor, tech lead or leading an engineering team; Experience (non-internship) in industry-based security vulnerabilities identification, attack patterns, and remediation techniques; Experience (non-internship) in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools; Experience (non-internship) in scripting, programming, and security code reviewing in a common programming language.
- Preferred Qualifications: Experience with security in service-oriented architectures/microservices and web services; Experience as a mentor, tech lead or leading an engineering team; Experience (non-internship) in industry-based security vulnerabilities identification, attack patterns, and remediation techniques; Experience (non-internship) in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools; Experience (non-internship) in scripting, programming, and security code reviewing in a common programming language.
Skills
Not specified
Benefits
Not specified
Pay
Base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location.
Schedule
Not specified