Jobs · Quality Assurance · Massachusetts

Senior Security Engineer, Corporate Services Security

Amazon · Boston, MA · Today
Quality AssuranceFull-time

About the role

The Senior Security Engineer is a senior individual contributor responsible for independently driving security initiatives across multiple services and teams. This role requires deep technical expertise in application security, threat modeling, and secure system design, combined with the ability to influence engineering teams and deliver high-impact security outcomes with minimal guidance.

Responsibilities

  • Lead end-to-end security reviews for complex, high-priority services including design reviews, threat modeling, and penetration testing scoping and readout

  • Serve as a subject matter expert for assigned affinity teams, providing architectural guidance and security consultation to service teams throughout the development lifecycle.

  • Provide guidance and advise to senior leaders, including providing ideas for team goals, contributing to Operational Planning and newsletters.

  • Independently perform and guide threat modeling exercises for complex distributed systems, identifying risks and recommending mitigations.

  • Conduct targeted manual code reviews of security-critical components, identifying vulnerabilities and insecure patterns that automated tools miss.

  • Scope, coordinate, and oversee penetration testing engagements; analyze results and drive remediation with service teams.

  • Identify, document, and track security findings to resolution; escalate critical issues to leadership when appropriate.

  • Mentor junior engineers, contribute to team processes and tooling improvements, and raise the security bar across the organization.

  • Demonstrate ability to communicate clearly across organization levels including technical and non-technical audience.

  • Design and build security automation, tooling, and processes that improve operational efficiency and scale the team's impact.

  • Leverage generative AI and machine learning to build intelligent security automations that streamline review workflows, enhance vulnerability detection, and reduce manual toil.

  • Write code for security automation.

  • Partner with service teams to improve security posture proactively, including developing self-service guidance, documentation, and readiness frameworks.

  • Define and track security metrics that measure risk reduction, operational efficiency, and builder experience improvements.

Qualifications

  • 4+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience

  • 5+ years of work in identifying security issues and risks, and developing mitigation plans experience

  • 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience

  • Experience working in identifying security issues and risks, and developing mitigation plans

  • Experience as a mentor, tech lead or leading an engineering team

Preferred Qualifications

  • Experience with any combination of the following: application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing

  • Experience with security in service-oriented architectures/microservices and web services

  • Knowledge of cloud computing services and deployment architecture

  • Experience with AWS services or other cloud offerings

Similar jobs