Sr Security Engineer, Corporate Services Security
About the role
The Corporate Services Security (CPSS) Security for Employee and Legal Systems (SEALS) team protects Amazon's enterprise HR and Legal applications, ensuring they meet the high security standards. You'll elevate our security strategy through broad leadership, cross-functional collaboration, and delivery of high-quality results that push us to continuously improve for our customers.
Responsibilities
Creating, updating, and maintaining threat models for a wide variety of web applications hosted on cloud
Manual and Automated Secure Code Review, primarily in Java, Python and Javascript
Development of security automation tools
Adversarial security analysis using the latest tools to augment manual effort
Provide Security training and outreach for internal development teams
Provide Security architecture and design guidance to application development teams
Independently solve systemic, complex security problems that require novel methods or approaches
Influence your team’s and partners’ process, priorities, strategy and choices by using data to improve security outcomes
Provide technical and strategic guidance to senior leaders and stakeholders through effective oral and written communications
Requirements
5+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools
5+ years of work in identifying security issues and risks, and developing mitigation plans
5+ years of (non-internship) scripting, programming, and security code review in common programming languages
Experience applying threat modeling or other risk identification techniques or equivalent
Experience with security in service-oriented architectures/microservices and web services
Qualifications
Experience with at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
Experience as a mentor, tech lead or leading an engineering team
Skills
Technically, this person will be a security specialist with one or more areas of deep expertise within application security. They will clearly articulate risks to technical and non-technical audiences alike. Successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions. They will shape the strategy of the Product Security Team and influence systemic security improvements across our service organizations. They will guide and mentor other engineers on the team.
Benefits
A comprehensive benefits package including health insurance, retirement savings, paid time off, parental leave, and more. For more details, visit here.
Pay
The base salary range for this position is $178,400.00 - $226,700.00 USD annually.
Schedule
Full-time.