Sr. Security Engineer, Leo Security
About the role
Leo is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world. The Leo Security team owns the security of product and operations of Leo end-to-end. We provide the necessary infrastructure and mechanisms to ensure the security of our satellite constellation and to protect the integrity and confidentiality of our customer data. Our team drives the research & development, deployment and operation of several mission-critical security systems and mechanisms. You will work in a start-up like environment, backed by Amazon's infrastructure to bootstrap security mechanisms, and help instill the security culture in the organization.
Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Responsibilities
- Help define, develop, and implement Leo's vulnerability management program
- Advocate for the creation & deployment of new testing tools, and detection mechanisms
- Leverage support from automation teams that find discoverable vulnerabilities
- Identify design & implementation defects and build compensating security controls
- Support product development processes by providing consultation services on difficult security decisions
- Collaborate with business leaders to define security priorities
- Support product leaders by acting as a trusted advisor
- Support leaders by providing them with direction that makes security easy
- Help leaders measure their org's security execution
- Guide teams towards outcomes that produce products that safely handle customer data
- Collaborate with builder teams to assess technical debt and risk
- Provide strategic direction that addresses vulnerabilities and fortifies our products
- Be a resource that leads the burn down of long-term risk
- Instill a security culture in builder teams
- Mentor builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours
- Hack some really cool bleeding edge tech
A day in the life
In this highly dynamic role, you'll be accountable for deciding where your time investments provide the most value. You will have a blend of building preventive and detective controls. Teams will reach out for ideas on how to handle a wide variety of security problems. You can anticipate implementation questions like "What's the paved path for vulnerability management?" "We've experienced an incident and need to perform 5 why's analysis to identify and correct the problem that produced the incident." When you're not working on responding to the questions of builder teams, you will be evaluating overall org performance to identify architectural defects and proposing new security scanning capability to correct problems in the org. You will help Amazon maintain a high bar for customer security.
Qualifications
- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
- 5+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience
- Experience (non-internship) in industry-based security vulnerabilities identification, attack patterns, and remediation techniques
- 5+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
- Experience as a mentor, tech lead or leading an engineering team
Preferred qualifications
- Experience applying threat modeling or other risk identification techniques or equivalent
- Experience with security in service-oriented architectures/microservices and web services
- Master's degree in Cybersecurity, Information Security, or a related field
- Experience using data and metrics to back up assumptions, evaluate outcomes, and make data-driven decisions
- Experience triaging security risks or vulnerabilities and ensuring that they are properly understood by the business and fixed or mitigated
- Experience in Space Vehicle/Satellite Operations, Space Communications or related industry
- Experience with embedded systems
- 8+ years Experience in performing and/or participating in technical security assessments, e.g. code level, application level, or network/infrastructure assessments
- Familiarity with programming and scripting or experience developing security tools & processes that work at scale
Pay
USA, WA, Redmond - 178,400.00 - 226,700.00 USD annually
Benefits
- Health insurance (medical, dental, vision, prescription)
- Basic Life & AD&D insurance and option for Supplemental life plans
- EAP, Mental Health Support, Medical Advice Line
- Flexible Spending Accounts
- Adoption and Surrogacy Reimbursement coverage
- 401(k) matching
- Paid time off
- Parental leave