Security Engineering Lead, AWS Security

Amazon

City of Melbourne

On-site

AUD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Amazon Web Services (AWS) Security Engineering Lead in Melbourne leads offensive security testing, threat modeling, and automated threat emulation efforts to secure large-scale cloud services. You will guide security practices across development teams, deliver robust testing plans, and mentor engineers while aligning with Australia-specific controls.

Applicants should have 7+ years in cybersecurity, strong knowledge of security frameworks, and experience with security tooling like Splunk and

Qualifications

  • Minimum 7+ years delivering cyber security solutions to large enterprises or government customers.
  • Experience guiding security engineering programs and defining strategies that balance prevention and detection.
  • Masters or PhD in Cybersecurity or a related field is preferred.

Responsibilities

  • Lead offensive security testing, threat emulation, and vulnerability research across AWS projects.
  • Develop automated threat emulation tools and secure development lifecycle guidance for teams.
  • Set testing standards, produce high-quality plans and reports, and mentor engineers.
  • Collaborate with security leaders across jurisdictions to implement Australian region controls.

Skills

Cybersecurity Expertise
Threat Modeling
Offensive Security
Security Testing

Education

Masters' degree in Cybersecurity
PhD in Cybersecurity

Tools

Splunk
CrowdStrike

Job description

Description

Applicants must be Australian citizens and hold or be eligible to obtain an Australian Government Security Clearance with the ability to successfully complete an Organisational Suitability Assessment. For more information regarding security clearances please visit https://www.agsva.gov.au/.

Amazon Web Services (AWS) is the leading cloud service provider, providing virtualised infrastructure, storage, networking, messaging, and many other services to customers all over the world. AWS runs a globally distributed environment, operating at massive levels of scale. Businesses, from start-ups to enterprises to large government customers, run their operations and applications on AWS' highly secure infrastructure.

AWS Security is looking for a Security Engineering Lead to join the team. You will be on a team responsible for conducting both pre and post launch testing, offensive campaigns, emergent threat modeling/testing, creating/maintaining automated threat emulation solutions, and helping security and service teams add offensive insight to their development, deployment, monitoring, and response processes. This team partners with the larger Security organisation and Service teams to continuously validate security throughout the service/system lifecycle.

You will be an expert across multiple domains such as cyber security; threat, vulnerability and risk assessments (TVRA), security tools (e.g. Splunk, Crowdstrike, etc.), application of security frameworks (e.g. PSPF, ISM, NIST, etc.) and/or implementation and monitoring of cyber security controls (i.e. detection, protection, alerting, etc.) and will be sought out for advice on a range of technical and business related issues. Your role will help ensure that our systems and processes are secured against the latest threats and you will lead security testing of large Amazon projects while setting standards and defining best practices for the AWS Security team. You will proactively share knowledge across the Amazon community and will be a critical member of the organisation in one or more of the core areas of security.

You will be expected to partner and align with other technical leaders and Principal Security Engineers from other geographic jurisdictions to leverage, extend and adapt critical security solution for the Australian region. You will collaborate closely with peers and other experts to deliver a sovereign security solution for Australia to address our country specific security controls.

Key job responsibilities
  • Offering recommendations and fine-tuning findings to enhance threat mitigations, ensuring robust security measures are in place.
  • Setting a high standard and generating high-quality testing plans and reports, striving for excellence in security testing procedures.
  • Conducting offensive security testing and engaging in ongoing vulnerability research to proactively identify potential risks.
  • Systematically identifying vulnerabilities and meticulously tracking them to facilitate timely remediation efforts.
  • Staying ahead of emerging threats by continuously testing systems and applications for vulnerabilities that may arise.
  • Developing and maintaining automated solutions for emulating threats, enhancing efficiency and accuracy in threat detection.
  • Providing security training and conducting outreach sessions with internal development teams to raise awareness and foster a security-conscious culture.
  • Developing comprehensive security guidance documentation, including policies, procedures, and best practices, to serve as a reference for the organization.
  • Designing and building security tools tailored to the organization's needs, enhancing the overall security posture.
  • Delivering meaningful security metrics to stakeholders and continuously improving the metrics for better insight into the security landscape.
A day in the life

Engineers in this role must show exemplary judgment in making technical trade-offs between short versus long term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. Conflicts should be addressed by listening, finding the best way forward and persuading one’s colleagues. Successful engineers in this role will regularly analyze their own performance with a critical eye. A broad understanding of the AWS business and its interconnections is required. This position will also provide training, advice, and mentorship to other engineers throughout AWS.

About the team
Why Amazon Security

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

The team is comprised of security professionals with a cross section of national security and private sector experience, providing a range of perspectives required for creative problem solving. We value diversity of thought, creativity, and a strong Bias for Action and Earn Trust. We believe that there are no "perfect" security solutions and we develop and iterate using a continuous improvement process.

Diverse Experiences

AWS values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.

Why AWS?

Amazon Web Services (AWS) is the world's most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that's why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.

Inclusive Team Culture

AWS values curiosity and connection. Our employee-led and company-sponsored affinity groups promote inclusion and empower our people to take pride in what makes us unique. Our inclusion events foster stronger, more collaborative teams. Our continual innovation is fueled by the bold ideas, fresh perspectives, and passionate voices our teams bring to everything we do.

Mentorship & Career Growth

We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.

Basic Qualifications
  • Minimum 7+ years of experience in delivering cyber security solution to large enterprises or to Government customers.
  • Efficient time management skills are required along with the ability to deliver results in the face of uncertainty.
  • Proven ability to provide technical and strategic oversight for a high-performing team of security professionals.
  • Demonstrated experience creating effective security strategies that balance prevention and detection, drive risk reduction and mitigation.
Preferred Qualifications
  • Masters' degree or PhD in Cybersecurity or related domain.
  • Worked on large-scale cloud programs to deliver security outcomes.
Acknowledgement of country

In the spirit of reconciliation Amazon acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.

IDE statement

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Manager, AWS Security
Cyber Security Manager, AWS Security

Amazon • Melbourne

On-site
AUD 90,000 - 150,000
Flexible Working Hours
Training and Career Growth Opportunities
Work-Life Balance Initiatives
+1
Security Specialist, Region Services
Security Specialist, Region Services

Amazon Web Services (AWS) • Council of the City of Sydney

On-site
AUD 180,000 - 240,000
Learning & development - AWS training
Health & life cover
Military differential pay—Australia
+3
Sr Security Engineer, Region Services
Sr Security Engineer, Region Services

Amazon Web Services (AWS) • Council of the City of Sydney

On-site
AUD 140,000 - 210,000
Learning & development support
Health, income protection & life cover
Military differential pay (Australia)
+3
Governance Risk and Compliance Manager, AWS Security
Governance Risk and Compliance Manager, AWS Security

Amazon • Melbourne

On-site
AUD 90,000 - 150,000
Flexible working hours
Career development opportunities
Diversity and inclusion initiatives
+1
Governance, Risk, and Compliance Specialist, AWS Security
Governance, Risk, and Compliance Specialist, AWS Security

Amazon • City of Melbourne

On-site
AUD 150,000 - 190,000
Learning & development
Health protection and life cover
Military differential pay
+3
Associate Security Specialist, Region Services
Associate Security Specialist, Region Services

Amazon Web Services (AWS) • Council of the City of Sydney

On-site
AUD 90,000 - 140,000
Learning & development - AWS training
Health, income protection and life cap
Military differential pay in Australia
+3
Senior Security Technical Program Manager, AWS Security
Senior Security Technical Program Manager, AWS Security

Amazon Web Services (AWS) • Sydney

On-site
AUD 180,000 - 240,000
Security Consultant, Global ProServe Security
Security Consultant, Global ProServe Security

Amazon • City of Melbourne

On-site
AUD 140,000 - 180,000
Governance, Risk, and Compliance Specialist, AWS Security
Governance, Risk, and Compliance Specialist, AWS Security

Amazon Web Services (AWS) • Council of the City of Sydney

On-site
AUD 140,000 - 180,000
Learning & development
Health insurance
Employee assistance
Security Engineer, AWS Security
Security Engineer, AWS Security

Amazon Web Services (AWS) • City of Melbourne

On-site
AUD 100,000 - 140,000