Security Engineer, AWS Security

JobCubby

Greater London

Hybrid

GBP 70,000 - 110,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Amazon is seeking an AppSec Security Engineer to evaluate service design and conduct deep-dive security assessments to ensure applications meet a high security bar before launch. You’ll work with senior engineers, drive remediation, and validate security requirements are met across architectures and services.

The role involves threat modelling, security reviews, and coordinating penetration testing, with guidance on secure coding, cryptography, and data protection.

Qualifications

  • Bachelor's degree or above in Computer Science, Computer Engineering, or related fields.
  • tExperience with web protocols, common security attacks, and remediation.
  • Experience with coding/scripting in one or more languages (e.g., Python, Java, C++, etc.)

Responsibilities

  • Security Reviews: Conduct design reviews for new and existing services, evaluating architecture documents and system designs for security risks.
  • Threat Modelling: Identify attack vectors and security weaknesses in application architectures through structured threat modelling exercises.
  • Penetration Testing: Coordinate penetration testing to validate security controls and identify exploitable vulnerabilities.
  • Finding Management: Document, track, and communicate security findings with remediation guidance, and verify fixes.
  • Security Guidance: Advise development teams on secure coding practices, authentication/authorization mechanisms, cryptographic implementations, and data protection strategies.
  • Escalation Support: Identify and escalate high-severity issues through appropriate channels, ensuring timely remediation aligned with launch timelines.
  • Documentation: Maintain clear documentation of review outcomes, security decisions, and risk assessments.
  • Tool Improvements: Leverage automated tools to support reviews and improve efficiency.

Skills

Web security
Threat modelling
Penetration testing
Remediation guidance
Programming (Python/Java)

Education

Bachelor's degree in a technical field

Tools

AWS
Security frameworks
Penetration testing tools

Job description

to apply - email only, no card. You can also save this posting or score it againstyour profile with AI.## About the roleThe Security Engineer evaluates service architecture and performs deep-dive security assessments to ensure applications meet high security standards. They also conduct threat modeling, coordinate penetration testing, and provide remediation guidance to development teams.## RequirementsCandidates must have a bachelor's degree in a technical field and experience with web protocols, security vulnerabilities, and remediation. Proficiency in at least one programming language and knowledge of application security frameworks are required.## Full descriptionThe AppSec Security Engineer evaluates service design and architecture and performs deep-dive security assessments to ensure applications and services meet a high security bar before launch. This role works alongside senior engineers to identify issues, drive remediation, and validate that security requirements are met.Key job responsibilities - Security Reviews: Conduct design reviews for new and existing services, evaluating architecture documents and system designs for security risks. - Threat Modelling: Identify attack vectors and security weaknesses in application architectures through structured threat modelling exercises. - Penetration Testing: Coordinate penetration testing to validate security controls and identify exploitable vulnerabilities. - Finding Management: Document, track, and communicate security findings to service teams with clear remediation guidance, and verify fixes are implemented. - Security Guidance: Advise development teams on secure coding practices, authentication/authorization mechanisms, cryptographic implementations, and data protection strategies. - Escalation Support: Identify and escalate high-severity issues through appropriate channels, ensuring timely remediation aligned with launch timelines. - Documentation: Maintain clear documentation of review outcomes, security decisions, and risk assessments. - Tool Improvements: Leverage automated tools to support reviews and improve efficiency.About the team Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.Basic Qualifications: - Experience with web protocols, common security attacks, and remediation (non-internship) - Bachelor's degree or above in Computer Science, Computer Engineering, or related fields - Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent - Experience in any combination of the following: application security frameworks, security code reviews, incident response, secure infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls, threat modeling, cryptography, threat intelligence, or secure software development - Experience with coding/scripting in one or more languages (e.g., Python, C, C++, Java, Ruby, or PowerShell)Preferred Qualifications: - Experience with AWS services or other cloud offerings - Knowledge of one or more of the following domains: web application development, penetration testing, mobile security, cryptography, public key infrastructure, forensic security, IP security, SSL/TLS, computer viruses and malware, network security, trusted security, trusted execution, threat intelligence, IoT security implications, or authentication - Experience using scripting languages, such as Python, Perl, Linux bash - Experience triaging and developing security alerts and response automation, conducting front-line analysis, and providing escalation supportAmazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice (https://www.amazon.jobs/en/privacy\\_page) to know more about how we collect, use and transfer the personal data of our candidates.Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

AMAZON UK • Greater London

On-site
GBP 80,000 - 120,000
Security Engineer, SDO AppSec
Security Engineer, SDO AppSec

AMAZON UK • Greater London

On-site
GBP 90,000 - 120,000
Senior Security Engineer, AWS Security
Senior Security Engineer, AWS Security

Amazon • City Of London

On-site
GBP 110,000 - 170,000
Security Engineer II, Specialized Businesses Security, External Vulnerability Operations
Security Engineer II, Specialized Businesses Security, External Vulnerability Operations

Amazon • Greater London

On-site
GBP 110,000 - 170,000
Cyber Security Analyst, AWS Security
Cyber Security Analyst, AWS Security

Amazon • City Of London

On-site
GBP 80,000 - 120,000
Principal Security Engineer, SDO AppSec EMEA
Principal Security Engineer, SDO AppSec EMEA

AMAZON UK • Greater London

On-site
GBP 85,000 - 120,000
Security Engineer I, AWS Security Incident Response
Security Engineer I, AWS Security Incident Response

AMAZON UK • Manchester

On-site
GBP 65,000 - 100,000
Product Security Manager, AWS Security
Product Security Manager, AWS Security

AMAZON UK • Greater London

On-site
GBP 120,000 - 160,000
Senior Security Engineer, AWS Security
Senior Security Engineer, AWS Security

Amazon Web Services (AWS) • Greater London

On-site
GBP 110,000 - 150,000
Security Engineer I, AWS Security Incident Response
Security Engineer I, AWS Security Incident Response

Amazon • Manchester

On-site
GBP 60,000 - 85,000