Security Engineer II, Specialized Businesses Security, External Vulnerability Operations

AMAZON UK

Greater London

On-site

GBP 90,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Amazon UK is seeking an experienced security engineer to triage externally disclosed risks and drive remediation across devices and services. You will partner with product and security teams to strengthen the secure software development lifecycle and protect customer trust.

You will analyze vulnerability data, automate workflows, and contribute to the growth of the Bug Bounty and Threat Intelligence programs, working with researchers and internal teams to deliver impactful security improvements.

Qualifications

  • Experience with application security frameworks, security code reviews and incident response.
  • Knowledge of vulnerabilities, remediation techniques and exploit development practices.
  • Experience in scripting or programming in Python, Java or C++ and familiarity with AWS.
  • Experience with device technologies, firmware flashing, logs and debugging is a plus.

Responsibilities

  • Triage externally disclosed hardware and service security issues, suggest fixes and collaborate with builder teams for remediation.
  • Identify risk trends in Amazon devices and services and collaborate with teams for remediation.
  • Automate manual security processes to improve efficiency.
  • Lead improvements to Amazon security programs and processes.
  • Create high-quality documentation for technical and non-technical audiences.
  • Manage relationships with customers and security researchers.

Skills

Application security
Security code reviews
Threat modeling
Penetration testing
Cloud security
Python
C++
Java
DevSecOps

Education

Bachelor's degree in a STEM field

Tools

AWS
Linux/Bash
Firmware analysis
Security tooling

Job description

Description

This individual will be working with external security researchers and Amazon teams to secure Amazon’s public-facing devices and services. In this role, you will be responsible for ensuring vulnerabilities are remediated with urgency by partnering with service teams, ensuring what is learned through disclosure and mitigation improves the security of Amazon’s device and software development life cycle. This role will provide you with challenging leadership and technical opportunities and the chance to grow Amazon’s Bug Bounty and Threat Intelligence programs into the best on planet Earth.

You will be in direct contact with teams in a variety of business verticals, giving you firsthand knowledge about how Amazon is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Amazon to find new ways to drive improvements to Customer relationships, services, processes, and technologies throughout the company, with the goal of ensuring the continued safety and security of our customers.

You will use your technical skills to triage disclosed risks and collaborate with customers and security researchers to maintain and raise Amazon’s high security bar. You’ll be backed up by a team of highly skilled security engineers all working with a singular focus of maintaining customer trust and security. You must demonstrate resilience and navigate ambiguous situations with composure and tact. Above all else, a strong sense of Customer Obsession is necessary to focus on the goal of keeping Amazon and its customers secure with the highest priority.

Key job responsibilities
  • Triage externally disclosed hardware and service security issues, suggest fixes, and collaborate with builder teams for remediation
  • Identify risk trends in Amazon devices and services, and collaborate with builder teams for remediation
  • Automate manual processes to streamline security work
  • Lead improvements to Amazon programs and processes
  • Write and deliver high-quality documents for technical and non-technical audiences
  • Manage relationships with Customers and security researchers
Basic Qualifications
  • Experience in any combination of the following: application security frameworks, security code reviews, incident response, secure infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls, threat modeling, cryptography, threat intelligence, or secure software development
  • Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
  • Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C++
  • Experience with AWS products and services
  • Experience working with device technologies under development, familiarity with flashing firmware, basic device debugging and familiarity with reading/pulling device logs, or experience scripting in one or more language (e.g. Bash, Python, Perl, Ruby)
  • Deep understanding of hardware security, firmware analysis, operating system internals, and low-level programming
Preferred Qualifications
  • Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics)
  • 5+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • Experience supporting Red Team, Penetration Testing, or Bug Bounty programs

Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( https://www.amazon.jobs/en/privacy_page) to know more about how we collect, use and transfer the personal data of our candidates.

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II, Specialized Businesses Security, External Vulnerability Operations
Security Engineer II, Specialized Businesses Security, External Vulnerability Operations

Amazon • Greater London

On-site
GBP 110,000 - 170,000
Product Security Manager, AWS Security
Product Security Manager, AWS Security

AMAZON UK • Greater London

On-site
GBP 120,000 - 160,000
Application Security Engineer
Application Security Engineer

AMAZON UK • Greater London

On-site
GBP 80,000 - 120,000
Software Development Engineer, IAM Stores Security
Software Development Engineer, IAM Stores Security

Amazon • City Of London

On-site
GBP 70,000 - 110,000
Sr. Security Engineer, Amazon Stores Security AppSec
Sr. Security Engineer, Amazon Stores Security AppSec

Amazon • Greater London

On-site
GBP 90,000 - 120,000
Security Engineer, SDO AppSec
Security Engineer, SDO AppSec

AMAZON UK • Greater London

On-site
GBP 90,000 - 120,000
Senior Security Engineer, AWS Security
Senior Security Engineer, AWS Security

Amazon • City Of London

On-site
GBP 110,000 - 170,000
Product Security Manager, AWS Security
Product Security Manager, AWS Security

Amazon Web Services (AWS) • Greater London

On-site
GBP 120,000 - 180,000
Senior Security Engineer, AWS Security
Senior Security Engineer, AWS Security

Amazon • Greater London

On-site
GBP 90,000 - 130,000
Security Engineer II — Bug Bounty & Threat Intelligence
Security Engineer II — Bug Bounty & Threat Intelligence

Amazon • Greater London

On-site
GBP 110,000 - 170,000