Proactive AppSec Engineer: Threat Modeling & Reviews

Amazon

Seattle (WA)

On-site

USD 136,000 - 184,000

Full time

11 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health insurance
RSUs (restricted stock units)
Sign-on bonus

Job summary

Amazon is seeking an Application Security Engineer, Proactive Security, to conduct security assessments and reviews of applications and services to identify vulnerabilities and ensure adherence to security standards. You will evaluate designs, model threats, and validate security before launch.

The role partners with senior engineers to deliver secure, scalable solutions across AWS, retail, and devices, with a focus on secure coding practices and risk management.

Qualifications

  • Bachelor's degree in Engineering, Computer Science, or a related field.
  • Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and exploit development.
  • Experience with coding/scripting in one or more languages (Python, C, C++, Java, Ruby, or PowerShell).

Responsibilities

  • Security Reviews: Conduct security design reviews for new and existing services, evaluating architecture documents, threat models, and system designs for potential security risks
  • Threat Modeling: Perform threat modeling exercises to identify attack vectors, security weaknesses, and areas of concern in application architectures
  • Penetration Testing: Execute or coordinate penetration testing activities to validate security controls and identify exploitable vulnerabilities
  • Finding Management: Document, track, and communicate security findings to service teams, providing clear remediation guidance and verifying fixes
  • Security Guidance: Provide security consultation to development teams on secure coding practices, authentication/authorization mechanisms, cryptographic implementations, and data protection strategies
  • Escalation Support: Identify and elevate high-severity security issues through appropriate channels, ensuring timely remediation aligned with launch timelines
  • Documentation: Maintain clear and thorough documentation of review outcomes, security decisions, and risk assessments
  • Tool Utilization: Leverage automated security scanning tools and internal security platforms to support review activities and improve efficiency

Skills

Web security fundamentals
Scripting languages
Security assessments & threat modeling

Education

Bachelor's degree in Engineering, Computer Science, or related field

Job description

Amazon is seeking an Application Security Engineer, Proactive Security, to conduct security assessments and reviews of applications and services to identify vulnerabilities and ensure adherence to security standards. You will evaluate designs, model threats, and validate security before launch.

The role partners with senior engineers to deliver secure, scalable solutions across AWS, retail, and devices, with a focus on secure coding practices and risk management.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Proactive AppSec Engineer – Cloud (AWS)
Proactive AppSec Engineer – Cloud (AWS)

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
AppSec Security Engineer: Threat Modeling & Automation
AppSec Security Engineer: Threat Modeling & Automation

Amazon • Herndon (VA)

On-site
USD 136,000 - 184,000
Health insurance
401(k) matching
Paid time off
+3
Senior AppSec Engineer: Threat Modeling & Secure Code
Senior AppSec Engineer: Threat Modeling & Secure Code

Amazon • United States

On-site
USD 178,000 - 227,000
Health insurance
AppSec Engineer: Cloud Security & Automation
AppSec Engineer: Cloud Security & Automation

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Security Engineering Manager - App Security (Flexible Hours)
Security Engineering Manager - App Security (Flexible Hours)

Amazon • Austin (TX)

On-site
USD 175,000 - 237,000
Security Engineer II, AppsSec Pen Test & Threat Modeling
Security Engineer II, AppsSec Pen Test & Threat Modeling

Amazon • New York (NY)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
+1
AWS Proactive Security Engineer: PenTest & Automation
AWS Proactive Security Engineer: PenTest & Automation

Amazon • Northern (KY)

Hybrid
USD 136,000 - 184,000
Senior Security Engineer — Threat Modeling & Secure Systems
Senior Security Engineer — Threat Modeling & Secure Systems

Amazon • Seattle (WA)

On-site
USD 178,000 - 227,000
Security Engineer II: Threat Modeling & Secure Coding
Security Engineer II: Threat Modeling & Secure Coding

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
RSUs
Health insurance
401(k) matching
+1
Security Engineer II - Threat Modeling & Secure Code Review
Security Engineer II - Threat Modeling & Secure Code Review

Socket.dev • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+2