Security Engineer, AWS Proactive Security

Amazon

Northern (KY)

Hybrid

USD 136,000 - 184,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Amazon is seeking a Security Engineer for AWS Proactive Security to join a team that evaluates services and features to uphold a high security bar across the AWS landscape. You will automate verification, perform manual audits of in-house code, and write PoCs to demonstrate the impact of potential issues.

You’ll collaborate with developers to drive fixes, provide long-term risk mitigation guidance, and reproduce attacker techniques to validate remediation across customer environments.

Qualifications

  • 2+ years of web protocols, common security attacks, and remediation experience
  • Bachelor's degree in Engineering, Computer Science, or a related field
  • Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and exploit development
  • Experience scripting with Python, Perl, Bash or PowerShell
  • Experience with AWS services or other cloud offerings
  • Experience with coding/scripting in one or more languages (e.g., Python, C, C++, Java, Ruby, or PowerShell)
  • Experience using standard security assessment and penetration testing tools such as BurpSuite, Metasploit, and IDA Pro

Responsibilities

  • Automate the verification and remediation of security issues
  • Manually audit the source code of web services and software authored in house by Amazon
  • Write proof of concept code to demonstrate the severity of a potential security issue
  • Provide clear communication on issues to developers that suggest and help to test the fix
  • Partner with AWS developers to drive improvement in application security as a result of security review engagements
  • Provide actionable long term risk mitigation guidance

Skills

Web protocols
Security vulnerabilities
Scripting: Python/PowerShell
AWS experience
Programming languages
Penetration testing tools

Education

Bachelor's degree in Engineering/Computer Science/related field

Tools

BurpSuite
Metasploit
IDA Pro

Job description

Security Engineer, AWS Proactive Security

ID lavoro: 10556291 | Amazon.com Services LLC

Are you interested in security and supporting penetration testing at a global scale? Do you strive to achieve a deep understanding of systems and apply a hacker mindset to determine how they can be broken? As a pre-launch Security Engineer, you are part of a testing team that evaluates AWS services and features to help builders maintain a high security bar. When builders have implemented fixes to security issues, you review their proposed corrections to determine efficacy before final release. You work closely with testers to understand their approaches and methodologies so you can quickly reproduce them in a variety of customer environments. You recognize the value of automation and are comfortable with scripting languages to develop tools that improve the speed and quality of your team's verification work.

Our team is responsible for the manual assessment of all products, services and software released by AWS. To accomplish this, we support and write a variety of automated tooling (e.g. fuzzers, scanners, analyzers, etc.) to verify security fixes related to penetration testing. We specialize in digging deep to find security issues that static analysis tools can’t, and write the tooling to help with these goals whenever possible. The AWS surface area is large and diverse, and we use results found in manual analysis to help improve our enterprise-wide automation to proactively spot and fix potential security issues to protect customers.

Key job responsibilities
  • Automate the verification and remediation of security issues
  • Manually audit the source code of web services and software authored in house by Amazon
  • Write proof of concept code to demonstrate the severity of a potential security issue
  • Provide clear communication on issues to developers that suggest and help to test the fix
  • Partner with AWS developers to drive improvement in application security as a result of security review engagements
  • Provide actionable long term risk mitigation guidance
A day in the life

As a Security Engineer supporting verifications for pre-launch testing, you have the opportunity to review and dive deep into builder-proposed fixes. You’ll access development environments for upcoming AWS services and features to dive deep into their code to learn how security issues were discovered and how the builders intend to address them. You perform static code analysis and dynamic reproduction of issues to make the final decision on whether the builder’s proposed fix is sufficient to allow their code release.

About the team
  • Diverse Experiences. Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
  • Why Amazon Security? At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
  • Inclusive Team Culture. In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
  • Training & Career Growth. We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career‑advancing resources here to help you develop into a better‑rounded professional.
  • Work/Life Balance. We value work‑life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
  • 2+ years of web protocols, common security attacks, and remediation (non‑internship) experience
  • Bachelor's degree in Engineering, Computer Science, or a related field
  • Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
  • Experience scripting with Python, Perl, Bash or PowerShell
  • Experience with AWS services or other cloud offerings
  • Experience with coding/scripting in one or more languages (e.g., Python, C, C++, Java, Ruby, or PowerShell)
  • Experience using standard security assessment and penetration testing tools such as BurpSuite, Metasploit, and IDA Pro

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits .

Qualifiche Preferenziali
  • Experience with AWS services or other cloud offerings
  • Experience with coding/scripting in one or more languages (e.g., Python, C, C++, Java, Ruby, or PowerShell)
  • Experience using standard security assessment and penetration testing tools such as BurpSuite, Metasploit, and IDA Pro

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits .

USA, WA, Virtual Location - Washington - 136,000.00 - 184,000.00 USD annually

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer, Proactive Security
Application Security Engineer, Proactive Security

Amazon • Seattle (WA)

On-site
USD 136,000 - 184,000
Health insurance
RSUs (restricted stock units)
Sign-on bonus
Security Engineer, Correlation and Response, AWS Security Hub
Security Engineer, Correlation and Response, AWS Security Hub

Amazon • Boston (MA), Northern (KY)

Hybrid
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
+1
Security Engineer, AWS Security
Security Engineer, AWS Security

Amazon Web Services (AWS) • Arlington (VA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Software Development Engineer, Amazon Integrated Security
Software Development Engineer, Amazon Integrated Security

Amazon • San Luis Obispo (CA)

On-site
USD 144,000 - 194,000
Application Security Engineer, AWS Security
Application Security Engineer, AWS Security

Socket.dev • Austin (TX)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Security Engineering Manager, Security Analytics and AI Research
Security Engineering Manager, Security Analytics and AI Research

Amazon • Seattle (WA)

On-site
USD 175,000 - 237,000
Health insurance
RSUs
401(k) matching
+1
Application Security Engineer, AWS Security
Application Security Engineer, AWS Security

Amazon Web Services (AWS) • Austin (TX)

On-site
USD 159,000 - 202,000
Sign-on payments
Restricted stock units (RSUs)
Health insurance
+3
Security Engineer, Corporate Services Security
Security Engineer, Corporate Services Security

Socket.dev • Boston (MA)

On-site
USD 159,000 - 202,000
Security Engineer II, Stores AppSec
Security Engineer II, Stores AppSec

Amazon • New York (NY)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
+1
Security Engineer II, Stores Security
Security Engineer II, Stores Security

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000