Security Engineer, Corporate Services Security

Amazon

Seattle (WA)

On-site

USD 150,000 - 200,000

Full time

13 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Amazon is seeking a Security Engineer to partner with application teams across CPSS, focusing on secure software development and GenAI security. You will conduct design and threat reviews, help embed security into the SDLC, and build automation to streamline security findings across projects.

The role emphasizes influencing architecture, mentoring engineers, and communicating risk to leadership while delivering secure software at scale from Seattle.

Qualifications

  • 3+ years in threat modeling, secure coding, or related security fields.
  • Experience with cloud-hosted services and security reviews.
  • Ability to identify risks and develop mitigations.

Responsibilities

  • Perform Design and Security Reviews to assess risk and prioritize remediation.
  • Promote security across the company and build cross-team relationships.
  • Develop and improve security tooling and automation.
  • Create, update, and maintain threat models for various projects.
  • Conduct manual and automated secure code reviews in Java, Python, and JavaScript.
  • Provide security training and guidance to development teams.
  • Influence senior leaders with data-driven security decisions.

Skills

Threat modeling
Secure coding
Identity management
Software development
Cryptography
System administration
Network security
Python
Java
C++

Job description

Description

The Corporate Services Security (CPSS) Finance and Communication Security (FCS) Team is responsible for securing the applications, infrastructure and data developed across Finance & Global Business Services (FGBS) and Communications and Corporate Responsibility (CCR). We partner with builder teams to minimize security risks across their applications while being a business enabler. Our team is responsible for the following:

  • Security consultations and guidance - Get security subject matter expert advice on security best practices and implementation strategies.
  • Application security reviews and threat modeling -Comprehensive security assessments for new features and applications
  • Security architecture decisions - Design reviews and architectural guidance to build security in from the start of the software development lifecycle
  • Issue remediation - Support for addressing security findings, vulnerabilities, and compliance gaps
  • Security backlog management - Prioritization and tracking of security improvements and technical backlog
  • Compliance and security standards questions - Guidance on meeting organizational security policies and industry standards
  • Security tooling and automation - Help with integrating security tools into your development workflows
Description

The Corporate Services Security (CPSS) Finance and Communication Security (FCS) Team is responsible for securing the applications, infrastructure and data developed across Finance & Global Business Services (FGBS) and Communications and Corporate Responsibility (CCR). We partner with builder teams to minimize security risks across their applications while being a business enabler. Our team is responsible for the following:

  • Security consultations and guidance - Get security subject matter expert advice on security best practices and implementation strategies.
  • Application security reviews and threat modeling -Comprehensive security assessments for new features and applications
  • Security architecture decisions - Design reviews and architectural guidance to build security in from the start of the software development lifecycle
  • Issue remediation - Support for addressing security findings, vulnerabilities, and compliance gaps
  • Security backlog management - Prioritization and tracking of security improvements and technical backlog
  • Compliance and security standards questions - Guidance on meeting organizational security policies and industry standards
  • Security tooling and automation - Help with integrating security tools into your development workflows
Key job responsibilities

A successful candidate will possess demonstrated combination of application security, GenAI Security, technical, and communication skills, as well as the ability to handle a mix of disparate tasks and include projects in addition to managing security review activities. This role will provide career growth opportunities as you gain new security skills in the course of your duties.

Perform Design and Security Reviews to determine the level of risk they present to our customers, and then accordingly prioritize their remediation in conjunction with the service team.

Participate in efforts to promote security throughout the Company and build good working relationships within the team and with others across Amazon.

Demonstrate high capacity and tolerance for context switching and interruptions while remaining productive and effective.

Escalate issues and provide recommendations to senior leadership when issues are not progressing at the correct pace based on impact to ensure we are putting customers first.

Explore building and improving our tooling to make your own life easier and share that benefit with all our engineers globally.

Contribute to recruiting activities, mentoring and administrative work.

Create, update, and maintain threat models for a wide variety of software projects.

Perform Manual and Automated Secure Code Review, primarily in Java, Python and Javascript.

Develop security automation tools.

Adversarial security analysis using tools to augment manual effort.

Provide Security training and outreach for internal development teams.

Provide Security architecture and design guidance to application development teams.

Independently solve systemic, complex security problems that require novel methods or approaches.

Influence your team’s and partners’ process, priorities, and choices by using data to improve security outcomes.

Provide technical and strategic guidance to senior leaders and stakeholders through effective oral and written communications.

A day in the life

As a Security Engineer, you will collaborate with application development teams to ensure we keep our customers safe while developing novel services using GenAI. In a given day, you might be inspecting an application’s code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service. The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security specialist with one or more areas of deep expertise within application security or software development. They will clearly articulate risks to technical and non-technical audiences alike. Successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions.

The Corporate Services Security (CPSS) Product Security Team

The Corporate Services Security (CPSS) Product Security Team is responsible for securing the applications, infrastructure and data developed across People eXperience and Technology (PXT), Finance & Global Business Services (FGBS), Legal and Communications and Corporate Responsibility (CCR). We partner with builder teams to minimize security risks across their applications while being a business enabler. Our team develops security tooling and automation to provide high quality security findings earlier in development lifecycles.

About The Team

Diverse Experiences

Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture

In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications
  • 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • 3+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience
  • Experience implementing security solutions at the cross-team level
  • Knowledge of usage or integration experience with common cloud-hosted services
  • Experience in identifying security issues and risks, and developing mitigation plans
Preferred Qualifications
  • Experience with AWS products and services
  • Experience programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language
  • Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Corporate Services Security
Security Engineer, Corporate Services Security

Amazon • Boston (MA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Security Engineer, Corporate Services Security
Security Engineer, Corporate Services Security

Socket.dev • Boston (MA)

On-site
USD 159,000 - 202,000
Sr Security Engineer, Corporate Services Security
Sr Security Engineer, Corporate Services Security

Amazon • Arlington (VA)

On-site
USD 178,000 - 227,000
Sign-on payments
Restricted stock units (RSUs)
Health insurance
+4
Senior Security Engineer, Corporate Services Security
Senior Security Engineer, Corporate Services Security

Amazon • Boston (MA)

On-site
USD 178,400 - 226,700
Health insurance
401(k) matching
Paid time off
+1
Security Engineer, CS Security
Security Engineer, CS Security

Amazon • Seattle (WA)

On-site
USD 159,000 - 202,000
Application Security Engineer, AWS Proactive Security
Application Security Engineer, AWS Proactive Security

Amazon • Herndon (VA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
RSUs
+3
Application Security Engineer, AWS Proactive Security
Application Security Engineer, AWS Proactive Security

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Security Engineer, AWS Security
Security Engineer, AWS Security

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
Restricted stock units (RSUs)
401(k) matching
+1
Security Engineer, CS Security
Security Engineer, CS Security

Amazon • Austin (TX)

On-site
USD 159,000 - 202,000
Security Engineer, AppSec, Stores Security
Security Engineer, AppSec, Stores Security

Amazon • Seattle (WA)

On-site
USD 136,000 - 184,000