Security Engineer II, Amazon Vulnerability Management - Container Domain

Amazon

Arlington (VA)

On-site

USD 159,000 - 202,000

Full time

36 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Amazon Security seeks a Security Engineer II for the AVM Container Domain Team in Arlington, VA. You will assess and remediate container vulnerabilities across ECS, EKS, and SageMaker, working with builder teams to patch fleets and strengthen container security posture.

The role emphasizes automation, scalable risk assessment, and on-call responsibilities to maintain secure container operations for AWS services. This is a full-time on-site position in Arlington, VA.

Qualifications

  • 2+ years scripting, programming, and security code review in a common language.
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating tasks with CLI tools.
  • Bachelor's degree in STEM or 2+ years IT Security experience.
  • Knowledge of HTTP, DNS, TCP/IP networking.
  • Knowledge of security vulnerabilities and remediation techniques.

Responsibilities

  • Analyze vulnerability disclosures and exploit code for container images and orchestrations (ECS/EKS/SageMaker).
  • Assess technical details and impact of container vulnerabilities across AWS services and infrastructure.
  • Triage container findings; assess severity, exploitability, and risk context.
  • Collaborate with builder teams to fix container security issues.
  • Develop scalable risk-assessment mechanisms for container workloads.

Skills

Scripting
Security code review
Log analysis
Networking
Vulnerability remediation

Education

STEM degree or IT security experience

Tools

Python
Java
C++

Job description

Embark on a mission to secure how Amazon builds and runs containers as a Security Engineer II with the AWS Vulnerability Management (AVM) Container Domain Team! Seeking an experienced and innovative Security Engineer to join our Container Domain Team in Arlington, VA. Our team is responsible for assessing, triaging, and driving the remediation of container vulnerabilities across AWS's container ecosystem spanning Amazon ECS, EKS, and SageMaker. We partner with builder teams across AWS to get container fleets patched.

Key job responsibilities
  • Analyze public and private vulnerability disclosures and exploit code, with an emphasis on container images, base layers, and orchestration platforms (ECS, EKS, SageMaker).
  • Deeply understand and assess the technical details and potential impact of container vulnerabilities across AWS's infrastructure, services, and applications.
  • Investigate and triage container findings, identifying severity, exploitability, and the scope of potential impact, including contextual risk assessment to distinguish real risk from noise.
  • Support response and remediation efforts, partnering with builder teams to fix container security issues.
  • Engineer high quality, scalable risk-assessment mechanisms for container workloads.
  • Design and implement automation, tooling, and workflows to enhance patch deployment, remediation tracking, and our overall container operations capabilities.
  • Periodic on-call responsibilities to ensure the continuous monitoring and remediation of container vulnerabilities.
About The Team

Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security? At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & career growth We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/life balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications
  • 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
  • Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • Knowledge of industry-based security vulnerabilities and remediation techniques
Preferred Qualifications
  • 2+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience
  • Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks
  • Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C++
  • Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
  • Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, VA, Arlington - 159,300.00 - 202,400.00 USD annually

Company - Amazon.com Services LLC

Job ID: A10568811

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer II, Amazon Vulnerability Management - Container Domain
Security Engineer II, Amazon Vulnerability Management - Container Domain

Amazon Inc. • Arlington (VA)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k)
Software Development Engineer, AWS Vulnerability Management (AVM)
Software Development Engineer, AWS Vulnerability Management (AVM)

Amazon Web Services (AWS) • Arlington (VA)

On-site
USD 144,000 - 194,000
Security Engineer II, AWS Vulnerability Managment
Security Engineer II, AWS Vulnerability Managment

Amazon Web Services (AWS) • Arlington (VA)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
Security Engineer II, AWS Vulnerability Managment
Security Engineer II, AWS Vulnerability Managment

Amazon Inc. • Arlington (VA)

On-site
USD 159,000 - 202,000
Security Engineer II, AVMS Orchestration
Security Engineer II, AVMS Orchestration

Amazon Inc. • Austin (TX)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
+2
Security Engineer II, Customer Logistics Security
Security Engineer II, Customer Logistics Security

Amazon • Jersey City (NJ)

On-site
USD 159,000 - 213,000
Health insurance
401(k) matching
Sign-on payments
+1
Software Development Engineer II, AWS Vulnerability Management
Software Development Engineer II, AWS Vulnerability Management

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 144,000 - 194,000
Security Engineer, AWS Security
Security Engineer, AWS Security

Amazon Inc. • Arlington (VA)

On-site
USD 136,000 - 184,000
Health insurance
RSUs (Restricted Stock Units)
401(k) matching
+2
Security Engineer II
Security Engineer II

Amazon • Herndon (VA)

On-site
USD 159,000 - 202,000
Software Development Engineer, AWS Vulnerability Management
Software Development Engineer, AWS Vulnerability Management

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 144,000 - 194,000
RSUs
Sign-on bonus
Comprehensive benefits