Security Engineer II, AppRank

Socket.dev

Austin (TX)

On-site

USD 159,000 - 202,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Amazon Stores’ AppSec team seeks a Security Engineer to advance AppRank and scale security across diverse, high-scale systems. You will translate complex architecture into actionable insights, design automation, and drive secure design across development lifecycles.

You will partner with software engineers, product managers, and security leadership, perform code reviews, build internal tooling, and help identify and remediate vulnerabilities at scale while mentoring teams on prevention and best

Qualifications

  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non‑internship) experience
  • Knowledge of industry-based security vulnerabilities and remediation techniques
  • Experience in scripting, programming, and security code reviewing in a common programming language (non‑internship)
  • Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non‑internship experience)
  • 4+ years of any combination of the following: application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing experience
  • Knowledge of one or more domains: access‑control system and methodology, network security, application- and system-development security, security architecture and models, cryptography, and operations security
  • Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or equivalent work experience

Responsibilities

  • Engineer AI-driven solutions to assess and classify security findings across business units
  • Identify root causes of recurring vulnerabilities and develop systemic remediation strategies
  • Design and build internal tools to analyze patterns in security findings and prevent recurrence
  • Collaborate with application teams to implement preventative security controls earlier in the development lifecycle (Shift-Left)
  • Develop automated workflows to integrate security insights into developer pipelines
  • Perform targeted code reviews and static/dynamic analysis to validate findings and guide mitigations
  • Contribute to the creation of security dashboards and metrics for visibility into finding trends and remediation velocity
  • Partner with security leadership and engineering stakeholders to define and prioritize high-impact prevention efforts
  • Investigate and eradicate classes of vulnerabilities through scalable solutions
  • Guide teams through remediations by providing technical mentorship and secure design best practices
  • Maintain deep awareness of emerging threats, and proactively adapt tooling and processes to address them

Skills

Python
Java
C++
Go
Swift
Ruby
Command line
Security vulnerabilities
Code review
AppSec
Cloud security
Threat intelligence
Penetration testing
Identity and access controls
Network security
Access control
Security architecture

Education

Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or equivalent work experience

Tools

Job description

In Amazon Stores, we develop and operate some of the most diverse and high-scale technologies in the world — from Amazon.com’s global retail platform to advanced machine learning systems and next-generation retail experiences. With the scale and innovation we drive comes the responsibility to build secure systems from the ground up.

We are seeking a Security Engineer to join the AppSec organization and support Application Ranking AppRank (application criticality measurement) — a critical initiative to identify Amazon's most critical applications and criteria. In this role, you will leverage your application architecture excellence to engineer scalable, innovative solutions to assess application criticality criteria for the identification of systemic patterns across business units. Your work will directly impact the security posture of Amazon's most strategic lines of business.

You will collaborate closely with software engineering teams, product managers, and security leadership to ensure the most critical applications are identified early in the software development lifecycle at scale.

The ideal candidate blends strong technical execution with security intuition, and thrives in environments where they can influence, automate, and scale security impact. You should be comfortable translating complex application architecture into actionable insights and driving adoption of security best practices across a large and distributed engineering organization.

At Amazon, we invest in our people and empower our teams to focus on high-leverage work over reactive tasks. Join us to work on some of the most innovative and impactful security challenges in the industry—and help keep our customers safe by preventing security issues before they happen.

Key job responsibilities
  • Engineer AI-driven solutions to assess and classify security findings across business units
  • Identify root causes of recurring vulnerabilities and develop systemic remediation strategies
  • Design and build internal tools to analyze patterns in security findings and prevent recurrence
  • Collaborate with application teams to implement preventative security controls earlier in the development lifecycle (Shift-Left)
  • Develop automated workflows to integrate security insights into developer pipelines
  • Perform targeted code reviews and static/dynamic analysis to validate findings and guide mitigations
  • Contribute to the creation of security dashboards and metrics for visibility into finding trends and remediation velocity
  • Partner with security leadership and engineering stakeholders to define and prioritize high-impact prevention efforts
  • Investigate and eradicate classes of vulnerabilities through scalable solutions
  • Guide teams through remediations by providing technical mentorship and secure design best practices
  • Maintain deep awareness of emerging threats, and proactively adapt tooling and processes to address them
A day in the life

You split your time between building, investigating, and advising. Some mornings you're deep in the risk-prioritization engine; refining how it classifies and scores risk so application reviews are focused on what actually matters. Other days you may be fielding questions, helping teams understand their risk posture and working through disagreements with technical depth.

You collaborate as much as you code; pairing with application teams to help understand and resolve risk for their applications at scale.

About the team
Diverse Experiences

Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture

In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications
  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non‑internship) experience
  • Knowledge of industry-based security vulnerabilities and remediation techniques
  • Experience in scripting, programming, and security code reviewing in a common programming language (non‑internship)
  • Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non‑internship experience)
  • 4+ years of any combination of the following: application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing experience
  • Knowledge of one or more of the following domains: access‑control system and methodology, network security, application- and system-development security, security architecture and models, cryptography, and operations security
  • Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or equivalent work experience
Preferred Qualifications
  • Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
  • Experience with AWS products and services
  • Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, TX, Austin - 159,300.00 - 202,400.00 USD annually

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II, AppRank
Security Engineer II, AppRank

JobCubby • Austin (TX)

On-site
USD 159,000 - 202,000
Security Engineer II, AppRank
Security Engineer II, AppRank

Amazon • Austin (TX)

On-site
USD 159,000 - 202,000
Application Security Engineer, AppSec ASSET
Application Security Engineer, AppSec ASSET

Socket.dev • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
RSUs
Security Engineer II, AppSec Stores, Stores Security
Security Engineer II, AppSec Stores, Stores Security

Socket.dev • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+2
Security Engineer, AppSec, Stores Security
Security Engineer, AppSec, Stores Security

Amazon • Seattle (WA)

On-site
USD 136,000 - 184,000
Security Engineer, AppSec, Stores Security
Security Engineer, AppSec, Stores Security

Socket.dev • Seattle (WA)

On-site
USD 136,000 - 184,000
Health insurance
RSUs (restricted stock units)
401(k) matching
+1
Security Engineer, AWS AppSec
Security Engineer, AWS AppSec

Amazon • Seattle (WA)

On-site
USD 136,000 - 184,000
Health insurance
401(k) matching
Paid time off
Security Engineer II, Stores Application Security
Security Engineer II, Stores Application Security

Socket.dev • New York (NY)

On-site
USD 159,000 - 213,000
Security Engineer II, Stores Application Security
Security Engineer II, Stores Application Security

Amazon • New York (NY)

On-site
USD 159,000 - 213,000
Software Engineer, AppSTAR COMPASS
Software Engineer, AppSTAR COMPASS

Socket.dev • Austin (TX)

On-site
USD 144,000 - 194,000