Security Engineer II, CLS Application Security

Cybersecurity Jobs

Irvine (CA)

On-site

USD 159,000 - 202,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Sign-on payments
Restricted stock units (RSUs)
Health insurance (medical, dental, etc
401(k) matching
Paid time off
Parental leave

Job summary

Amazon CLS Application Security is hiring a Security Engineer II to embed security early and scale prevention through automation and AI-enabled tooling. You will own end-to-end security initiatives, lead design reviews, and partner with development teams to deliver fast, actionable guidance.

The role requires 3+ years in application security, strong communication of risk, and experience in AWS CI/CD environments. Onsite in Irvine, CA with comprehensive benefits and RSUs.

Qualifications

  • 2+ years of scripting, programming, and security code review in a non-internship</br>
  • Knowledge of system security vulnerabilities and remediation techniques
  • Experience owning and leading significant projects from concept through deployment
  • Experience writing to communicate security risk to technical and non-technical stakeholders
  • 3+ years of application security engineering experience including threat modeling and code-level analysis
  • Experience carrying a builder-facing security consult load

Responsibilities

  • Own a strategic security initiative end to end: scoping, design, implementation, testing, deployment, and maintenance
  • Build security automation and AI-powered tooling to prevent vulnerabilities in production
  • Lead security design reviews and steer teams toward secure-by-default implementations
  • Collaborate with development teams to resolve findings and provide actionable guidance
  • Centralize controls to enable multiple teams to adopt shared solutions
  • Investigate high-impact risks and implement reproducible root-cause fixes
  • Communicate risk and recommendations clearly to engineers and stakeholders
  • Coach teammates to raise the team’s operating standard

Skills

Scripting & programming
Security code review
Security risk communication
Project ownership
Security design reviews
Builder-facing security consult

Tools

AWS
CI/CD pipelines

Job description

Amazon CLS Application Security is hiring a Security Engineer II to embed security early and scale prevention through automation and AI-enabled tooling.

Responsibilities
  • Own a strategic security initiative end to end: scoping, design, implementation, testing, deployment, and maintenance, while guiding other engineers during execution
  • Build security automation and AI-powered tooling to move beyond one-off reviews, including prevention rules, secure defaults, and “paved paths” that stop vulnerabilities before production
  • Review application architecture and designs by leading security design reviews and steering teams toward secure-by-default implementations
  • Partner directly with development teams to resolve findings and deliver fast, actionable guidance aligned with the security bar
  • Identify opportunities to centralize controls so multiple teams can adopt a shared solution instead of building duplicates
  • Investigate ambiguous, high-impact risks, detect patterns across large application footprints, and fix root causes with reproducible mechanisms that are simple, maintainable, and built to last
  • Communicate risk and recommendations clearly to engineers, partner security teams, and business stakeholders, and advocate for the right outcome even when it is unpopular
  • Coach and mentor teammates to raise the team’s operating standard and the value delivered
Requirements
  • 2+ years of experience in scripting, programming, and security code review in a common programming language (non-internship)
  • Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and development of exploits (or equivalent)
  • Experience owning and leading significant projects from concept through deployment
  • Experience writing to communicate security risk to technical and non-technical stakeholders
  • 3+ years of application security engineering experience, including security design reviews, threat modeling, and code-level vulnerability analysis
  • Experience carrying a builder-facing security consult load, including intake, triage, guidance, and resolution tracking
Technologies
  • AWS: IAM, VPC, KMS, CloudTrail
  • CI/CD pipelines
Benefits
  • Sign-on payments
  • Restricted stock units (RSUs)
  • Health insurance (medical, dental, vision, prescription), Basic Life & AD&D insurance, and option for Supplemental life plans; EAP and Mental Health Support; Medical Advice Line; Flexible Spending Accounts; Adoption and Surrogacy Reimbursement coverage
  • 401(k) matching
  • Paid time off
  • Parental leave
Preferred Qualifications
  • Experience in a logistics/operations environment
  • Experience with root cause analysis and error correction, including changing procedures and systems for long-term fixes to avoid repeat issues
  • Experience mentoring, leading, or managing more junior engineers
  • Experience with cloud security in AWS (IAM, VPC, KMS, CloudTrail, or equivalent services)
  • Experience building automated security controls or shifting security left in CI/CD pipelines
Location and Work Model
  • Irvine, CA (onsite)
Additional Job Information (Los Angeles County Applicants)
  • Job duties include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies
  • Criminal history may have a direct, adverse, and negative relationship with some material job duties
  • Under the Los Angeles County Fair Chance Ordinance, qualified applicants with arrest and conviction records will be considered
Work/Life Balance
  • Work-life harmony is valued
  • Flexible work hours and arrangements are part of the culture
Training & Career Growth
  • Endless knowledge-sharing, training, and other career-advancing resources
Inclusive Team Culture
  • Ongoing DEI events and learning experiences to embrace uniqueness and continue learning
  • Seeking out and celebrating diverse ideas, perspectives, and voices to address tough security challenges

Compensation: USD 159,300 - 202,400 per year

Minimum experience: 3 years

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer II, CLS Application Security
Security Engineer II, CLS Application Security

Amazon Inc. • Irvine (CA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1
Security Engineer II, Customer Logistics Security
Security Engineer II, Customer Logistics Security

Amazon • Austin (TX)

On-site
USD 159,000 - 202,000
Security Engineer II, Stores AppSec
Security Engineer II, Stores AppSec

Amazon • United States

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
Security Engineer II: AI-Powered App Security (Onsite Irvine)
Security Engineer II: AI-Powered App Security (Onsite Irvine)

Cybersecurity Jobs • Irvine (CA)

On-site
USD 159,000 - 202,000
Sign-on payments
Restricted stock units (RSUs)
Health insurance (medical, dental, etc
+3
Sr. Security Engineer, Ring Application Security
Sr. Security Engineer, Ring Application Security

Ring • Austin (TX)

On-site
USD 140,000 - 210,000
Application Security Engineer, US Amazon Dedicated Cloud Security
Application Security Engineer, US Amazon Dedicated Cloud Security

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 178,000 - 227,000
SecEng III, AppSec - Amazon Stores Security
SecEng III, AppSec - Amazon Stores Security

Amazon • United States

Remote
USD 178,000 - 227,000
Health insurance
RSUs
Paid time off
+1
Application Security Engineer, US Amazon Dedicated Cloud Security
Application Security Engineer, US Amazon Dedicated Cloud Security

Amazon Web Services (AWS) • Jessup (MD)

On-site
USD 178,000 - 227,000
Health insurance
401(k) matching
Paid time off
+1
Application Security Engineer
Application Security Engineer

Cybersecurity Jobs • Arlington (VA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+3
Sr. Security Engineer, Proactive Security
Sr. Security Engineer, Proactive Security

Cybersecurity Jobs • Arlington (VA)

On-site
USD 178,000 - 227,000
Sign-on payments/RSUs
Health insurance (medical, dental, etc
401(k) matching
+2