Enable job alerts via email!

Security Engineer, Specialized Businesses Security, Vulnerability Management

Amazon

Arlington (VA)

On-site

USD 90,000 - 150,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Join a forward-thinking company as a Security Engineer in their Specialized Businesses Security team. This role focuses on enhancing vulnerability detection capabilities throughout the Software Development Lifecycle (SDLC) by utilizing a diverse set of security scanning tools. You'll partner with development teams to prioritize and remediate vulnerabilities, ensuring the delivery of secure products. If you're passionate about security and eager to make a significant impact, this opportunity is perfect for you. Embrace the challenge of protecting innovative devices and services while working in a collaborative environment that values diversity and inclusion.

Qualifications

  • 3+ years programming experience in Python, Ruby, Go, or similar languages.
  • Hands-on experience in Vulnerability Management and Application Security.

Responsibilities

  • Develop and tune automated detection tools for security vulnerability analysis.
  • Collaborate with partners to develop scalable security solutions.

Skills

Python
Ruby
Go
Swift
Java
.Net
C++
Threat Modeling
Secure Coding
Identity Management
Cryptography
Network Security

Education

Bachelor's degree in Computer Science

Tools

Static Application Security Testing (SAST)
Dynamic Application Security Testing (DAST)
Open Source Composition Analysis (SCA)
AWS

Job description

Security Engineer, Specialized Businesses Security, Vulnerability Management

Job ID: 2907760 | Amazon.com Services LLC

Amazon’s Specialized Businesses Security team is seeking an innovative Security Engineer to join our Vulnerability Management Detection Team. In this position, you will focus on detection, assessment, triage and supporting remediation of vulnerabilities. You will work with a diverse set of security scanning tools to support our application security vulnerability detection capabilities. Your goal will be to deeply understand Amazon’s innovative Devices and Services to enhance our vulnerability detection capabilities throughout the Software Development Lifecycle (SDLC). You will partner with development teams to drive prioritization and remediation of vulnerabilities to help deliver secure products for our customers.


Key job responsibilities
  1. Developing and tuning custom, open source and third-party high quality automated detection tools (e.g. static analyzers, fuzzers, scanners, etc.) to perform variety of security vulnerability analysis (SAST, DAST, SCA, etc.)
  2. Reviewing output of automated detection tools for accuracy
  3. Analyzing public and private vulnerability disclosures to analyze impact on Amazon Devices and Services
  4. Providing actionable long-term risk prioritization and mitigation guidance to drive security improvements at scale
  5. Proposing mechanisms for integrating security detection tools into the development lifecycle
  6. Collaborate with partners across Amazon to develop scalable solutions to security problems

BASIC QUALIFICATIONS
  1. 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  2. Experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security
  3. Bachelor's degree in computer science or equivalent
  4. 3+ years hands-on experience in Vulnerability Management, Product Security and/or Application Security

PREFERRED QUALIFICATIONS
  1. 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  2. Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
  3. Experience with AWS products and services
  4. Knowledge of common software security vulnerabilities (memory corruption, privilege escalation, web application exploitation, protocol-based weaknesses, etc.) and analyzing their impact
  5. Working experience with vulnerability detection tools such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST) and Open Source Composition Analysis (SCA)
  6. Experience with scripting (Python, bash, etc.)

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Software Development Engineer, Specialized Businesses Security, Vulnerability Detections

Amazon

Seattle

On-site

USD 129,000 - 224,000

11 days ago