Senior Security Engineer, Proactive Security

Amazon

Austin (TX)

On-site

USD 178,400 - 226,700

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

RSUs

Job summary

Amazon seeks a Senior Security Engineer, Proactive Security, to lead end-to-end security reviews for complex services and guide threat modeling across distributed systems.

You will mentor engineers, drive security tooling, and leverage AI/ML to automate workflows, improving remediation and risk reduction across the organization.

Qualifications

  • 4+ years of non-internship background troubleshooting systems issues and analyzing logs using command line tools

Responsibilities

  • Lead end-to-end security reviews for complex, high-priority services including design reviews, threat modeling, and scoping readouts
  • Provide architectural security guidance to service teams throughout the development lifecycle
  • Independently perform and guide threat modeling exercises for complex distributed systems
  • Conduct targeted manual code reviews of security-critical components
  • Scope, coordinate, and oversee penetration testing engagements and drive remediation with service teams
  • Identify, document, and track security findings to resolution and elevate critical issues to leadership when needed
  • Mentor junior engineers and contribute to team processes and tooling improvements
  • Design and build security automation, tooling, and processes to scale impact
  • Leverage generative AI and ML to automate review workflows and vulnerability detection
  • Partner with service teams to improve security posture and develop self-service guidance and readiness frameworks
  • Define and track security metrics that measure risk reduction and builder experience improvements

Skills

Troubleshooting
Log analysis
Automation
Scripting
Security code review
Mentorship
Leadership
Programming languages

Job description

Senior Security Engineer, Proactive Security

Job ID: 10485499 | Amazon.com Services LLC


Key job responsibilities


  • Security Reviews & Assessments: Lead end-to-end security reviews for complex, high-priority services including design reviews, threat modeling, and penetration testing scoping and readout

  • Technical Leadership: Serve as a subject matter expert for assigned affinity teams, providing architectural guidance and security consultation to service teams throughout the development lifecycle

  • Threat Modeling: Independently perform and guide threat modeling exercises for complex distributed systems, identifying risks and recommending mitigations

  • Manual Code Review: Conduct targeted manual code reviews of security-critical components, identifying vulnerabilities and insecure patterns that automated tools miss

  • Penetration Testing: Scope, coordinate, and oversee penetration testing engagements; analyze results and drive remediation with service teams

  • Findings Management: Identify, document, and track security findings to resolution; elevate critical issues to leadership when appropriate

  • Mentorship & Influence: Mentor junior engineers, contribute to team processes and tooling improvements, and raise the security bar across the organization

  • Design & Build Security Tooling: Design and build security automation, tooling, and processes that improve operational efficiency and scale the team's impact

  • AI-Powered Security Automation: Leverage generative AI and machine learning to build intelligent security automations that streamline review workflows, enhance vulnerability detection, and reduce manual toil

  • Builder Engagement: Partner with service teams to improve security posture proactively, including developing self-service guidance, documentation, and readiness frameworks

  • Metrics & Reporting: Define and track security metrics that measure risk reduction, operational efficiency, and builder experience improvements


About the team

Diverse Experiences


Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.


Why Amazon Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.


Inclusive Team Culture

In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.


Training & Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.


Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.


Basic Qualifications


  • 4+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience

  • 5+ years of work in identifying security issues and risks, and developing mitigation plans experience

  • 4+ years of (non-internship) scripting, programming, and security code review in common programming languages experience

  • Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go

  • Experience working in identifying security issues and risks, and developing mitigation plans

  • Experience as a mentor, tech lead or leading an engineering team


Preferred Qualifications


  • Experience applying threat modeling or other risk identification techniques or equivalent

  • Experience with security in service-oriented architectures/microservices and web services


Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.


Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.


The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.


USA, TX, Austin - 178,400.00 - 226,700.00 USD annually

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer, Corporate Services Security
Senior Security Engineer, Corporate Services Security

Amazon • Boston (MA)

On-site
USD 178,400 - 226,700
Health insurance
401(k) matching
Paid time off
+1
AI Security Engineer, AWS Security, AWS Security - AISec
AI Security Engineer, AWS Security, AWS Security - AISec

Amazon • Austin (TX)

On-site
USD 136,000 - 184,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 202,000
Sr Manager, Security Engineer, AWS Foundational & Hardware Security
Sr Manager, Security Engineer, AWS Foundational & Hardware Security

Amazon • Arlington (VA)

On-site
USD 208,300 - 281,800
Manager, Security Engineering, Secure Third Party Tools
Manager, Security Engineering, Secure Third Party Tools

Socket.dev • Arlington (VA)

On-site
USD 175,000 - 237,000
Security Engineer, Amazon Leo Security
Security Engineer, Amazon Leo Security

Socket.dev • Redmond (WA)

On-site
USD 159,000 - 202,000
Security Engineer – Sec Escalations, Security Escalations
Security Engineer – Sec Escalations, Security Escalations

Amazon • Herndon (VA)

On-site
USD 178,000 - 227,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Socket.dev • Austin (TX)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
Security Engineer II, AppSec Stores, Stores Security
Security Engineer II, AppSec Stores, Stores Security

Socket.dev • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+2
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 159,000 - 202,000