Software Development Engineer II, AWS Vulnerability Management

Amazon.com Services LLC

Seattle (WA)

On-site

USD 140,000 - 210,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Amazon.com Services LLC is seeking a Software Development Engineer to join the AWS Vulnerability Management organization. You will build systems that automate vulnerability remediation across the AWS host fleet, working with service teams to reduce the attack surface and accelerate patching at scale.

You will prototype, productionize, and own components from idea to operation, with a focus on reliability, security data processing, and fleet-scale design.

Qualifications

  • 3+ years of non-internship professional software development experience.
  • 2+ years of non-internship design or architecture experience in distributed systems.
  • Experience programming with large-scale fleet data and automation.

Responsibilities

  • Build systems that determine why vulnerabilities persist across the AWS host fleet and drive remediation automatically.
  • Create detection to identify where patching automation is not reaching hosts and route findings to the owning team.
  • Prototype quickly against fleet-scale security data and take successful ideas to production and on-call.

Skills

Software development
System design
Fleet-scale engineering

Job description

We are seeking a Software Development Engineer to join the AWS Vulnerability Management organization. Our organization is accountable for the end to end vulnerability lifecycle across all of AWS. Within the organization, our team owns host operating system vulnerability management, and our job is to mitigate the highest security risks at machine speed and at the lowest cost to AWS. We find the hardest security problems in our fleet, build prototypes, iterate fast, and reduce the attack surface so vulnerabilities never reach production hosts. Working with some of the largest services at AWS like EC2, S3, RDS, SageMaker, and Amazon Linux means diving deep into operating systems, fleet automation, and security data at AWS scale.

The successful candidate is one who turns a hard security problem into a service that solves it fleet wide. You will build the systems that determine why vulnerabilities persist across millions of hosts, predict which ones will become critical before they do, and drive remediation without a human in the loop, moving mean time to remediate down and cutting the engineering hours AWS spends on patching. You will work directly with AWS service teams and partner security teams, prototype fast, and take what works from prototype to production. You will set the engineering practice for a growing team and own what gets built.

We are open to hiring candidates to work out of one of the following locations: Seattle, WA

Key job responsibilities
  • Build the systems that determine why vulnerabilities persist across the AWS host fleet and drive them to remediation automatically.
  • Build detection that identifies where patching automation is not reaching hosts, and route what it finds to the owning team.
  • Prototype fast against fleet-scale security data, then take what works to production and own it there, including on-call.
  • Partner with AWS service teams and security platform teams to reduce the attack surface across the fleet.
A day in the life

You will spend your days building and operating the systems that find and eliminate the causes of vulnerabilities across the AWS host fleet, at a scale where every decision has to be right the first time. You will prototype an idea, prove it against real fleet data, and take the ones that work into production. You will work directly with AWS service teams to turn what you find into remediation they can act on immediately. The team is security engineers with deep fleet expertise, a technical program manager, and a support engineer, and the engineering team is growing.

About the team

Our team owns host operating system vulnerability management for AWS. We find the hardest problems keeping vulnerabilities alive in the fleet, build the services that eliminate them, and work directly with the AWS service teams who run that fleet. You will build security services that protect AWS from real adversaries, at a scale where the solution has to be automatic. The engineering team is growing and the scope grows with it.

Diverse Experiences

Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.

Why Amazon Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture

In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth

We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve.

Basic Qualifications:
  • 3+ years of non-internship professional software development experience
  • 2+ years of non-internship design or architecture (design patterns, reliability and scaling) of new and existing systems experience
  • Experience programming w
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Development Engineer, AWS Vulnerability Management
Software Development Engineer, AWS Vulnerability Management

Amazon.com Services LLC • Seattle (WA)

On-site
USD 140,000 - 190,000
Software Development Engineer II, AWS Vulnerability Management
Software Development Engineer II, AWS Vulnerability Management

Socket.dev • Seattle (WA)

On-site
USD 144,000 - 194,000
Software Development Engineer, AWS Vulnerability Management
Software Development Engineer, AWS Vulnerability Management

Socket.dev • Seattle (WA)

On-site
USD 144,000 - 194,000
Health insurance
RSUs
401(k) matching
+1
Software Development Engineer, AWS Vulnerability Management
Software Development Engineer, AWS Vulnerability Management

Amazon • Seattle (WA)

On-site
USD 144,000 - 194,000
Software Development Engineer, Amazon Integrated Security
Software Development Engineer, Amazon Integrated Security

Amazon • Seattle (WA)

On-site
USD 144,000 - 194,000
Software Development Engineer II, Defensive Security - Security Findings Management
Software Development Engineer II, Defensive Security - Security Findings Management

Amazon • Austin (TX)

On-site
USD 120,000 - 180,000
Systems Development Engineer, Cryptography and Identity Management
Systems Development Engineer, Cryptography and Identity Management

Amazon Development Center U.S., Inc. • Seattle (WA)

On-site
USD 140,000 - 200,000
Software Development Engineer II, AWS Security
Software Development Engineer II, AWS Security

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 144,000 - 194,000
Health insurance
401(k) matching
Paid time off
+1
Software Development Engineer, AWS Vulnerability Management (AVM)
Software Development Engineer, AWS Vulnerability Management (AVM)

Amazon • Austin (TX)

On-site
USD 144,000 - 194,000
Health insurance
RSUs
401(k) matching
+2
Security Engineer II, Vulnerability Management and Remediation Operations
Security Engineer II, Vulnerability Management and Remediation Operations

Amazon • Seattle (WA)

On-site
USD 159,300 - 202,400