Sr. Security Engineer, Proactive Security, Leo Security - METALS

Socket.dev

Redmond (WA)

On-site

USD 178,000 - 227,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Amazon Security is seeking a senior engineer to drive secure-by-default solutions across product and operations for Project Kuiper. You will guide teams, mentor engineers and collaborate with Red Teams to ensure thorough threat modeling and proactive defense.

The role emphasizes defining security priorities and transforming security into an enabling, scalable capability across the organization. You will work in a fast-paced, startup-like environment backed by Amazon’s infrastructure, securing

Qualifications

  • 5+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience
  • 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
  • 5+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
  • Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
  • Experience as a mentor, tech lead or leading an engineering team
  • Experience in written and oral communication, including the ability to communicate with all levels in the organization (technical, business, executive)

Responsibilities

  • Guide teams towards solutions that are secure by default and invent or propose secure-by-default solutions when needed
  • Collaborate with automation teams to find discoverable vulnerabilities and advocate for new testing tools and detectors
  • Establish product-specific security bar, threat models and defense priorities to aid builders in consistent security execution across the business
  • Identify design and implementation defects and provide consultation on difficult security decisions
  • Collaborate with business leaders to define security priorities and measure security execution across the org
  • Provide strategic direction to address vulnerabilities and reduce long-term security costs
  • Mentor builders to become security advocates and engineers through 1-1 sessions and office hours
  • Assist Red Teams in scoping tests and analyzing incidents to prevent recurrence
  • Propose a security vision that protects customers and leads bleeding-edge tech efforts
  • Hack bleeding-edge tech and contribute to a high-security culture across teams

Skills

Troubleshooting
Security issues
Scripting
Languages
Mentor/Tech lead
Communication

Job description

Project Kuiper is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world.

Have you wanted an opportunity to secure an advanced satellite broadband telecom service? The Kuiper Security team owns the security of product and operations of Project Kuiper end-to-end. We provide the necessary infrastructure and mechanisms to ensure the security of our satellite constellation and to protect the integrity and confidentiality of our customer data. Our team drives the research & development, deployment and operation of several mission-critical security systems and mechanisms. You will work in a start-up like environment, backed by Amazon’s infrastructure to bootstrap security mechanisms, and help instill the security culture in the organization.

Export Control Requirement

Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

Key job responsibilities

You will guide teams towards solutions that are secure by default. If secure-by-default solutions don’t exist, you will invent & propose them. You will leverage support from automation teams that find discoverable vulnerabilities. You will advocate for the creation & deployment of new testing tools, and detection mechanisms.

You will be responsible for establishing product-specific security bar, threat models & defense priorities. These will aide builders in ensuring consistent security execution across the business. You’ll identify design & implementation defects. You'll support product development processes by providing consultation services on difficult security decisions.

You will collaborate with business leaders to define security priorities. You will support product leaders by acting as a trusted advisor. You will support leaders by providing them with direction that makes security easy. You will help leaders measure their org's security execution. You'll guide teams towards outcomes that produce products that safely handle customer data.

You will collaborate with builder teams to assess technical debt and risk. You will provide strategic direction that addresses vulnerabilities and fortifies our products. You will be a resource that leads the burn down of long-term risk.

You will guide teams towards solutions that are secure by default. If secure-by-default solutions don’t exist, you will invent & propose them. You will leverage support from automation teams that find discoverable vulnerabilities. You will advocate for the creation & deployment of new testing tools, and detection mechanisms.

You will enable builder teams to become proactive & self-sufficient on security. You will work with builder teams to understand their build processes. You'll ensure that they use appropriate security linting & static analysis tools. You'll help our builders find security solutions that reduce security operations costs over time. You will instill a security culture in builder teams. You will mentor builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours.

You will assist Red Teams in identifying security testing priorities. You will assist in scoping penetration tests and help deep-dive on these engagements. You will investigate emerging security issue, root cause them, and devise mechanisms to prevent them.

You will propose a security vision for the business that delivers security that protects our customers.

And last of all, you will hack some really cool bleeding edge tech!

A day in the life

In this highly dynamic role, you'll be accountable for deciding where your time investments provide the most value. You will have a blend of proactive and reactive work. Teams will reach out for ideas on how to handle a wide variety of security problems. You can anticipate implementation questions like

"What's the right way to handle authentication tokens in service to service communications?"

"We need to define security requirements for a confidential new product launch."

"We've experienced an incident and need to perform 5 why's analysis to identify and correct the problem that produced the incident."

When you're not working on responding to the questions of your builder teams, you will be evaluating overall org performance to identify architectural defects and proposing new security initiatives to correct problems in the org. You will help Amazon maintain a high bar for customer security.

About the team
Diverse Experiences

Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build

experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture

In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications:
  • - 5+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools experience
  • - 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
  • - 5+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
  • - Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
  • - Experience working in identifying security issues and risks, and developing mitigation plans
  • - Experience as a mentor, tech lead or leading an engineering team
  • - Experience in written and oral communication, including the ability to communicate with all levels in the organization (technical, business, executive)
Preferred Qualifications:
  • - Experience applying threat modeling or other risk identification techniques or equivalent
  • - Experience with security in service-oriented architectures/microservices and web services
  • - Experience using data and metrics to back up assumptions, evaluate outcomes, and make data-driven decisions
  • - 8+ years Experience in performing and/or participating in technical security assessments, e.g. code level, application level, or network/infrastructure assessments

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, WA, Redmond - 178,400.00 - 226,700.00 USD annually

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer, Amazon Leo Security
Security Engineer, Amazon Leo Security

Amazon • Redmond (WA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+2
Security Engineer, Leo Security
Security Engineer, Leo Security

Amazon • Redmond (WA)

On-site
USD 159,000 - 202,000
RSUs
Health insurance
401(k) matching
Application Security Engineer, Leo Proactive Security, Leo Security - METALS
Application Security Engineer, Leo Proactive Security, Leo Security - METALS

Socket.dev • Redmond (WA)

On-site
USD 159,000 - 202,000
Sr. Security Engineer, Proactive Security, Leo Security - METALS
Sr. Security Engineer, Proactive Security, Leo Security - METALS

Amazon • Redmond (WA)

On-site
USD 140,000 - 210,000
Senior Security Engineer, Corporate Services Security
Senior Security Engineer, Corporate Services Security

Amazon • Boston (MA)

On-site
USD 178,400 - 226,700
Health insurance
401(k) matching
Paid time off
+1
Senior Security Engineer, Proactive Security
Senior Security Engineer, Proactive Security

Amazon • Seattle (WA)

On-site
USD 178,000 - 227,000
Sr. Security Engineer, Leo Security
Sr. Security Engineer, Leo Security

Socket.dev • San Francisco (CA)

On-site
USD 183,000 - 248,000
Health insurance
401(k) matching
Paid time off
Senior Security Engineer, Proactive Security
Senior Security Engineer, Proactive Security

Amazon • Austin (TX)

On-site
USD 178,000 - 227,000
Health insurance
401(k) matching
Paid time off
+1
Senior Technical Program Manager, Leo Security, Leo Security - METALS
Senior Technical Program Manager, Leo Security, Leo Security - METALS

Amazon • Redmond (WA)

On-site
USD 148,700 - 201,200
Health insurance
401(k) matching
Parental leave
Security Engineer, Corporate Services Security
Security Engineer, Corporate Services Security

Amazon • Boston (MA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off
+1