Job Title: Corporate Services Security (CPSS)
We are part of the Amazon security team, aligned with Finance & Global Business Services (FGBS), People eXperience & Technology (PXT), Legal and Global Communications and Community Impact (GCCI) business units. Our Mission is to protect and safeguard Amazon's corporate services, systems, and data.
Key Responsibilities:
* Creating, updating, and maintaining threat models for web applications hosted on cloud
* Manual and Automated Secure Code Review in Java, Python, and Javascript
* Development of security automation tools
* Adversarial security analysis using latest tools to augment manual effort
* Providing Security training and outreach for internal development teams
* Providing Security architecture and design guidance to application development teams
* Solving complex security problems independently, requiring novel methods or approaches
* Influencing team processes, priorities, strategy, and choices using data to improve security outcomes
* Providing technical and strategic guidance to senior leaders and stakeholders through effective oral and written communications
About the Role:
As a Senior Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing novel services. In a given day, you might be inspecting an application's code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service.
Requirements:
* Minimum of 8 years of web application security industry experience with at least four areas of expertise: threat modeling, secure coding, identity management, Web Application Security, cryptography, penetration testing, cloud security, mobile security, and network security
* Intimate knowledge of security engineering, web application security, system and network security, authentication and security protocols, cryptography
* Experience reading and writing in at least one programming language
* BS in Computer Science or related field, or equivalent work experience
* Demonstrated ability of judgement in assessing and prioritizing technical risk
* Strong application security background with a focus on scalable solutions
* Experience building and securing complex AWS architecture
* Proven experience identifying and removing bottlenecks for your teammates, both in process and technology
* Experience securing Finance applications
* Proven experience shaping the strategy of a Product Security Team
* Demonstrated experience influencing security strategy across organization
About Us:
Amazon Security values diverse experiences. We encourage candidates to apply, even if they do not meet all of the qualifications and skills listed in the job description. We strive to create an inclusive culture that empowers Amazonians to deliver the best results for our customers.