Security Engineer , Global Services Security

apartmentAmazon placeHerndon calendar_month 
Global Services Security is looking for an Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You

will build and automate security assessments into scalable tools to enable and inspect collaboration across AWS including Amazon partners.

A Security Engineer at AWS is expected to be strong in multiple domains and provide significant contributions to the teams within AWS Global Services, Security and to multiple groups throughout Amazon. Security engineers are expected to develop elegant solutions to complex business problems and apply appropriate technologies while following security engineering best practices.

You are also expected to mentor more junior engineers and be a security thought leader for the organization.

A Security Engineer must foster constructive dialogue and seek resolution when confronted with discordant views. Engineers in this role are expected to participate fully in the planning of the security team's work and constantly seek opportunities for process improvement.

They should also have a deep understanding of at least one specialty for which they are a sought out resource (both within AWS IT Security and by groups throughout Amazon), while having an understanding of the application of Information Security in a broad range of technical areas.

You will have the combination of troubleshooting, technical, and communication skills, as well as the ability to handle a mix of disparate tasks which may include project and software development work. This role will provide career growth opportunities as you gain new security skills in the course of your duties.

Key job responsibilities
  • Security tool automation and development
  • Application security reviews
  • Secure architecture design
  • Threat modeling
  • Projects and research work as needed
  • Security training and outreach to internal development teams
  • Security guidance documentation
  • Security metrics delivery and improvements
  • Assistance with recruiting activities and administrative work
A day in the life

Diverse Experiences

Amazon values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why AWS

Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that’s why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve in the cloud.

Inclusive Team Culture

Here at AWS, it’s in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences, inspire us to never stop embracing our uniqueness.

Mentorship and Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.

About the team

The Global Services Security team, a part of Amazon Web Services (AWS), leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world’s workloads and building a brighter future for humanity requires us to focus on reliable delivery of bar raising security outcomes and investment in security mechanisms and automation on behalf of our customers- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • Knowledge of commonly found software security vulnerabilities (like OWASP top 10) and remediation techniques
  • 2+ years of programming in one of the following or similar: Python, Ruby, Go, Swift, Java, .Net, C++.- Experience with AWS products and services
  • Experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security
  • Experience with Security Engineering (building tools) and Assurance methodologies e.g. fuzzing, static and dynamic code analysis
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies.
Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation.

Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.
Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits.

For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

placeHerndon (VA)
and detailed oriented Junior Network Security Engineer to join our security operations team. The ideal candidate will have a strong understanding of information security principles and practices, a solid foundation in network security, effective communication...
apartmentAmazonplaceHerndon (VA)
Amazon Web Services is looking for a Security Engineer to join the SOC Physical Operations (PhysOps)Team! PhysOps drives physical security incident response across AWS spanning a range of physical, logical, and technical domains. At AWS, we obsess...
apartmentRandstadplaceWashington, 20 mi from Herndon (VA)
job summary: Job Description: Lead Security Engineer with entire Microsoft suite Azure. Expertise in Entra, Purview, Priva, and having additional knowledge in ADF / DataBricks. This key resource will conduct an assessment, develop, and implement...