Are you passionate about delivering innovative security solutions and protecting millions of customers through automation and scalable security guardrails and paved roads? The Customer Service Security - Application Security team is looking for a talented and results-driven Security Engineer to help shape how Amazon protects customer data through secure-by-design principles.

In this role, you'll protect our customers by combining deep security expertise with automation and scalable solutions. You'll conduct threat modeling and security reviews, architect and implement automated security solutions, and partner with development teams and other security stakeholders to embed secure-by-default practices into their applications early and throughout the software development lifecycle. Using AWS services and modern development practices, you'll transform manual security processes into scalable solutions that secure Amazon's technology landscape.

If you're excited about solving complex security challenges through a blend of security engineering and automation, and want to deliver innovative solutions that protect millions of customers, join our team and help define the future of application security at Amazon.

Key job responsibilities
1. Design, develop, and implement automated security guardrails and paved roads that enable secure-by-default practices across Amazon's technology landscape

2. Conduct application security reviews, threat modeling sessions, and penetration testing to identify and remediate security risks early in the development lifecycle

3. Partner with development teams to embed security controls into their applications, providing technical guidance on complex architectural decisions

4. Lead security initiatives to establish automated security solutions using AWS services, transforming manual processes into scalable controls

5. Create and maintain security documentation, including architecture designs, implementation guides, and best practices to promote secure development practices

6. Identify security risks and drive continuous improvement in security controls and practices

7. Collaborate with security stakeholders to develop comprehensive security strategies and participate in periodic on-call rotations to support security incidents

About the team
The Customer Service Security - Application Security team provides proactive security guidance and support to an Amazon Customer Service. We address security early in the software development lifecycle by providing guardrails and paved paths. We bridge gaps between application security and software engineering by advocating for secure coding standards, automating processes, and developing reusable security solutions that are leveraged company-wide. We stay ahead through continuous research into emerging threats and the adoption of new techniques and best practices. Our collaborative environment encourages diverse perspectives and continuous learning to shape strategies that protect customer data while delivering reliable, trusted services.

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training and Career growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

BASIC QUALIFICATIONS

- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- Bachelor's degree in computer science or equivalent
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- 3+ years of experience in application security with any combination of the following: threat modeling experience, secure design reviews, code reviews

PREFERRED QUALIFICATIONS

- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Experience with AWS products and services
- Experience implementing security solutions at the business division level or equivalent
- Experience leveraging Large Language Models (LLMs) to automate and scale security, with a strong understanding of associated security risks and mitigation strategies
- Strong verbal and written communications skills

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.