SDE, PubTech, Infrastructure, Amazon

Amazon Ads - Publisher Technology (PubTech) is a new and exciting program that is building supply side technology and pioneering novel experiences for our content publishers including audio (Alexa), video (Prime Video, Twitch, Freevee, FireTV), display (Amazon.com) to aid in their selling their inventory, optimize yield, and maximize monetization.The Publisher Ad Server Infrastructure team within PubTech is engaged in developing highly scalable ad serving mechanisms along with necessary features to serve ads. Among others, this team is responsible for ad serving for large Alexa, Prime Video, live events such as TNF, Twitch etc.Our scope has grown substantially and we are looking for a engineering leader to grow the team, build best in class publisher experiences and deliver a scalable system that will delight customers worldwide.Key job responsibilitiesWe are looking for a Software Development Engineer who can build on our early success, pioneer new programs for customers, and help define our future. As a member of the Publisher Ad Server team, you will spend your time as a hands-on engineer directly impacting ad delivery, customer experience and revenue. You will play a key role in building software products and features from the ground up to experiment and enable different ad strategies. You will use a wide range of technologies, programming languages and systems. Your responsibilities will include all aspects of software development. You will have the freedom and encouragement to explore your own ideas and the reward of seeing your contributions benefit tens of millions of customers. This is very much Day 1 for PubTech so you would be joining an entrepreneurial and pioneering team that is building from scratch.A day in the life- Monitor AWS CloudWatch dashboards for key metrics, set up and refine CloudWatch Alarms for critical thresholds- Analyze system performance using AWS X-Ray, Profiler and CloudWatch Logs- Manage Auto Scaling groups for EC2 instances, Optimize Elastic Load Balancer configurations, Plan and implement horizontal scaling strategies- Design and implement multi-AZ and multi-region architectures, Set up and maintain AWS Route 53 for DNS management and failover, Implement and test disaster recovery procedures- Maintain and update AWS CloudFormation templates or Terraform configurations- Maintain and improve the CI/CD pipeline using AWS CodePipelineAbout the teamThe Publisher Ad Server Infrastructure and Developer Experience (PAS InDEx) team is responsible for building and maintaining the underlying infrastructure and developer tooling for Publisher Ad Server. This includes handling API design/versioning, integration with internal and external systems (e.g. Inventory, Caching, Event Tracking and Amazon Ad Exchange), scaling and deployment, monitoring and logging, CI/CD pipelines, request cost optimization, and overall operational excellence.PAS InDEx team is also responsible for easing the onboarding by a self-serve documentation repository, and automating the publisher onboarding.BASIC QUALIFICATIONS- 2+ years of non-internship design or architecture (design patterns, reliability and scaling) of new and existing systems experience- Experience programming with at least one software programming language- 3+ years of non-internship professional software development experience ...

SDM for AWS Console Telemetry Services, AWS Infrastructure

AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. In other words, we’re the people who keep the cloud running. We support all AWS data centers and all of the servers, storage, networking, power, and cooling equipment that ensure our customers have continual access to the innovation they rely on. We work on the most challenging problems, with thousands of variables impacting the supply chain — and we’re looking for talented people who want to help. You’ll join a diverse team of software, hardware, and network engineers, supply chain specialists, security experts, operations managers, and other vital roles. You’ll collaborate with people across AWS to help us deliver the highest standards for safety and security while providing seemingly infinite capacity at the lowest possible cost for our customers. And you’ll experience an inclusive culture that welcomes bold ideas and empowers you to own them to completion.Interested in leading a software team that is a critical part of the control plane of AWS? Would you enjoy broad yet equally deep scope that impacts all AWS systems globally? Are you up for leading the software team that is at the interface of hardware and software? What do we do: AWS Infrastructure Console Services team develops the platforms and tools that support critical AWS control plane and monitoring functions. What you will do: You will have the opportunity to lead the team that builds, refactors, upgrades, and scales distributed software systems for AWS Console Services. You lead the service development, team management and coaching, operations, technical/business tradeoffs, and long term strategy, budgeting. You work with senior AWS leadership to plan for the future. Why it’s high-impact: Our services ensure that AWS services can control AWS hardware and to monitor this hardware for health and functionality. What’s the challenge: Our space is fast-moving, and has a large number of ambiguous and difficult challenges. You will have a team of highly skilled software developers, support from your leadership, and you'll own your space. You will be responsible for identifying solutions, trying ideas, given space to fail and iterate to produce products that your customers love.Who would succeed in this role: Deeply technical leaders, who stay close to the customer, daily operations, employee growth, as well as the architecture and design. A leader who can coach their team on developing and operating systems at scale and who reaches out across the organization to enlist input from key engineers to leverage the experience of the broader team. A person who dives deep in to a problem to deeply understand how things work, when to make subtle change, and when to disrupt the status quo to achieve the right results. A Software Development Manager in AWS Hardware Engineering Services needs to have key qualities to lead teams and steer successful projects.Technical Expertise - Strong understanding of distributed systems, software development processes, architecture at scale, data pipelines, global deployments, system design, and cloud proficiency. Global Infrastructure Partner. People Management/Leadership Skills - Ability to inspire and motivate small member teams. Run 1:1's, project checkpoints, weekly project review meetings, agile ceremonies (daily stand-up, planning, backlog grooming, retro) provide coaching and advocate for promotions. Helping engineers to grow in their career, mentoring, coaching engineers in the team and organization. Customer Focus - Understanding of customer needs and the ability to translate them into technical requirements and solutions. Key Product Manager for the team. Building out requirements and have impact on stakeholders through Road Map Vision. Project Management - Planning through 2025 and beyond, execution and monitoring, meeting deadlines, and delivering quality results. Owner of project communication. Agile Methodology. Daily stand ups. Bi-weekly task planner for team and Sprint planner. Capital project delivery. Operational Excellence - Strong analytical skills to identify issues, evaluate options, and bias for action to implement effective solutions. Owns operations and health of systems through dashboard. Strategic Thinking - Ability to align team goals into broader AWS Hardware Engineering Services. Build out Roadmap into 3-5 Year Vision. Present and connect with leaders in organization and customers on Roadmap. Adjust yearly planning to support overarching Vision. Look for ways to influence cross-functional teams by closely following known and unknown customer needs. Launch and lead project work in other areas to support Vision. Quality Assurance - Hold high bar for unit, integration and pre-prod testing before deploying code changes to production. Showcase deployment safety testing and code inspections to fix errors upstream and downstream. Innovation - Vision must have aspects of customer features and needs. Anticipating future technology in the pursuit of innovative solutions to enhance product offerings. Key job responsibilities - Effectively mentor and manage a team of software development engineers - Ensure that monitoring systems meet and exceed the requirements from Hardware Engineering Services and from our service owner customers (EC2, S3, EBS, et al) - Drive operational excellence - Contribute to and lead design, architecture, process and development discussions - Argue for the right outcomes with data, conviction and diplomacyA day in the lifeAn effective SDM for AWS Console Services will coach engineers, puts in place excellent closed loop mechanisms, drives OP1/OP2 for Monitoring, sets Director/MBR/Northstar Goals, sets a high systems design goal, and drives program management excellence through TPMs. This SDM will work closely with the counterparts in Hardware Engineering Services, S3, EC2, EBS, Annapurna, DCO, Data Center Automation and other areas in AWS to meet their technical and business requirements. About the teamAbout AWSDiverse ExperiencesAWS values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying. Why AWS?Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that’s why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.Inclusive Team CultureHere at AWS, it’s in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences, inspire us to never stop embracing our uniqueness.Mentorship & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional. Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve in the cloud.BASIC QUALIFICATIONS- 3+ years of engineering team management experience- 6+ years of leading the definition and development of multi tier web services experience- Bachelor's degree- 6+ years of leading the definition and development of distributed systems based micro services system. ...

Security Engineer – 2025 (US)

NOTE: By applying to this position, your application will be considered for all Security Engineer roles at all locations we hire for in the United States including but not limited to: Greater Seattle Area (Seattle, Bellevue, Redmond), Greater Bay Area (San Francisco, Sunnyvale, Santa Clara), Greater DMV (DC, MD, VA), Austin (TX), New York City (NY), Minneapolis (MN). Would you like to assess risk and help deliver countermeasures that protect customer data and prevent attempts to infiltrate company systems? Are you passionate about solving problems in an online world where threats grow ever more sophisticated? At Amazon, we hire the best minds in technology to innovate on behalf of our customers. The intense focus we have on our customers is why we are one of the world’s most beloved brands – customer obsession is part of our company DNA. Security engineers use cutting-edge technology to solve complex problems and get to see the impact of their work first-hand. The challenges security engineers solve for at Amazon are big and impact millions of customers, sellers, and products around the world. Our path is not always simple, so we are selective about who joins us on this journey. There is a certain kind of person who takes on this role at Amazon – someone who is excited by the idea of creating new products, features, and services from scratch while managing ambiguity and the pace of a company whose ship cycles are measured in weeks, not years.Key job responsibilitiesAs a Security Engineer, you will/may:• Collaborate with experienced Amazonians to create and execute security controls, defenses, and countermeasures to intercept and prevent internal and/or external attacks. • Develop, test, review, debug, or deploy code that supports security protocols. • Work effectively with your team to identify security problems and improve the security aspects of their service(s). • Assess risks that could affect the confidentiality, integrity, or availability of data, systems, or services. • Resolve security events, incidents, or conduct security assessments using penetration tests, ethical hacking tools, or risk mitigation methodologies to evaluate vulnerabilities. • Classify, store, and handle data in accordance with policy or best practices. • Troubleshoot, research the root cause of, and resolve security or risk issues with guidance.A day in the lifeWe’re on the lookout for the curious, those who think big and want to define the world of tomorrow.At Amazon, you will grow into the high impact, visionary person you know you’re ready to be. Every day will be filled with exciting new challenges, developing new skills, and achieving personal growth.How often can you say that your work changes the world? At Amazon, you’ll say it often. Join us and define tomorrow.About the teamBASIC QUALIFICATIONS• Currently working towards a Bachelor’s Degree in computer science, computer engineering, electrical engineering, cybersecurity, information security, or other equivalent discipline, with an expected conferral date between September 2023 – February 2025 and/or completed your degree within the last 24 months.• Experience with coding/scripting in one or more languages (e.g., Python, C, C++, Java, Ruby, or PowerShell).• Coursework, projects, and/or knowledge in one or more of the following domains: access-control system and methodology, network security, application- and system-development security, security architecture and models, cryptography, and operations security. ...

Security Engineer I, AppSec Stores

In Amazon Stores, we ship some of the widest arrays of technology found at any company. From Amazon.com to world class machine learning pipelines, from digital healthcare to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services. In a given day, you might be inspecting an application’s code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service alongside its software developers.The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security generalist with one or more areas of deep expertise. In their communication, they will clearly articulate risks to technical and non-technical audiences alike. Interpersonally, successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions.Our organization prizes its employees, and we show it through investing in work-life harmony. We have dedicated resources that consistently innovate in reducing on-call time and ensuring the team spend their time on the highest-value tasks. Join the stores AppSec organization to work hard, have fun, and make history!Key job responsibilities- Creating, updating, and maintaining threat models for a wide variety of software projects- Manual and Automated Secure Code Review, primarily in Java, Python and JavaScript- Development of security automation tools- Adversarial security analysis using modern tools to augment manual effort- Security training and outreach for internal development teams- Security architecture and design guidance- Independently solve security problems that require novel methods or approaches- Influence your team’s and partners’ process, priorities, and choices to improve outcomesAbout the teamAbout Amazon SecurityDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- Knowledge and understanding of application security, security engineering, system and network security, authentication an security protocols, cryptography, or application security.- Experience reading and writing in at least one programming language- BS degree in Computer Science, Computer Engineering, Electrical Engineering, similar technology degrees or 5+ years' equivalent technology experience ...

Security Engineer I, AppSTAR-NAMER

Amazon Information Security is looking for an Application Security Engineer to join our Application Review Team. You will have the opportunity to ensure security of applications that are under consideration for merger or acquisition.Our team approaches security challenges with empathy and curiosity to help service teams identify areas of improvement and guidance on how to remediate risk. Amazon Application Security focuses on enabling our builders to provide a secure and trustworthy experience to our customers without compromising the overall customer experience. As a Security Engineer on our team, you will solve interesting security challenges. You will need a combination of technical and communication skills as well as a cutomer-focused mindset and a desire to continue to grow and learn from those around you.Key job responsibilities* Creating, updating, and maintaining threat models for a wide variety of software projects* Manual and Automated Secure Code Review, primarily in Java, Python and Javascript* Development of security automation tools* Adversarial security analysis using modern tools to augment manual effort* Security training and outreach for internal development teams* Security architecture and design guidance* Independently solve security problems that require novel methods or approaches* Influence your team’s and partners’ process, priorities, and choices to improve outcomesAbout the teamWe are the Appstar-NAMER team, our mission is to provide high quality and timely security reviews and certifications for applications across Amazon. Our team is also dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded engineer and enable them to take on more complex tasks in the future.About Amazon Security:Diverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.Hybrid WorkWe value innovation and recognize this sometimes requires uninterrupted time to focus. We also value in-person collaboration and time spent face-to-face.BASIC QUALIFICATIONS- Experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent- Experience programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language- Bachelor's degree in computer science or equivalent ...

Security Engineer II, AppSec Stores

In Amazon Stores, we ship some of the widest arrays of technology found at any company. From Amazon.com to world class machine learning pipelines, from digital healthcare to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As a Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services. In a given day, you might be inspecting an application’s code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service alongside its software developers.The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security generalist with one or more areas of deep expertise. In their communication, they will clearly articulate risks to technical and non-technical audiences alike. Interpersonally, successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions.Our organization prizes its employees, and we show it through investing in work-life harmony. We have dedicated resources that consistently innovate in reducing on-call time and ensuring the team spend their time on the highest-value tasks. Join the stores AppSec organization to work hard, have fun, and make history!Key job responsibilities- Creating, updating, and maintaining threat models for a wide variety of software projects- Manual and Automated Secure Code Review, primarily in Java, Python and JavaScript- Development of security automation tools- Adversarial security analysis using modern tools to augment manual effort- Security training and outreach for internal development teams- Security architecture and design guidance- Independently solve security problems that require novel methods or approaches- Influence your team’s and partners’ process, priorities, and choices to improve outcomesAbout the teamAbout Amazon SecurityDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- 3+ year's experience in Application Security- Advanced knowledge and understanding of security engineering, system and network security, authentication an security protocols, cryptography, or application security.- Experience reading and writing in at least one programming language- BS degree in Computer Science, Computer Engineering, Electrical Engineering, similar technology degrees or 5+ years' equivalent technology experience ...

Security Engineer II, Security Assurance

At Amazon Healthcare Security, we are on a mission to make healthcare secure and easy. We are developing a patient-centric healthcare experience that is personal, transparent, and convenient. We are looking for a Senior Security Engineer to join our team.As a Security Engineer, your responsibility is to ensure the data, devices, 3rd Party services, and systems are secure, resilient, and compliant. Your teammates are a global team of security engineers, software developers, and technical program managers dedicated to continuously raising the security bar.A Security Engineer in Amazon will be strong in multiple security domains and sought out for advice on technical issues. Efficient time management skills are required along with the ability to deliver results in the face of uncertainty. Engineers in this role must show exemplary judgment in making technical trade-offs between short versus long term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. The successful candidate must be one that can handle several difficult challenges and problems, can make risk-based assessments founded on data and facts.Additionally, the successful candidate will be: - A leader on the team who can earn trust with the people they work with, both on their team and external partners - Methodically empirical and experimental in approach and evaluation without being bound by over paralysis-by-analysis; - Continuously improve knowledge of the security field, threat landscape, security intelligence, moving proactively toward prevention and detection of threats; - Be an enthusiastic learner and curiosity seeker, focusing on what can be done rather than hindered by notions of what cannot be; - Possess effective verbal and written communication skills, be passionate about sharing knowledge, tactics, strategy, as well as advocating for the project mission; - Have excellent time management skills along with the ability to deliver results in the face of uncertainty; and - Evangelize security within Amazon.com and be an advocate for customer trust.A successful candidate will be a deeply curious individual who brings technical expertise, and ability to work within a fast-paced startup culture in a large company that has broad business impact.Key job responsibilitiesCreating, updating, and maintaining threat models for a wide variety of software projectsManual and Automated Secure Code Review, primarily in Java, Python and JavascriptDevelopment of security automation toolsAdversarial security analysis using cutting-edge tools to augment manual effortProvide Security training and outreach for internal development teamsProvide Security architecture and design guidance to application development teamsIndependently solve systemic, complex security problems that require novel methods or approachesInfluence your team’s and partners’ process, priorities, and choices by using data to improve security outcomesProvide technical and strategic guidance to senior leaders and stakeholders through effective oral and written communicationsA day in the lifeAs a Security Engineer, you will collaborate with application development teams to ensure we keep our customers safe while developing novel services. In a given day, you might be inspecting an application’s code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service. The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security specialist with one or more areas of deep expertise within application security. They will clearly articulate risks to technical and non-technical audiences alike. Successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions.About the teamThe Amazon HealthSec ProdSec team is tasked with enabling the business to build secure, trustworthy healthcare products and services. We work closely with the business throughout the development process to help ensure great security decisions are made early and often. This allows us to be a partner with the business so security tradeoffs are infrequent.Working closely with our product teams means that we get to take part in deep technical discussion and decisions. We make sure we have time to get the right training and career growth opportunities so we can Dive Deep and Earn Trust with our build teams.We believe the best employees are ones who find what they do impactful, enjoyable, and purposeful. To that end we value training, career development, team culture, and work life balance for the long run. We want to make strategic choices for our team that will help build a culture of diversity, inclusion, development, and trust so our team works well together for a long time.Diverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying. Why Amazon Security At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve. Inclusive Team Culture In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training and Career growthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional. BASIC QUALIFICATIONS- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent- 5+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience- Bachelor's degree in computer science or equivalent ...

Security Engineer II, Security Services Delivery, Dedicated Security Team

At Amazon, we obsess over our customers and maintaining their trust. To earn that trust in an environment as vast and varied as Amazon’s requires the applied skills of smart security engineers and experienced, innovative security leaders willing to tackle challenges at dizzying scales.We are seeking Senior Security Engineers who want to help secure Amazon. If you’re passionate about Information Security, have exceptional technical depth in one or more security domains, and want to join a large scale, fast-paced organization with global impact on millions of customers, then we’d like to talk to you. We are passionate in our desire to secure Amazon's environments and protect our customers' trust and unflinching in our resolve to hold the security bar high.As a Security Engineer, you will be responsible for leading security diligence for acquisitions, designing and guiding post-close acquisition security roadmaps, identifying cross-cutting security risks, and enabling existing Amazon subsidiaries to seamlessly secure their environments through the delivery of innovative security solutions and acting as a Trusted Advisor across the organization. As part of the Security Services Delivery team you will also be responsible for improving Amazon’s subsidiary security at a company-wide scale by identifying opportunities to improve, build, or acquire security tooling, processes, and procedures. The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security generalist with one or more areas of deep expertise. In their communication, they will clearly articulate risks to technical and non-technical audiences alike. Interpersonally, successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions.Our organization prizes its employees, and we show it through investing in work-life harmony. We have dedicated resources that consistently innovate in reducing on-call time and ensuring the team spend their time on the highest-value tasks.Key job responsibilities- Communicate effectively at multiple levels of management and engineering, building trust across the organization, and demonstrating discretion with sensitive information.- Identify and drive continuous process improvements at unprecedented scale.- Support and deliver scalable security solutions across our diverse subsidiary networks.- Strong desire to up-skill and self-develop to learn at Amazon scale.- Demonstrate and promote security best practices and influence others to do the same.- Perform threat modeling and turn that into actionable plans to reduce risk.- Conduct pre-acquisition security due diligence interviews and create security findings and recommendations reports.- Create post-close secure integration roadmaps for new acquisitions, act as a Trusted Advisor to new and existing subsidiaries. - Identify the need for and evaluate security tooling, support the development of new tools and managed services.About the teamDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying. Why Amazon Security At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve. Inclusive Team Culture In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training and Career growthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional. BASIC QUALIFICATIONS- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience- Bachelor's degree in computer science or equivalent- Knowledge of networking protocols such as HTTP, DNS and TCP/IP ...

Security Engineer Summer Internship – 2025 (US)

Amazon internships are full-time positions, and interns should expect to work Monday-Friday, up to 40 hours per week typically between 8am-5pm. Specific team norms around working hours will be communicated by your manager. Interns should not have conflicts such as classes or other employment during the Amazon work-day.Applicants should have a minimum of one quarter/semester/trimester remaining in their studies after their internship concludes. By applying to this position, your application will be considered for all Security Engineer roles at all locations we hire for in the United States including but not limited to: Greater Seattle Area (Seattle, Bellevue, Redmond), Greater Bay Area (San Francisco, Sunnyvale, Santa Clara), Greater DMV (DC, MD, VA), Austin (TX), New York City (NY), Minneapolis (MN). You will be able to provide your preference of location and start date during the application process but, we cannot guarantee that we can meet your selection based on several factors including but not limited to the availability and business needs of this role. Finalization on the location and start dates available will be provided to you at the time of job offer. Start dates for our internships in this posting include the following period:1. Summer (Starts May/June 2025)Would you like to assess risk and help deliver countermeasures that protect customer data and prevent attempts to infiltrate company systems? Are you passionate about solving problems in an online world where threats grow ever more sophisticated? You will have the opportunity to impact the evolution of Amazon technology as well as lead mission critical projects early in your career.If this describes you, consider joining us as an security engineer intern! Amazon interns have the opportunity to work alongside the industry’s brightest engineers who innovate every day on behalf of our customers. Please review the following page for information on Amazon University Talent's recruiting timeline and additional FAQs: https://techengamazon.splashthat.com/Key job responsibilitiesAs a security engineer intern, you will/may: • Collaborate with experienced Amazonians to create and execute security controls, defenses, and countermeasures to intercept and prevent internal and/or external attacks • Develop, test, review, debug, or deploy code that supports security protocols • Work effectively with your team to identify security problems and improve the security aspects of their service(s) • Assess risks that could affect the confidentiality, integrity, or availability of data, systems, or services • Resolve security events, incidents, or conduct security assessments using penetration tests, ethical hacking tools, or risk mitigation methodologies to evaluate vulnerabilities • Classify, store, and handle data in accordance with policy or best practices • Troubleshoot, research the root cause of, and resolve security or risk issues with guidanceA day in the lifeOur internship program provides hands-on learning and building experiences for students who are interested in a career in security engineering. In addition to working on an impactful project, you will have the opportunity to engage with Amazonians for both personal and professional development, expand your network, and participate in fun activities with other interns throughout the summer. No matter the location of your internship, we give you the tools to own your internship and learn in a real-world setting.BASIC QUALIFICATIONS- Experience scripting with Python, Perl, Bash or PowerShell- Experience with at least one modern language such as Java, Python, C++, or C# including object-oriented design- Experience in one or more of the following domains: access- control system and methodology, network security, application- and system-development security, security architecture and models, cryptography, and operations security- Are 18 years of age or older- Work 40 hours/week minimum and commit to 12 week internship maximum- Currently working towards a Bachelor’s Degree in Computer Science, Computer Engineering, Cybersecurity, or other equivalent discipline, with an expected conferral date between October 2025 – December 2028. ...

Security Engineer-Infrastructure, Device Services Security

This is a security engineering role that provides direction for Amazon's Devices org. You will help meet Amazon's commitment to be Earth's most customer-centric company by establishing a high bar for security. You will set the security vision for cloud services that support Amazon's consumer products.At Amazon, security is everyone's responsibility. You will be the security leader who helps builders maintain a high security bar. You will assess org execution. You will provide technical direction. You will launch efforts to improve security execution within your partner org. You will lead implementation of security that gets trustworthy products to market quickly.In this role, you will be an offensive-minded insider who helps builder teams build resilient services & devices. You will be a technical leader who embodies the "Is right a lot" Leadership principle. You are the expert who finds the kinds of defects that static analysis tools miss. You will be responsible for driving better security outcomes across product teams. Key job responsibilitiesYou will be responsible for establishing product-specific threat models & defense priorities. These will aide builders in ensuring consistent security execution across the business. You’ll identify design & implementation defects. You'll support product development processes by providing consultation services on difficult security decisions. You will collaborate with business leaders to define security priorities. You will support product leaders by acting as a trusted advisor. You will support leaders by providing them with direction that makes security easy. You will help leaders measure their org's security execution. You'll guide teams towards outcomes that produce products that safely handle customer data.You will collaborate with builder teams to assess technical debt and for risk. You will provide strategic direction that addresses vulnerabilities and fortifies our products. You will be a resource that leads the burn down of long-term risk.You will guide teams towards solutions that are secure by default. If secure-by-default solutions don’t exist, you will invent & propose them. You will leverage support from automation teams that find discoverable vulnerabilities. You will advocate for the creation & deployment of new testing tools.You will enable builder teams to become proactive & self-sufficient on security. You will work with builder teams to understand their build processes. You'll ensure that they use appropriate security linting & static analysis tools. You'll help our builders find security solutions that reduce security operations costs over time. You will instill a security culture in builder teams. You will mentor builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours.You will assist Red Teams in identifying security testing priorities. You will assist in scoping penetration tests and help deep-dive on these engagements.You will propose a security vision for the business that delivers security that protects our customers. And last of all, you will hack some really cool bleeding edge tech!A day in the lifeIn this highly dynamic role, you'll be accountable for deciding where your time investments provide the most value. You will have a blend of proactive and reactive work. Teams will reach out for ideas on how to handle a wide variety of security problems. You can anticipate implementation questions like "What's the right way to handle authentication tokens in service to service communications?""We need to define security requirements for a confidential new product launch.""We've experienced an incident and need to perform 5 why's analysis to identify and correct the problem that produced the incident." When you're not working on responding to the questions of your builder teams, you will be evaluating overall org performance to identify architectural defects and proposing new security initiatives to correct problems in the org. You will help Amazon maintain a high bar for customer security.About the teamDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to buildexperience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- 5+ years of industry experience with hands-on security engineering experience on services- 5+ years of risk assessment and enabling organizations making security decisions- 5+ years influencing teams (including providing technical direction, coaching and mentoring)- 5+ years of experience communicating technical concepts to a non-technical audience- Strong verbal and written communications skills are a must, as well as the ability to work effectively across internal and external organizations ...

Security Engineer, AWS Cloud Response

The AWS Cloud Response Team manages the security and availability of AWS Cloud services. We operate on the ‘AWS’ side of the Shared Responsibility Model to ensure “Security of the Cloud” and to protect our customers. This role requires engineers to work tactically with both internal and external stakeholders to solve security challenges at massive scale, and to think strategically to develop and implement changes to drive automation, scalability and continuous progress for the organization.An ideal candidate should possess most of the following:- be able to assess technical vs. business risks and consistently drive internal engineering teams to take the right actions in the appropriate time frames to mitigate risks.- have a good mix of broad and deep technical knowledge and a demonstrated background in information security.- be technically proficient in the fields of network and operating system security, cryptography, software security, security operations, incident response, and emergent security intelligence.- possess a combination of troubleshooting, technical, and communication skills, as well as the ability to manage a mix of disparate tasks which may include small-project and software development work.- be comfortable challenging and escalating to senior leadership to always ensure the best outcome for customers.Key job responsibilitiesA successful candidate will need a combination of troubleshooting, technical, and communication skills, as well as the ability to handle a mix of disparate tasks which may include small-projects in addition to managing incident response activities. This role will provide career growth opportunities as you gain new security skills in the course of your duties.- Triage new incoming issues to determine the level of risk they present to AWS, and then accordingly prioritise its remediation in conjunction with the impacted service team.- Communicate the state of these issues to various audiences, both technical and non-technical, at various levels of seniority (up to and including AWS’ Chief Information Security Officer).- Participate in efforts to promote security throughout the Company and build good working relationships within the team and with others across Amazon- Demonstrate high capacity and tolerance for extreme context switching and interruptions while remaining productive and effective- Escalate issues to senior AWS leadership if you feel your issues are not progressing at the correct pace based on impact to ensure we are putting customers first.- Explore building and improving our tooling to make your own life easier and share that benefit with all our engineers globally.- Assistance with recruiting activities and administrative work- Fulfill regular on-call responsibilities.#SecOpsA day in the lifeA day in the lifeThis position supports AWS with security operations and incident response activities. You will be responsible for coordinating and facilitating security response activities for all AWS products and services. You will drive security related issues to resolution across numerous service teams, interacting directly with those teams and other AWS Security engineers.About the teamAbout the teamCloud Response is a team inside AWS Security Operations. This team is broadly responsible for the 'AWS' side of the Shared Responsibility Model, and provides oversight of security issues from their identification through to resolution. Cloud Response operates follow-the-sun with teams based around four different geographical locations.We work with other AWS teams, to ensure security issues are resolved with the right level of urgency, whilst ensuring that our stakeholders are kept into the loop. Diverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- Bachelor's degree in computer science or equivalent- Knowledge of networking protocols such as HTTP, DNS and TCP/IP- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience- 3+ years of proven experience with a focus in areas such as digital forensics and incident response- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security- Strong demonstrated knowledge of web protocols, common attacks, and an in-depth knowledge of Linux/Unix tools and architecture. ...

Security Engineer, AWS Security

Amazon Web Services (AWS) Security seeks a passionate and innovative Security Engineer for the AWS Vulnerability Management (AVM) team. At AWS, security is job zero, and our AVM team leads the way in securing our cloud services. We continuously raise the bar for security by blending analytics, cybersecurity skills, and technical expertise to protect our customers and the cloud. We are data-driven, set big goals, and are always challenging ourselves and each other to identify better solutions and take on new challengesAs a security engineer, you will focus on host operating systems (OS) patching and enable software builders to improve their service's security posture. You will define and execute both short-term and long-term strategies for vulnerability remediation, and drive remediation activities across AWS’s vast scale. You'll work closely with the builders to gain deep insights into their operational constraints, architectural consideration and compensating control and partner with senior security engineers to review, refine and optimize remediation plans. Your impact will be critical in helping AWS maintain top-tier security by balancing risk and service delivery. You'll focus on identifying security trends, enhancing security visibility, and recommending improvements to our security posture.Key job responsibilities- Collaborate closely with service teams to identify opportunities to improve the overall security posture- Partnering with product teams across AWS to develop scalable solutions to security problems- Developing tooling to automate and refine vulnerability management processes- Identifying security risks through data analytics.- Identifying and owning projects that continuously improve proactive security across AWS- Periodic on-call responsibilitiesAbout the teamDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience- Bachelor's degree in computer science or equivalent- Knowledge of networking protocols such as HTTP, DNS and TCP/IP- Knowledge of system security vulnerabilities and remediation techniques. ...

Security Engineer, AWS Security Cloud Response

The AWS Cloud Security Response team manages the security and availability of AWS Cloud services. We operate on the ‘AWS’ side of the Shared Responsibility Model to ensure “Security of the Cloud” and to protect our customers. This role requires engineers to work tactically with both internal and external stakeholders to solve security challenges at massive scale, and to think strategically to develop and implement changes to drive automation, scalability and continuous progress for the organization.We’re looking for talented software and systems professionals with a passion for security who thrive in dynamic environments to help us continue to raise the security bar for cloud computing.Successful candidates should:* be able to assess technical vs. business risks and consistently drive internal engineering teams to take the right actions in the appropriate time frames to mitigate risks.* have a good mix of broad and deep technical knowledge and a demonstrated background in information security.* be technically proficient in the fields of network and operating system security, cryptography, software security, security operations, incident response, and emergent security intelligence.* possess a combination of troubleshooting, technical, and communication skills, as well as the ability to manage a mix of disparate tasks which may include small-project and software development work.* be comfortable challenging and escalating to senior leadership to always ensure the best outcome for customers.An ideal candidate should be able to conduct most of the following:* Triage/assess security issues and engage with internal service teams to ensure prompt remediation of issues, escalating internally as necessary to ensure the right level of urgency and engagement.* Participate in efforts to promote security throughout the Company and build good working relationships within the team and with others across Amazon.* Demonstrate high ability and tolerance for frequent context switching and interruptions while staying productive and effective.* Develop pragmatic solutions that achieve business requirements while keeping an acceptable level of risk.* Help with recruiting activities and administrative work.* Mentoring of junior staff and proactive knowledge sharing within the team and across the company.* Fulfill regular on-call responsibilities.Key job responsibilities* Supply oversight of in-flight security issues.* Triage new incoming issues to determine the level of risk they present to AWS, and then accordingly prioritize its remediation in conjunction with the impacted service team.* Communicate the state of these issues to various audiences, both technical and non-technical, at various levels of seniority (up to and including AWS’ Chief Information Security Officer).* Escalate issues to senior AWS leadership if you feel your issues are not being treated at the correct pace due to their impact to ensure that we are putting customers first.* Explore building and improving our tooling to make your own life easier, and at the same time, sharing that benefit with all our engineers globally.A day in the lifeAs part of our "follow-the-sun rotation", you will receive a handoff from global peers and be delegated ownership of various security issues presently in-flight. The issues could relate to any of our 200+ products, so you will often need to learn on-the-fly.You will engage various stakeholders, such as the internal service team who owns the service and it's mitigation, along with AWS Security Leadership, Legal, and the leadership of the involved service team.As the day progresses, new issues will be automatically assigned to you based on your workload and you will be responsible for triaging them, determining their level of impact, and work towards resolving them at the appropriate pace.At the end of the day, you will have documented your work to allow the incoming shift to continue driving issues to resolution.About the teamCloud Response is a team within AWS Security Operations. This team is broadly responsible for the 'AWS' side of the Shared Responsibility Model, and provides oversight of security issues from their identification through to resolution.Diverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.Cloud Response operates with a "follow-the-sun model", with teams based around four different geographical locations.We work with other AWS teams to ensure security issues are resolved with the right level of urgency whilst ensuring that our stakeholders are informed.BASIC QUALIFICATIONS- BS degree in Computer Science, Computer Engineering, Electrical Engineering, or 3+ years’ equivalent technology experience.- 3+ years or more of proven experience with a focus in areas such as systems, network, and/or application security.- 2+ years of scripting/coding experience in any language (including Bash/PowerShell scripting). Previous experience in Python scripting would be ideal. ...

Security Engineer, AWS Security Vulnerability Management

Amazon is seeking a Security Engineer to join the AVM (AWS Vulnerability Management) organization. Our organization is accountable for the end-to-end software vulnerability lifecycle across all aspects of AWS. We are responsible for building the platform that monitors intelligence, detects vulnerabilities, drives remediation response, and drives innovation to meet the scale and demand of all AWS customers. Working with teams such as EC2, S3, RDS, CloudHSM, Containers, and Amazon Linux requires us to dive deep into all aspects of first- and third-party software across AWS including Operating Systems, firmware, databases, service/system hardening, cryptography, and audit analysis. We are passionate about diving deep to identify and build solutions that keep our customers safe.As a security engineer, you will help define and execute short-term and long-term strategy for vulnerability remediation. You're well-known for your excellent prioritization skills, as well as your ability to communicate at all levels of an organization (technical and non-technical). The successful candidate must be autonomous, comfortable operating in highly ambiguous situations, and relish the idea of solving security problems at scale.The successful candidate is one who loves working directly with software developers to understand their needs, and design security systems and solutions that enable developers to operate more effectively, securely and safely. You will have the opportunity to engage with systems that are at the cutting edge of technology. You will work directly with AWS service teams, partner security teams, and administrative teams to identify opportunities to improve our security posture. You will build tooling, drive process improvements, and work with service owners and cutting-edge technology to develop innovative solutions to complex technical challenges.The role can be located in Seattle, WAKey job responsibilitiesResearch and interpret vulnerability disclosures and intelligenceOwn and coordinate vulnerability assessment and triage activities with subject-matter experts across AWSOwn workstreams during large-scale remediation or triage campaigns.Author risk assessment statements, remediation guidance, and status reportsPartner with product teams across Amazon to develop scalable solutions to security vulnerabilitiesDevelop tooling to automate and refine vulnerability management processesPeriodic on-call responsibilities.A day in the life AWS Security is on the cutting edge of many security issues for a wide variety of platforms and technologies including cloud services, Internet of things (IoT), identity and access management, mobile devices, virtualization and custom hardware, all operating at massive scale. Our team drives large scale, long-term programs across all of AWS.About the teamOur organization is accountable for the end-to-end software vulnerability lifecycle across all AWS.Diverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- BS degree in Computer Science, Computer Engineering, Information Systems or related degree; or 4+ years equivalent technology experience- 3 years experience in system, network, and/or application security- 3 years experience in threat modeling and interpreting vulnerability disclosures- 2 years experience building automated tools in C, C++, Java, Python, Perl, PowerShell, or Ruby- Strong understanding of Windows and Linux internals and system design. ...

Security Engineer, AWS SOC

The Amazon Web Services Security Operations Center (AWS-SOC) Cloud Operations Team manages security issues across the globe. The team is looking for a highly motivated, technically inclined individual to work as a Security Engineer. A successful candidate will need to embody our 16 leadership principles; especially in Learn and Be Curious, Earns Trust, and Dives Deep. You will work from the Seattle, WA SOC location. You need to be comfortable working in a dynamic technical, and at times, ambiguous environment.Key job responsibilities- Monitor and analyze security alerts from various sources to detect and respond to potential threats in real-time.- Develop, implement, and fine-tune detection rules and correlation logic to improve threat detection capabilities.- Conduct in-depth investigations of security incidents, perform forensic analysis, and coordinate incident response activities.- Maintain and optimize security information and event management systems and other security tools used in the SOC.- Collaborate with other teams to enhance threat intelligence, improve incident response procedures, and provide regular reports on security posture.A day in the lifeAs a Security Engineer in Detections, your day revolves around safeguarding our digital assets. This position supports other AWS Security Engineers with security engineering, security operations and incident response activities. You will be responsible for coordinating and facilitating security response activities, fine-tuning detection rules. You'll investigate potential incidents, collaborate with threat intelligence teams, and develop new detection algorithms. About the teamDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- BS degree in Computer Science, Computer Engineering, Electrical Engineering, or 3+ years’ equivalent technology experience.- Minimum of 2 years’ experience on a Security team, especially experience coordinating responses to security incidents.- 1+ year knowledge of web protocols, common attacks, and an in-depth knowledge of Linux/Unix tools and architecture. ...

Security Engineer, Security Incident Response Team (SIRT)

Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within the Amazon Security Incident Response Team (SIRT). SIRT Security Engineers respond to security events, conduct analysis of threats such as malware and intrusion attempts, and provide security services to safeguard highly sensitive data. They work hands-on with detection systems and vulnerability analysis tools to respond to potential threats to Amazon systems. SIRT Security Engineers are unique individuals prepared to relentlessly resolve security issues by gathering and analyzing event data and conducting root-cause analysis. With your technical expertise, you will be solving security challenges at scale, working to protect the applications powering the most sophisticated e-commerce platform ever built. We value broad and deep technical knowledge, specifically in the fields of forensics, malware analysis, network security, application security, threat hunting, and threat intelligence.Key job responsibilities- Responding to security incidents, and coordinating a cohesive response involving multiple teams across Amazon.- Providing security engineering solutions and support during customer-facing incidents, proactively considering the prevention of similar incidents from occurring in the future.- Assisting in the development of pragmatic solutions that achieve business requirements while maintaining an acceptable level of risk.- Identifying and recommending solutions that improve or expand Amazon’s incident response capabilities.- Working alongside and mentoring Information Security engineers to improve security, reduce and quickly address risk.- Evaluating the impact of current security trends, advisories, publications, and academic research to Amazon, coordinating response as necessary across affected teams.- Keeping your knowledge and skills current with the rapidly changing threat landscape.- Participating in a follow-the-sun on-call rotation.A day in the lifeEngineers in this role triage and investigate security events to determine if they are a Security Incident. If they are a Security incident the candidate is responsible for containing the issue, ensuring it is eradicated from the environment and bring in the right reams to ensure full remediation. About the teamDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying. Why Amazon Security At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve. Inclusive Team Culture In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training and Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional. BASIC QUALIFICATIONS- Associate's degree or above- Experience working as part of a computer Security Incident Response Team (CSIRT) or Product Security Incident Response Team (PSIRT)- Knowledge of internet fundamentals and cloud computing concepts ...

Security Engineer, Threat Research Team, TRT, Networking Services & Edge

AWS Infrastructure Services owns the design, planning, delivery, and operation of all AWS global infrastructure. In other words, we’re the people who keep the cloud running. We support all AWS data centers and all of the servers, storage, networking, power, and cooling equipment that ensure our customers have continual access to the innovation they rely on. We work on the most challenging problems, with thousands of variables impacting the supply chain — and we’re looking for talented people who want to help. You’ll join a diverse team of software, hardware, and network engineers, supply chain specialists, security experts, operations managers, and other vital roles. You’ll collaborate with people across AWS to help us deliver the highest standards for safety and security while providing seemingly infinite capacity at the lowest possible cost for our customers. And you’ll experience an inclusive culture that welcomes bold ideas and empowers you to own them to completion.The AWS Threat Research Team (TRT) is looking for a security engineer with deep expertise in application and network security who is passionate about research, advocacy, and protecting large-scale, production applications. In this role, you will serve as an application and network security subject matter expert and work directly with AWS customers across industry verticals to protect applications against external threats. You will leverage your deep expertise and understanding of customer use cases to design and implement security policies that protect customers at-scale or address bespoke requirements. You will conduct both routine and reactive security research to improve customer understanding of threats, exposures, and vulnerabilities through external communication like blogs, whitepapers, and presentations. As the threat environment evolves, you will respond with rapid solutions and communication strategies that mitigate risk to customer applications and earn trust with stakeholders at all levels.About the team*Why AWS*Amazon Web Services (AWS) is the world’s most comprehensive and broadly adopted cloud platform. We pioneered cloud computing and never stopped innovating — that’s why customers from the most successful startups to Global 500 companies trust our robust suite of products and services to power their businesses.*Diverse Experiences*Amazon values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.*Work/Life Balance*We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve in the cloud.*Inclusive Team Culture*Here at AWS, it’s in our nature to learn and be curious. Our employee-led affinity groups foster a culture of inclusion that empower us to be proud of our differences. Ongoing events and learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences, inspire us to never stop embracing our uniqueness.*Mentorship and Career Growth*We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.BASIC QUALIFICATIONS- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience- Bachelor's degree in computer science or equivalent- Knowledge of networking protocols such as HTTP, DNS and TCP/IP ...

Security Engineering Manager, AWS Security

Join us in leading a team that builds innovative services protecting AWS from security threats!As a Security Engineering Manager in AWS Security, you’ll lead a team in building and managing innovative services that detect and automate the mitigation of cyber threats across all of Amazon’s infrastructure. You’ll manage software development engineers, data scientists, and security engineers to develop innovative security solutions at a massive scale. Our services help protect AWS for all customers, preserving our customers’ trust in us. Your team will get to use the full power and breadth of AWS technologies to build services that proactively protect every AWS customer, both internally and externally, from security threats – not many teams can say that!Candidates are expected to have a track record of delivering high-quality results in a dynamic environment. We need someone who’s comfortable building teams, developing talent, delivering results, and leading by example. The team's services operate at a large scale and on critical workloads, so good security judgement and a passion and discipline for operational excellence are key.Key job responsibilitiesAre you excited by big data and analytics technologies? Creating high-fidelity indicators of malicious behavior that are directly actionable? Able to capitalize on the scale and scope all of AWS can provide? Interested in leading a team of software developers, data scientists, and security engineers?If so, this is a high-impact, high-visibility role with responsibility across all of Amazon. You will have the opportunity to build teams and services that innovate with technology, scale, and security operations. You will work directly with AWS service teams, security operations, and infrastructure teams to continually identify, refine, and develop new ideas and opportunities for improving AWS' security posture. You will manage a mixed-discipline team that identifies and creates opportunities to raise the security posture across all of AWS infrastructure, helping to protect AWS, its employees, and our customers. A day in the lifeA successful candidate is one who thrives in a dynamic and diverse environment. You are passionate about utilizing big data and analytics to solve real business problems. This role will offer you the opportunity to lead architectural and technical innovation, and drive the direction of future security solutions. We have a team culture that encourages innovation and expects all team members to have a high degree of ownership for their program, vision, and execution of ideas.About the teamDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including the cloud.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexibility is part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- 3+ years of engineering team management experience- 5+ years of working knowledge and understanding of security engineering, system and network security, authentication and security protocols, cryptography, and application security- 1+ years of detection engineering experience- Experience managing and building teams that develop, maintain, and scale production software ...

Security Engineering Manager, AWS Vulnerability Management

Help us protect not only the Amazon Web Services (AWS) cloud computing environment but all of our customers as well! Since 2006, our great team at AWS has been enabling our customers to bring great ideas to life in ways that aren’t possible in traditional IT environments. With AWS you can flexibly harness compute, storage, security, and other services from across the globe as your business demands them.You will be responsible for managing a team of security engineers, support engineers, and technical program managers deeply investigating problems to enable builders to patch their host operating systems (OS) within the AWS patching SLAs. This includes prioritizing risks, building programs to build detection and prevention capabilities, collaborating closely with stakeholders in Builder Tools and the centralized patching automation tooling teams to simplify how host OS patching occurs in AWS. You will measure success through defined KPIs and program metrics to ensure we are achieving the security outcomes expected for this team. You will help set the direction for a team of security professionals that is responsible for all AWS products and services. This role combines long term strategic planning to raise the bar on security across the enterprise with the excitement and challenge of quickly reacting to new threat scenarios.As a security engineering manager at Amazon, you will be expected to speak authoritatively on behalf of your team and your technical knowledge should demonstrate both depth and breadth. You will be responsible for your team’s organizational structure and how that team works within the context of the larger AWS Security team. Leveraging the strengths of individual team members, delegating tasks appropriately and managing delivery of long term projects will all be critical tasks for this role. A security manager has deep knowledge in their domain and is a sought after thought leader across the organization. They have both management and technical expertise and actively participate in the organization’s planning processes.Key job responsibilities* Team management, growth, and organization* Professional development of team members* Project management* Metrics and projections* Driving security initiatives* Recruiting* Process Improvement* Work across AWS to partner on solutionsA day in the lifeIn this role you'll lead a team of engineers and TPMs, you'll build their careers and help solve complex security problems. You'll help identify trends in the findings your team generates and will work with partners to remove these bug classes at source. You'll participate in hiring, development, training, and team leadership. You'll own a part of the team and will be encouraged to grow your ownership and role.About the teamAt Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Diverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- A Bachelor’s degree in Computer Science, Cybersecurity, Information Security, degree in similar technical field, or equivalent professional experience can be used in lieu of a degree- Minimum of 5 years of experience in Security Engineering management- Minimum of 5 years of experience in managing or leading engineering teams- Experience in vulnerability management ...

Security Incident Response Engineer, AWS, AWS CorpSec Response

The Amazon Web Services team is looking for a passionate Security Incident Response Engineer who can lead the response to security issues across the largest cloud provider in the world. You must thrive in dynamic/ambiguous situations, and think like both an attacker and defender, while working through the entire incident response lifecycle. You’ll be working in a global team environment where clear and accurate communication and collaboration on security issues is critical. In this role you’ll be conducting security monitoring and response activities for the Amazon internal network. We value broad and deep technical knowledge, specifically in the fields of operating system security, network security, cryptography, software security, malware analysis, forensics, security operations, incident response, and emergent security intelligence. We don’t expect you to be an expert in all of the domains mentioned above, but we do expect you to be excited to learn about them! You’ll apply your creative and critical problem solving skills to quickly design and build tooling that enables programmatic automation at a massive scale. You must have a passion for engineering solutions to complex security challenges, and recognize and fill gaps in capabilities. Above all, you should be passionate about information security, the threat landscape and security automation and tooling.A day in the lifeDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- Bachelor's degree in computer science or equivalent- 5+ years or more of demonstrated experience with a focus in areas such as systems, network, and/or application security.- 3+ years of experience on a Security Operations team, coordinating responses to security incidents.- Proficiency with one high-level programming or scripting language. ...