Sr. Security Engineer, AppSec
Job Description
Amazon’s Stores organization ships a wide range of technology, and protecting customers is part of how those products are built and maintained. In this Senior Security Engineer role focused on AppSec, you will partner with software development teams to improve the security of novel services through practical reviews, threat thinking, and automation.
You will help turn security expertise into repeatable outcomes by leading threat model maintenance, performing secure code review, and using adversarial analysis to strengthen coverage. The role also includes mentoring through training and design guidance, plus influencing partner teams’ process and priorities so security risks are addressed early and effectively.
What you’ll do
- Create, update, and maintain threat models across a wide variety of software projects.
- Perform manual and automated secure code review, primarily using Java, Python, and JavaScript.
- Develop security automation tools to improve review and assurance workflows.
- Conduct adversarial security analysis using innovative tools to extend and augment manual security work.
- Provide security training and outreach to internal development teams.
- Deliver security architecture and design guidance for services and systems.
- Independently solve security problems that require novel methods or approaches.
- Influence your team and partners by shaping process, priorities, and choices to improve outcomes.
What you’ll bring
- 8+ years of Application Security or Development experience.
- 4+ years (non-internship) background troubleshooting systems issues, analyzing logs, or automating complex tasks with command line tools.
- 5+ years work identifying security issues and risks and developing mitigation plans.
- 4+ years (non-internship) scripting, programming, and security code review using common programming languages.
- Knowledge of at least two of: Scala, Java, Python, C/C++, or Go.
- Experience (non-internship) identifying industry-based security vulnerabilities, attack patterns, and remediation techniques.
- Experience in one or more domains: access-control systems and methodology, network security, application- and system-development security, security architecture and models, cryptography, or operations security.
- Technologies relevant to the role include Java, Python, JavaScript, Scala, C/C++, Go, and command line tools.
Preferred qualifications
- Experience with security in service-oriented architectures, including microservices and web services.
- One or more certifications: CCSP, CEH, CFR, Cloud+, CySA+, GCED, GICSP, or PenTest+.
Location and compensation
- Location: Seattle, WA (onsite)
- Salary: USD 178,400 - 226,700 per year
Benefits
- Health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance, and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage)
- 401(k) matching
- Paid time off
- Parental leave
Working culture
- Amazon values work-life harmony and flexibility as part of its working culture.
- The organization highlights resources that help reduce on-call time and support time on highest-value tasks.
Training, growth, and inclusion
- Ongoing knowledge sharing, training, and career-advancing resources to help you develop into a better-rounded professional.
- In Amazon Security, teams emphasize learning and curiosity, with DEI events and learning experiences.
If you do not meet every qualification listed, Amazon encourages candidates to apply, including those with non-traditional or alternative career paths.