Application Security Engineer
Job Description
Amazon’s Information Security organization is hiring a hands-on Application Security Engineer to help protect critical customer-facing systems and services. This Seattle, WA onsite role combines application security reviews, security design and testing, incident response support, and practical guidance for Amazon builders.
You will collaborate across partner teams and stakeholders to raise the security bar at scale, troubleshoot issues, and improve internal tooling that reduces overhead and improves efficiency. The position also includes participation in an on-call rotation as part of the team’s incident response coverage.
Key Responsibilities
- Preserve Amazon customer trust through security reviews and guidance.
- Conduct application security reviews for critical systems and services.
- Engineer security solutions to protect systems, networks, and applications.
- Support security design and testing for Amazon’s most critical applications.
- Respond to security violations, vulnerabilities, and event detection systems.
- Provide security policy guidance and consultations to teams.
- Evangelize security across Amazon and advocate for customer trust.
- Participate in a team on-call rotation.
- Provide security guidance and support to Amazon builders.
- Develop and deliver projects that increase the security bar at scale.
- Work closely with partner teams, stakeholders, and builders to drive security improvements across the company.
- Troubleshoot, maintain, and improve internal team tooling to reduce overhead and improve efficiency.
Requirements
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++, or a similar object-oriented language.
- 2+ years of scripting, programming, and security code review in a common programming language (non-internship).
- 2+ years troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship).
- Bachelor’s degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience.
- Knowledge of networking protocols such as HTTP, DNS, and TCP/IP.
- Knowledge of industry-based security vulnerabilities and remediation techniques.
- Knowledge of usage or integration experience with common cloud-hosted services.
- Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks.
- Experience with AWS products and services.
- Experience performing security activities across one or more phases of the SDLC, such as security design review, threat modeling, secure code review, and security testing.
Technologies
- Python, Ruby, Go, Swift, Java, .Net, C++
- HTTP, DNS, TCP/IP
Compensation
- USD 159,300 - 202,400 per year
Benefits
- Sign-on payments
- Restricted stock units (RSUs)
- Health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage)
- 401(k) matching
- Paid time off
- Parental leave
- Flexible work hours and arrangements
About the Team
- Diverse Experiences: Amazon Security values diverse experiences and encourages candidates to apply even if not all qualifications and skills are met.
- Inclusive Team Culture: ongoing DEI events and learning experiences; the team emphasizes diversity of ideas, perspectives, and voices to address complex security challenges.
- Training & Career Growth: knowledge-sharing, training, and other career-advancing resources.
- Work/Life Balance: flexible work hours and arrangements.