Application Security Engineer, AWS Security
Job Description
The Application Security Engineer for AWS Security role focuses on validating the security of AWS services, applications, and websites. You will assess application security, identify and address issues, automate security workflows, and respond rapidly when new threat scenarios emerge.
Location
Seattle, WA (onsite)
Salary
USD 159,300 - 202,400 per year
Responsibilities
- Conduct application security reviews
- Perform penetration testing activities
- Complete projects and research work as required
- Support security training and outreach to internal development teams
- Develop and maintain security guidance documentation
- Build security tooling and automation
- Deliver security metrics and drive improvements based on findings
- Provide assistance with recruiting activities and administrative work
Requirements
- 3+ years of programming experience in Python, Ruby, Go, Swift, Java, .Net, C++, or a similar object-oriented language
- 2+ years of scripting, programming, and security code review experience in a common programming language (non-internship)
- 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship)
- Bachelor’s degree in a STEM field (Science, Technology, Engineering, Mathematics) or 2+ years of IT Security experience
- Knowledge of networking protocols including HTTP, DNS, and TCP/IP
- Knowledge of industry security vulnerabilities and remediation techniques
Technologies
- AWS
- Python, Ruby, Go, Swift, Java, .Net, C++
- HTTP, DNS, TCP/IP
Benefits
- Sign-on payments
- Restricted stock units (RSUs)
- Health insurance, including medical, dental, vision, prescription, Basic Life & AD&D coverage, and options for Supplemental life plans
- EAP and Mental Health Support
- Medical Advice Line
- Flexible Spending Accounts
- Adoption and Surrogacy Reimbursement coverage
- 401(k) matching
- Paid time off
- Parental leave
Preferred Qualifications
- 2+ years of any combination of: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, and network security
- 2+ years of scripting, programming, or security code review in a common language such as Python, Java, or C++
- Knowledge of networking protocols including HTTP(S), DNS, and TCP/IP
- Experience performing security activities across one or more phases of the SDLC, such as security design review, threat modeling, secure code review, and security testing
Minimum Experience
3 years
Education
Bachelor’s degree in a STEM field (Science, Technology, Engineering, Mathematics)