SecEng III, AppSec
Job Description
Amazon.com Services LLC offers an Application Security role based in California (onsite), with a compensation range of USD 178,400 - 226,700 per yearly. The position supports secure engineering at scale through hands-on security work, automation, and collaboration with software teams, with sign-on payments, RSUs, comprehensive healthcare, and time off.
This SecEng III, AppSec opportunity is designed for experienced engineers with 8+ years in Application Security or Development, who want to improve outcomes by influencing how teams approach threat modeling, secure code review, and security design.
What you’ll do
- Create, update, and maintain threat models across a wide variety of software projects.
- Perform manual and automated secure code reviews, primarily using Java, Python, and JavaScript.
- Build security automation tools to increase coverage and efficiency.
- Conduct adversarial security analysis using innovative tools to strengthen and augment manual effort.
- Support internal teams through security training and outreach.
- Provide security architecture and design guidance to development partners.
- Independently tackle security problems that require novel methods or approaches.
- Help shape team and partner process, priorities, and choices to improve security outcomes.
Required qualifications
- 4+ years (non-internship) troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools.
- 5+ years identifying security issues and risks and developing mitigation plans.
- 4+ years (non-internship) scripting, programming, and security code review in common programming languages.
- Knowledge of at least two of: Scala, Java, Python, C/C++, Go.
- Experience (non-internship) identifying industry security vulnerabilities, attack patterns, and remediation techniques.
- 8+ years Application Security or Development experience.
Technologies you may use
Java, Python, JavaScript, Scala, C/C++, Go, command line tools, and service-oriented architectures (microservices) and web services.
Certifications listed for alignment include CCSP (Certified Cloud Security Professional), CEH (Certified Ethical Hacker), CFR (CyberSec First Responder), Cloud+, CySA+ (CompTIA Cybersecurity Analyst), GCED (GIAC Certified Enterprise Defender), GICSP (Global Industrial Cyber Security Professional), and PenTest+.
Preferred qualifications
- Experience with security in service-oriented architectures/microservices and web services.
- One or more: CCSP, CEH, CFR, Cloud+, CySA+, GCED, GICSP, or PenTest+.
Benefits
- Sign-on payments and restricted stock units (RSUs)
- Health insurance (medical, dental, vision, prescription)
- Basic Life & AD&D insurance
- Option for Supplemental life plans
- EAP
- Mental Health Support
- Medical Advice Line
- Flexible Spending Accounts
- Adoption and Surrogacy Reimbursement coverage
- 401(k) matching
- Paid time off
- Parental leave
Application deadline: Oct 5, 2026