Sr. Security Engineer, Proactive Security
Job Description
As a Sr. Security Engineer in proactive application security at AWS Security, you will help validate the security of services, applications, and websites. The role focuses on application security analysis, issue discovery and remediation, security automation, and continuous improvement through metrics, guidance, and mentorship.
Location
Arlington, VA (onsite)
Compensation
USD 178,400 - 226,700 per year
Role Summary
This position partners with engineering teams to analyze application security, identify and address risks, and build security automation. You will also respond to new threat scenarios, contribute to security training and outreach, and drive process improvements. The role includes mentoring engineers and supporting recruiting and administrative activities as needed.
Responsibilities
- Conduct application security reviews, including architecture reviews, threat modeling, code reviews, and security testing
- Perform mobile security reviews
- Support projects and research work as needed
- Provide security training and outreach to internal development teams
- Deliver security guidance and documentation
- Build security workflow automation
- Deliver security metrics and drive process improvements
- Assist with recruiting activities and administrative work
Requirements
- 5+ years of any combination of application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing experience
- 5+ years of full secure software development life cycle experience, including coding standards, code reviews, source control management, build processes, testing, and operations
- 4+ years of non-internship scripting, programming, and security code review in common programming languages
- Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
- Bachelor's degree in Computer Science or a related field
- Experience identifying security issues and risks, and developing mitigation plans
- Non-internship experience identifying security vulnerabilities, attack patterns, and remediation techniques
- Experience as a mentor, tech lead, or leading an engineering team
- Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP
Technologies
- Scala
- Java
- Python
- C/C++
- Go
- HTTP(S)
- DNS
- TCP/IP
Benefits
- Sign-on payments and restricted stock units (RSUs)
- Health insurance including medical, dental, vision, prescription, Basic Life & AD&D, with option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, and Adoption and Surrogacy Reimbursement coverage
- 401(k) matching
- Paid time off
- Parental leave
Preferred Qualifications
- Experience applying threat modeling or other risk identification techniques
- Experience with security in service-oriented architectures, microservices, and web services
- Experience working with device technologies under development, including flashing firmware, basic device debugging, familiarity with reading or pulling device logs, or technical support experience
- Experience in any combination of application security frameworks, security code reviews, incident response, secure infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls, threat modeling, cryptography, threat intelligence, or secure software development
- Strong analytical skills, attention to detail, and effective communication, or experience in web security with automation and version control tools
About the Team
- Diverse Experiences
- Why Amazon Security?
- Inclusive Team Culture
- Training & Career Growth
- Work/Life Balance