5 days ago
Base Salary
$178k - $227k/yr
Responsibilities
- Conduct application security reviews, including architecture reviews, threat modeling, code reviews, and security testing.
- Perform mobile security reviews and investigate security issues, risks, attack patterns, and remediation techniques.
- Build security workflow automation and deliver security metrics and process improvements.
- Provide security training, guidance, documentation, and outreach to internal development teams.
- Lead projects and research, mentor junior engineers, and provide security thought leadership and guidance to stakeholders.
- Assist with recruiting activities and administrative work.
Requirements
- 5+ years of experience in a combination of application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing.
- 5+ years of experience across the full secure software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations.
- 4+ years of non-internship experience with scripting, programming, and security code review in common programming languages.
- Knowledge of at least two of Scala, Java, Python, C/C++, or Go.
- Bachelor’s degree in Computer Science or a related field.
- Experience identifying security issues and risks and developing mitigation plans.
- Experience identifying industry-based security vulnerabilities and applying attack patterns and remediation techniques.
- Experience as a mentor, tech lead, or engineering team leader.
- Knowledge of common software security vulnerabilities, including the OWASP Top 10, and remediation techniques.
- Knowledge of networking and network security concepts, including TCP/UDP, firewalls, switches, Wi-Fi security, and TLS.
- Preferred experience with threat modeling or other risk identification techniques, security in service-oriented architectures, microservices and web services, device technologies, firmware flashing, device debugging, device logs, technical support, fuzzing, and static or dynamic code analysis.
- Ability to drive multiple technically complex security reviews while providing effective security guidance to stakeholders.
Benefits
- Comprehensive benefits including medical, dental, vision, prescription, life and AD&D insurance, an employee assistance program, mental health support, a medical advice line, flexible spending accounts, adoption and surrogacy reimbursement, 401(k) matching, paid time off, and parental leave.
- Flexible work hours and arrangements are part of the team’s work culture.
- Access to knowledge-sharing, training, DEI learning experiences, and career-development resources.
- The compensation package may include sign-on payments and restricted stock units.
About Amazon
Amazon builds and operates a global e-commerce marketplace, logistics network, and consumer devices, and provides cloud computing via AWS for businesses and developers. The company earns revenue from online retail, third‑party seller services, subscriptions like Prime, advertising, and AWS usage. Founded in 1994 and headquartered in Seattle, it is publicly traded on NASDAQ (AMZN) and serves customers in dozens of countries.
