2 days ago
Base Salary
$159k - $202k/yr
Responsibilities
- Own security outcomes for assigned builder teams and the HR and Legal applications they operate.
- Threat model GenAI and LLM-backed applications, including prompt injection, insecure output handling, data leakage through model context, and excessive agent authority.
- Secure agentic workflows through transitive authentication and scoped authorization.
- Author and refine automated detection rules that identify risks at code commit and provide actionable fixes.
- Use GenAI for AI-assisted code review, detection authoring, and triage.
- Drive adoption of Secure CDK Blueprints, automated patching, standardized authorization, and transitive authentication for agentic workflows.
- Perform adversarial analysis and manual secure code review in Java, Python, and JavaScript, then turn identified gaps into new detections.
- Provide security architecture guidance and lead security outcomes for design reviews.
- Prioritize remediation by business impact and escalate launch-blocking risk decisions when needed.
- Communicate security outcomes to security and service team leadership and mentor other engineers.
Requirements
- 3+ years of programming experience in Python, Ruby, Go, Swift, Java, .Net, C++, or a similar object-oriented language.
- 2+ years of non-internship scripting, programming, and security code review experience in a common programming language.
- 2+ years of non-internship experience troubleshooting systems issues, analyzing logs, or automating basic tasks with command-line tools.
- Bachelor’s degree in computer science or equivalent, or qualifying IT Security experience as specified in the posting.
- Knowledge of networking protocols including HTTP, DNS, and TCP/IP.
- Knowledge of industry security vulnerabilities and remediation techniques.
- Preferred: 2+ years in combinations of threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, or network security.
- Preferred: experience with AWS products and services.
- Preferred: experience performing security activities across software development lifecycle phases such as security design review, threat modeling, secure code review, and security testing.
Benefits
- Comprehensive health insurance, including medical, dental, vision, prescription, Basic Life and AD&D insurance, and optional supplemental life plans.
- Employee Assistance Program, mental health support, medical advice line, flexible spending accounts, and adoption and surrogacy reimbursement coverage.
- 401(k) matching, paid time off, and parental leave.
- Additional package components include sign-on payments and restricted stock units; the position is based in Seattle, Washington.