DESCRIPTION:
The AppSec Security Engineer evaluates service design and architecture and performs deep-dive security assessments to ensure applications and services meet a high security bar before launch. This role works alongside senior engineers to identify issues, drive remediation, and validate that security requirements are met.
Key job responsibilities
- Security Reviews: Conduct design reviews for new and existing services, evaluating architecture documents and system designs for security risks.
- Threat Modelling: Identify attack vectors and security weaknesses in application architectures through structured threat modelling exercises.
- Penetration Testing: Coordinate penetration testing to validate security controls and identify exploitable vulnerabilities.
- Finding Management: Document, track, and communicate security findings to service teams with clear remediation guidance, and verify fixes are implemented.
- Security Guidance: Advise development teams on secure coding practices, authentication/authorization mechanisms, cryptographic implementations, and data protection strategies.
- Escalation Support: Identify and escalate high-severity issues through appropriate channels, ensuring timely remediation aligned with launch timelines.
- Documentation: Maintain clear documentation of review outcomes, security decisions, and risk assessments.
- Tool Improvements: Leverage automated tools to support reviews and improve efficiency.
About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.
BASIC QUALIFICATIONS:
- Experience with web protocols, common security attacks, and remediation (non-internship)
- Bachelor's degree or above in Computer Science, Computer Engineering, or related fields
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
- Experience in any combination of the following: application security frameworks, security code reviews, incident response, secure infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls, threat modeling, cryptography, threat intelligence, or secure software development
- Experience with coding/scripting in one or more languages (e.g., Python, C, C++, Java, Ruby, or PowerShell)
PREFERRED QUALIFICATIONS:
- Experience with AWS services or other cloud offerings