Amazon is seeking qualified Senior Security Engineers to join our innovative, high energy Payments Security Engineering (PSE) team and work within the Payments Engineering organization. Amazon Payments processes millions of transactions every day across numerous countries and payment methods. Paramount to our success is ensuring that our customer data is secure.
As a senior security engineer within PSE, you will balance your efforts between strategic and operational deliverables. You will help define your team's long term and short term security strategy and in parallel partner with multiple engineering teams within Amazon, to ensure that applications are designed and built securely.
· Develop a broad and deep technical understanding of products, services and architectures pertaining to the Payment Engineering organization.
· Leverage this understanding to identify long term and short term security strategy to ensure that applications are designed and built securely.
· Partner with your stakeholders to conduct architecture reviews, threat modelling and code reviews on web applications, mobile applications and other relevant services.
· Interpret security tools and penetration testing results to stakeholders, providing advice on vulnerability remediation and risk mitigation.
· Create relevant documentation and metrics to your stakeholders and business leaders and deliver these in a clear, concise manner.
· Research and maintain proficiency in attacker Tools, Techniques, Procedures and other security topics.
· Propose and develop training materials to help raise the security bar across the Payment Engineering organization.
· Develop innovative and scalable tools, solutions, and processes to enhance the PSE’s operations.
· BS in Computer Science, Information Security, or equivalent professional experience.
· 8+ years of demonstrated experience in areas such as application security, offensive security and/or systems security.
· Understanding of threat modeling, security vulnerabilities, attacker exploit techniques, and methods for their remediation.
· Understanding of best practices in security engineering, including secure development, cryptography, network security, security operations, systems security, policy, and/or incident response.
· Excellent written and verbal communication skills with the ability to adapt messaging to executive, technical, and non-technical audiences.
· Ability to drive multiple technically complex security reviews together while remaining effective at providing security guidance to stakeholders.
· Ability to work with a high degree of autonomy.
· Scripting skills (E.g: Python, Perl, Bash, Ruby, PowerShell, etc.)
· 8+ years of experience in Secure SDLC.
· Experienced with reviewing and mitigating critical web application risks as defined by OWASP Top 10/SANS 25.
· Experienced with AWS services and security concepts.
· Programming experience in Python and/or Java.
· Relevant industry certifications from SANS, ISC2, etc.