Application Security Engineer - Payments Security

Job ID: 1532768 | Amazon Data Srvcs Ireland Ltd


Job Description

Amazon is seeking qualified Application Security (AppSec) Engineers to join our innovative, high energy Payments Security Engineering (PSE) team and work within the Payments Engineering organization. Amazon Payments processes millions of transactions every day across numerous countries and payment methods. Paramount to our success is ensuring that our customer data is secure.

As an application security engineer within PSE, you will partner with engineering teams in a consulting facility throughout the Software Development Life Cycle (SDLC), to ensure that applications are designed and built securely. You will identify potential vulnerabilities in the applications and enable developers to understand and remediate such identified vulnerabilities.

Job Responsibilities:

· Develop a broad and deep technical understanding of products, services and architectures pertaining to the Payment Engineering organization.
· Leverage this understanding to conduct architecture reviews, threat modelling and code reviews on web applications, mobile applications and other relevant services.
· Interpret security tools and penetration testing results to stakeholders, providing advice on vulnerability remediation and risk mitigation.
· Create relevant documentation and metrics to your stakeholders and business leaders and deliver these in a clear, concise manner.
· Research and maintain proficiency in attacker Tools, Techniques, Procedures and other security topics.
· Propose and develop training materials to help raise the security bar across the Payment Engineering organization.
· Develop innovative and scalable tools, solutions, and processes to enhance the PSE’s operations.


· BS in Computer Science, Information Security, or equivalent professional experience.
· 5+ years of demonstrated experience in areas such as application security, offensive security and/or systems security.
· Understanding of threat modeling, security vulnerabilities, attacker exploit techniques, and methods for their remediation.
· Understanding of best practices in security engineering, including secure development, cryptography, systems security and/or policy.
· Excellent written and verbal communication skills with the ability to adapt messaging to executive, technical, and non-technical audiences.
· Ability to drive multiple technically complex security reviews together while remaining effective at providing security guidance to stakeholders.
· Ability to work with a high degree of autonomy.
· Scripting skills (E.g: Python, Perl, Bash, Ruby, PowerShell, etc.)


· 5+ years of experience in Secure SDLC.
· Experienced with reviewing and mitigating critical web application risks as defined by OWASP Top 10/SANS 25.
· Experienced with AWS services and security concepts.
· Programming experience in Python and/or Java.
· Relevant industry certifications from SANS, ISC2, etc.