Sr. Security Engineer, Device Services Security
DESCRIPTION
This is a security engineering role that provides direction for Amazon's Devices org. You will help meet Amazon's commitment to be Earth's most customer-centric company by establishing a high bar for security. You will set the security vision for cloud services that support Amazon's consumer products.
At Amazon, security is everyone's responsibility. You will be the security leader who helps builders maintain a high security bar. You will assess org execution. You will provide technical direction. You will launch efforts to improve security execution within your partner org. You will lead implementation of security that gets trustworthy products to market quickly.
In this role, you will be an offensive-minded insider who helps builder teams build resilient services & devices. You will be a technical leader who embodies the "Is right a lot" Leadership principle. You are the expert who finds the kinds of defects that static analysis tools miss. You will be responsible for driving better security outcomes across product teams.
Key job responsibilities
You will be responsible for establishing product-specific threat models & defense priorities. These will aide builders in ensuring consistent security execution across the business. You’ll identify design & implementation defects. You'll support product development processes by providing consultation services on difficult security decisions.
You will collaborate with business leaders to define security priorities. You will support product leaders by acting as a trusted advisor. You will support leaders by providing them with direction that makes security easy. You will help leaders measure their org's security execution. You'll guide teams towards outcomes that produce products that safely handle customer data.
You will collaborate with builder teams to assess technical debt and for risk. You will provide strategic direction that addresses vulnerabilities and fortifies our products. You will be a resource that leads the burn down of long-term risk.
You will guide teams towards solutions that are secure by default. If secure-by-default solutions don’t exist, you will invent & propose them. You will leverage support from automation teams that find discoverable vulnerabilities. You will advocate for the creation & deployment of new testing tools.
You will enable builder teams to become proactive & self-sufficient on security. You will work with builder teams to understand their build processes. You'll ensure that they use appropriate security linting & static analysis tools. You'll help our builders find security solutions that reduce security operations costs over time. You will instill a security culture in builder teams. You will mentor builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours.
You will assist Red Teams in identifying security testing priorities. You will assist in scoping penetration tests and help deep-dive on these engagements.
You will propose a security vision for the business that delivers security that protects our customers.
And last of all, you will hack some really cool bleeding edge tech!
A day in the life
In this highly dynamic role, you'll be accountable for deciding where your time investments provide the most value. You will have a blend of proactive and reactive work. Teams will reach out for ideas on how to handle a wide variety of security problems. You can anticipate implementation questions like
"What's the right way to handle authentication tokens in service to service communications?"
"We need to define security requirements for a confidential new product launch."
"We've experienced an incident and need to perform 5 why's analysis to identify and correct the problem that produced the incident."
When you're not working on responding to the questions of your builder teams, you will be evaluating overall org performance to identify architectural defects and proposing new security initiatives to correct problems in the org. You will help Amazon maintain a high bar for customer security.
About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build
experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
BASIC QUALIFICATIONS
- 5+ years of industry experience with hands-on security engineering experience on services
- 5+ years of risk assessment and enabling organizations making security decisions
- 5+ years influencing teams (including providing technical direction, coaching and mentoring)
- 5+ years of experience communicating technical concepts to a non-technical audience
- Strong verbal and written communications skills are a must, as well as the ability to work effectively across internal and external organizations
PREFERRED QUALIFICATIONS
- Experience in performing and/or participating in technical security assessments
- Hands-on experience working successfully in a very fast-paced, results-oriented environment
- Strong analytical and quantitative skills with the ability to use data and metrics to back up assumptions and recommendations that produce results
- Experience developing security tools & processes that work at scale
- Experience triaging security risks/vulnerabilities and ensuring that they are properly understood by the business and fixed and/or mitigated.
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.