Amazon logo
Amazon
Posted 11 days agoVerified live 1d ago

Security Engineer II, Stores AppSec

Brief overview

Remote
UndergradOr in progress
$159k–$202k/yrStated range
3+ yrsMinimum
17,535 H-1B approvalsDept. of Labor
9,838 green cardsCertified filings
Application Security ReviewsPenetration TestingSecurity Code ReviewPythonRubyGoSwiftJavaC++.NETCommand-Line ToolsLog AnalysisNetworking Protocols HTTPNetworking Protocols DNSNetworking Protocols TCP/IPSecurity Vulnerabilities and RemediationThreat Modeling

About the company

Amazon is a tech firm with a focus on e-commerce, cloud computing, digital streaming, and artificial intelligence.

Visa sponsorship history

4 years sponsoring, last filed FY2026H-1B dependent

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
17,535H-1B approved
95%approval rate
4,213new H-1B hires
9,838PERM certified
$194,500median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20235,035
20245,735
20254,327
20262,438
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20233,533
20245,158
20253,940
20263,351
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20236,267
20243,567
20251
20263
Top sponsored roles
Software Development Engineer IIProfessional Services IISolutions Architect IIISoftware Development Engineer IProfessional Services III
Sponsored employees from
IndiaChinaCanadaBrazilNigeria

Job description

Summary

Amazon is seeking a Security Engineer II to help protect its customers and services through application security assessments and penetration testing. The role involves discovering and reporting security issues, documenting remediation recommendations, improving security tooling, and collaborating with technical teams and senior leadership to resolve findings.

Responsibilities

  • Conducting high quality application security reviews and penetration tests independently, or as part of a team
  • Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
  • Contributing to team tooling, innovation, and improvements
  • Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings

Skills

  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  • 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
  • Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • Knowledge of industry-based security vulnerabilities and remediation techniques
  • 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks
  • Experience with AWS products and services
  • Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C++
  • Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing

Qualifications

Must Haves

  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  • 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience
  • Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • Knowledge of industry-based security vulnerabilities and remediation techniques

Nice to Haves

  • 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks
  • Experience with AWS products and services
  • Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C++
  • Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing

Benefits

  • Sign-on payments
  • Restricted stock units (RSUs)
  • Health insurance, including medical, dental, vision, prescription, Basic Life & AD&D insurance, and an option for Supplemental life plans
  • Employee Assistance Program (EAP)
  • Mental Health Support
  • Medical Advice Line
  • Flexible Spending Accounts
  • Adoption and Surrogacy Reimbursement coverage
  • 401(k) matching
  • Paid time off
  • Parental leave
  • Endless knowledge-sharing, training, and other career-advancing resources
  • Flexible work hours and arrangements

More jobs like this