Amazon Web Services (AWS) logo
Amazon Web Services (AWS)
Posted 47 days agoVerified live 1d ago

Security Engineer, AWS Security

Brief overview

Remote
UndergradOr in progress
$159k–$202k/yrStated range
3+ yrsMinimum
Security EngineeringScripting and ProgrammingSecurity Code ReviewThreat ModelingSecure CodingIdentity Management and AuthenticationCryptographyNetwork SecuritySecurity Vulnerability RemediationHTTP, DNS, and TCP/IPAI/ML for SecuritySecurity Testing

Job description

Summary

Amazon Web Services (AWS) is seeking a Security Engineer to secure the foundational compute and networking systems powering its cloud platform. The role focuses on designing automated security controls, embedding security into development, building scalable security tools, addressing risks, and advancing AI-enabled security practices.

Responsibilities

  • Design, build, and maintain automated security guardrails and paved paths that enable secure-by-default practices
  • Engage early with development teams at the ideation and design stage to embed security into applications from the start, providing guidance on secure architecture and coding practices
  • Build automated, continuous security assessment capabilities that replace manual security reviews and scale across our business unit
  • Contribute code for security fixes and paved path solutions directly alongside developers, making the secure path the easy path
  • Partner with developers to build scalable, self-service security tools that enable teams to identify and remediate security risks without bottlenecking on security teams
  • Design and implement preventive and detective security controls that provide continuous assurance rather than point-in-time assessments
  • Collaborate with security stakeholders to define and drive the long-term security strategy and participate in periodic on-call rotations to support security incidents
  • Leverage AI tools and techniques to accelerate security assessments, automate threat detection, and drive innovation in how we secure systems at scale

Skills

  • • 3+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • • 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • • Knowledge of industry-based security vulnerabilities and remediation techniques
  • • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • • Bachelor's degree in computer science or other related discipline
  • • Demonstrated experience using AI/ML tools and techniques to solve security problems, such as automating threat detection, triaging vulnerabilities, or augmenting code review and security analysis workflows
  • • 5+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • • Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
  • • Hands-on experience with AI-native development practices

Qualifications

Must Haves

  • • 3+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • • 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • • Knowledge of industry-based security vulnerabilities and remediation techniques
  • • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • • Bachelor's degree in computer science or other related discipline
  • • Demonstrated experience using AI/ML tools and techniques to solve security problems, such as automating threat detection, triaging vulnerabilities, or augmenting code review and security analysis workflows

Nice to Haves

  • • 5+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • • Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
  • • Hands-on experience with AI-native development practices

Benefits

  • Sign-on payments
  • Restricted stock units (RSUs)
  • Health insurance, including medical, dental, vision, prescription, Basic Life & AD&D insurance, and an option for Supplemental life plans
  • Employee Assistance Program (EAP)
  • Mental Health Support
  • Medical Advice Line
  • Flexible Spending Accounts
  • Adoption and Surrogacy Reimbursement coverage
  • 401(k) matching
  • Paid time off
  • Parental leave
  • Ongoing DEI events and learning experiences
  • Knowledge-sharing, training, and other career-advancing resources
  • Flexible work hours and arrangements

More jobs like this