Security Engineer, AmSec

AmazonArlington, VA

About The Position

Amazon Security is seeking a Security Engineer who thrives in ambiguity and is motivated to build scalable security solutions. The Secure Third Party Tools (S3T) team has bold ambitions to redefine how Amazon protects customer trust across all third-party interactions — shifting from reactive assessments to proactive, automated protection at global scale. Security Engineers are integral to this mission, combining deep technical review expertise with a builder's mindset to influence the AI-powered tooling that scales our impact. They must demonstrate excellent written and verbal communication skills, strong ownership on review engagements, integrating GenAI to improve operationally efficiency, and solid understanding of vendor security risk and effective controls. Security Engineers work backwards from customer risk to identify what matters most in a third-party engagement — there is no checklist. You'll apply threat modeling, architecture analysis, and enterprise security control knowledge to bottom out on key risks quickly, then translate findings into clear, actionable guidance. When barriers arise, you focus on solutions: scripting, leveraging AI tools, and codifying decisions in S3T tooling so the next review is faster and more accur. Security is central to maintaining customer trust and delivering delightful customer experiences. Our vision is that Builders raise the Amazon security bar when they use our recommended tools and processes, with no overhead to their business. S3T scales through software, not people — using high-judgment engineers to codify security decisions into automation that protects Amazon customers worldwide. Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. At Amazon, security is central to maintaining customer trust. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience across cloud, AI/ML, retail, and more. In Amazon Security, it's in our nature to learn and be curious. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices. We value work-life harmony. Flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve. Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations [https://amazon.jobs/content/en/how-we-hire/accommodations] for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Requirements

  • 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • Experience working in identifying security issues and risks, and developing mitigation plans
  • Experience in risk assessment and enabling organizations to make security decisions

Nice To Haves

  • Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks
  • Experience with AWS products and services
  • Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
  • Experience in identifying security risks in AI applications
  • Experience in using or developing AI tooling for risk assessment and enabling organizations to make security decisions
  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience

Responsibilities

  • Perform technical deep-dive security reviews of third-party services across diverse and ambiguous use cases, including AI/ML integrations, cloud architectures, and services handling sensitive customer data
  • Identify and trace data flows through complex systems, evaluating where security controls are lacking or require supplementation
  • Evaluate vendor penetration test reports, assessing finding applicability and severity within the context of each engagement
  • Threat model third-party use cases to rapidly surface sharp edges and drive risk-proportionate decisions
  • Influence and contribute to AI-powered security tooling that automates and scales review decisions across the organization
  • Clearly communicate identified risks and recommendations to service teams and leadership, driving resolution through escalation when needed
  • Author and improve security baselines, decision rubrics, and implementation patterns for novel third-party use cases

Benefits

  • health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage)
  • 401(k) matching
  • paid time off
  • parental leave
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service