Amazon - Austin, TX

posted 3 months ago

Full-time - Mid Level
Austin, TX
Sporting Goods, Hobby, Musical Instrument, Book, and Miscellaneous Retailers

About the position

AWS Security is at the forefront of addressing a wide array of security challenges across various platforms and technologies, including cloud services, Internet of Things (IoT), identity and access management, mobile devices, virtualization, and custom hardware, all operating at a massive scale. Our collaborative team is dedicated to the growth of each member as our business expands. We are seeking an Application Security Engineer to ensure that our services, applications, and websites are designed and implemented to the highest security standards. In this role, you will analyze the security of applications and services, identify and resolve security issues, build security automation, and respond swiftly to emerging threat scenarios. You will have the opportunity to learn from and be mentored by experts who are building and securing our cutting-edge services. As an Application Security Engineer at Amazon, you are expected to excel in multiple domains and make significant contributions to the AWS IT Security team and various groups throughout Amazon. Security engineers are tasked with developing elegant solutions to complex business problems and applying appropriate technologies while adhering to security engineering best practices. You will also mentor junior engineers and serve as a security thought leader within the organization. It is essential to foster constructive dialogue and seek resolution when faced with differing opinions. Engineers in this role are expected to actively participate in planning the AWS Security team's work and continuously seek opportunities for process improvement. A deep understanding of at least one specialty area is crucial, as you will be a sought-after resource both within AWS Security and across Amazon, while also having a broad understanding of Information Security applications in various technical areas.

Responsibilities

  • Conduct application security reviews including architecture reviews, threat modeling, code reviews, and security testing.
  • Perform mobile security reviews.
  • Engage in projects and research work as needed.
  • Provide security training and outreach to internal development teams.
  • Develop security guidance and documentation.
  • Automate security workflows.
  • Deliver security metrics and implement process improvements.
  • Assist with recruiting activities and administrative tasks.

Requirements

  • Bachelor's degree in Computer Science or a related field, or equivalent work experience.
  • Minimum of 2+ years of experience in security engineering, including architecture reviews, threat modeling, secure coding, system and network security, authentication and security protocols, cryptography, or application security.
  • Familiarity with common attack patterns and exploitation techniques for web and mobile applications and IoT devices.
  • Knowledge of commonly found software security vulnerabilities (e.g., OWASP top 10) and remediation techniques.
  • Understanding of basic networking and network security concepts (TCP/UDP, Firewalls/Switches, Wi-Fi security, TLS, etc.).

Nice-to-haves

  • Strong understanding of network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols).
  • Experience with Security Engineering and Assurance methodologies such as fuzzing, static and dynamic code analysis.
  • Experience with IoT/embedded device security (hardware and firmware security).
  • Demonstrable teamwork skills and resourcefulness.
  • Self-driven with the ability to progress initiatives despite ambiguity and imperfect knowledge.
  • Ability to manage multiple technically complex security reviews while effectively providing security guidance to stakeholders.
  • Strong sense of ownership, urgency, and ability to drive initiatives with a high degree of autonomy, along with excellent written and verbal communication skills.

Benefits

  • Comprehensive medical, financial, and other benefits packages.
  • Equity and sign-on payments as part of total compensation packages.
  • Flexible work hours and arrangements to support work-life balance.
  • Opportunities for knowledge-sharing and training for career advancement.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service