Amazon - Seattle, WA

posted 4 months ago

Full-time - Mid Level
Seattle, WA
Sporting Goods, Hobby, Musical Instrument, Book, and Miscellaneous Retailers

About the position

Our team is responsible for growing an innovative global project that informs and drives larger company strategic decisions. We identify and improve the experience for Amazon's customers by applying various methodologies and building software solutions across a wide range of technical stacks. In this role, you will be responsible for implementing and maintaining technical security controls for a multi-cloud infrastructure while maintaining a high security bar that is in line with Amazon InfoSec and industry standard information security frameworks. This role will provide you with an opportunity to work across a broad set of systems and services, and if being in a dynamic multi-cloud environment and experimenting with the newest technologies sounds exciting to you, it will also be a lot of fun. You will be engaging with teams working on exciting new technologies, requiring highly customized security judgment outside of existing IT and security structures. You will be responsible for analyzing the security of applications and services, discovering and addressing security issues, building security automation, and decisively taking action to remediate emerging threats throughout a full secure development life-cycle. You will be partnering with system and software engineers and Amazon InfoSec to raise the security bar through secure design and architecture in a multi-cloud environment. You are a trusted resource on secure development and implementation practices, and work closely with engineers to identify opportunities to improve developer velocity and program efficiency while maintaining a high security and privacy bar. You will also lead work-streams to identify and prioritize security problems that can be detected using automation, and develop detection prototypes for security problems to enhance our toolset for static and dynamic analysis. Mentorship & Career Growth: We are dedicated to supporting new team members. Our team has a broad mix of experience levels and Amazon tenures, and we're building an environment that celebrates knowledge sharing and mentorship. We care about your career growth. You will work on projects and tasks that will develop your skills and enable you to take on increasingly complex tasks. Inclusive Team Culture: Our team is intentional about attracting, developing, and retaining amazing talent from diverse backgrounds. We're looking for a new teammate who is enthusiastic, empathetic, curious, motivated, reliable, and able to work effectively with a diverse team of peers; someone who will help us amplify the positive & inclusive team culture we've been building.

Responsibilities

  • Implement and maintain technical security controls for a multi-cloud infrastructure.
  • Analyze the security of applications and services, discovering and addressing security issues.
  • Build security automation and take action to remediate emerging threats throughout a full secure development life-cycle.
  • Partner with system and software engineers and Amazon InfoSec to raise the security bar through secure design and architecture.
  • Lead work-streams to identify and prioritize security problems that can be detected using automation.
  • Develop detection prototypes for security problems to enhance our toolset for static and dynamic analysis.
  • Create security guidance and documentation for team and customers.
  • Perform proactive risk assessments to identify threats to IT assets.
  • Collaborate with engineering to design and develop tools to improve security automation.
  • Support projects, create SOPs, and serve as an escalation point for information security issues.

Requirements

  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object-oriented language experience.
  • Bachelor's degree in computer science or equivalent.
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP.

Nice-to-haves

  • 3+ years of any combination of threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience.
  • Experience applying threat modeling or other risk identification techniques or equivalent.
  • Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent.
  • Experience with AWS products and services.

Benefits

  • Medical, financial, and other benefits as part of a total compensation package.
  • Equity and sign-on payments may be provided as part of the compensation package.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service