At a Glance
- Tasks: Lead security initiatives, conduct code reviews, and develop security tools for web applications.
- Company: Join Amazon's Corporate Services Security team, dedicated to safeguarding systems and data.
- Benefits: Enjoy work-life harmony, continuous learning, and opportunities for career growth in a diverse environment.
- Why this job: Make a real impact on security while collaborating with innovative teams and shaping strategies.
- Qualifications: 8+ years in web application security; expertise in threat modeling, secure coding, and AWS architecture.
- Other info: Diverse backgrounds are encouraged; apply even if you don't meet every qualification.
The predicted salary is between 48000 - 84000 £ per year.
Senior Security Engineer, Corporate Services Security
Job ID: 2874209 | Amazon Data Services UK Limited
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global Business Services (FGBS), People eXperience & Technology (PXT), Legal and Global Communications and Community Impact (GCCI) business units.
Our Mission is to protect and safeguard Amazon’s corporate services, systems, and data. Through proactive engagement with the development teams, we understand the dynamic business processes that run Amazon, and enable our stakeholders to innovate, build, and scale securely. The Product Security Team within CPSS supports a large number of applications built using AWS Services. Apart from work, we provide opportunities for our engineers to pursue projects they are passionate about while maintaining work life harmony.
Key Job Responsibilities
- Creating, updating, and maintaining threat models for a wide variety of web applications hosted on cloud
- Manual and Automated Secure Code Review, primarily in Java, Python and Javascript
- Development of security automation tools
- Adversarial security analysis using the latest tools to augment manual effort
- Provide Security training and outreach for internal development teams
- Provide Security architecture and design guidance to application development teams
- Independently solve systemic, complex security problems that require novel methods or approaches
- Influence your team’s and partners’ process, priorities, strategy and choices by using data to improve security outcomes
- Provide technical and strategic guidance to senior leaders and stakeholders through effective oral and written communications
A Day in the Life
As a Senior Security Engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing novel services. In a given day, you might be inspecting an application’s code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service.
The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security specialist with one or more areas of deep expertise within application security. They will clearly articulate risks to technical and non-technical audiences alike. Successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions. They will shape the strategy of the Product Security Team and influence systemic security improvements across our service organizations. They will guide and mentor other engineers on the team.
BASIC QUALIFICATIONS
- Minimum of 8 years of web application security industry experience with at least four of the following: threat modeling experience, secure coding, identity management and authentication, Web Application Security, cryptography, penetration testing, cloud security, mobile security, and network security
- Intimate knowledge and understanding of security engineering, web application security, system and network security, authentication and security protocols, cryptography
- Experience reading and writing in at least one programming language
PREFERRED QUALIFICATIONS
- BS in Computer Science or related field, or equivalent work experience
- Demonstrated ability of judgement in assessing and prioritizing technical risk
- Strong application security background with a focus on scalable solutions
- Experience building and securing complex AWS architecture
- Proven experience identifying and removing bottlenecks for your teammates, both in process and technology
- Experience securing Finance applications
- Proven experience shaping the strategy of a Product Security Team
- Demonstrated experience influencing security strategy across organization
Posted: November 7, 2024 (Updated 19 minutes ago)
Posted: January 6, 2025 (Updated 1 day ago)
Posted: January 10, 2025 (Updated 2 days ago)
Posted: January 21, 2025 (Updated 2 days ago)
Posted: December 5, 2024 (Updated 2 days ago)
#J-18808-Ljbffr
Senior Security Engineer, Corporate Services Security, Corporate Services Security employer: Amazon
Contact Detail:
Amazon Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Engineer, Corporate Services Security, Corporate Services Security
✨Tip Number 1
Familiarize yourself with Amazon's security culture and values. Understanding how Amazon prioritizes security and customer trust will help you align your responses during interviews and discussions.
✨Tip Number 2
Showcase your experience with AWS services, especially in relation to application security. Be prepared to discuss specific projects where you've implemented security measures in cloud environments.
✨Tip Number 3
Prepare to demonstrate your ability to communicate complex security concepts to both technical and non-technical audiences. This skill is crucial for influencing stakeholders and guiding teams towards secure solutions.
✨Tip Number 4
Highlight any experience you have in mentoring or leading teams. Amazon values candidates who can guide others and shape security strategies, so be ready to share examples of how you've done this in the past.
We think you need these skills to ace Senior Security Engineer, Corporate Services Security, Corporate Services Security
Some tips for your application 🫡
Tailor Your CV: Make sure to customize your CV to highlight your relevant experience in web application security, threat modeling, and secure coding. Use specific examples that demonstrate your expertise in the areas mentioned in the job description.
Craft a Strong Cover Letter: Write a compelling cover letter that outlines your passion for security and how your background aligns with Amazon's mission. Mention your experience with AWS architecture and your ability to influence security strategy, as these are key aspects of the role.
Showcase Technical Skills: Clearly list your technical skills, especially in programming languages like Java, Python, and JavaScript. Provide examples of projects where you applied these skills to solve complex security problems.
Highlight Leadership Experience: If you have experience mentoring other engineers or leading security initiatives, make sure to include this in your application. Amazon values candidates who can guide and influence their teams effectively.
How to prepare for a job interview at Amazon
✨Showcase Your Technical Expertise
Be prepared to discuss your deep knowledge in web application security, threat modeling, and secure coding practices. Highlight specific projects where you've successfully implemented security measures, especially in Java, Python, or JavaScript.
✨Communicate Clearly and Effectively
Since the role requires influencing both technical and non-technical stakeholders, practice articulating complex security concepts in simple terms. Use examples from your past experiences to demonstrate how you’ve communicated risks and solutions.
✨Demonstrate Leadership and Collaboration Skills
Prepare to share instances where you've led a team or influenced security strategies across an organization. Emphasize your ability to harmonize differing opinions and guide teams towards secure solutions.
✨Emphasize Continuous Learning and Adaptability
Amazon values curiosity and ongoing learning. Be ready to discuss how you stay updated with the latest security trends and tools, and how you’ve applied this knowledge to improve security outcomes in your previous roles.