Skip to main content
Back to jobs

Sr. Security Engineer (Vulnerability Management), Leo Security

External
Amazon.com Services LLC logoAmazon.com · Redmond, WA
Full-timeOn-site1w ago
ReactAWS
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying. Why Amazon Security? At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportuni

Requirements

  • Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
  • Key job responsibilities
  • You will be responsible for driving scalable security patching mechanisms across a heterogeneous product and enterprise environment, and advise on security priorities. These will aide builders in ensuring consistent security execution across the business. You'll support product development processes by ensuring builders start with secure by default assets and infrastructure.
  • You will collaborate with business leaders to define security priorities. You will support product leaders by acting as a trusted advisor. You will support leaders by providing them with direction that makes security easy. You will help leaders measure their org's security execution. You'll guide teams towards outcomes that produce products that safely handle customer data.
  • You will collaborate with builder teams to assess technical debt and risk. You will provide strategic direction that addresses vulnerabilities and fortifies our products. You will be a resource that leads the burn down of long-term risk.
  • You will guide teams towards solutions that are secure by default. If secure-by-default solutions don't exist, you will invent & propose them. You will leverage support from automation teams that find discoverable vulnerabilities. You will advocate for the creation & deployment of new testing tools, and detection mechanisms.
  • You will assist Red Teams in identifying security testing priorities. You will assist in scoping penetration tests and help deep-dive on these engagements. You will investigate emerging security issue, root cause them, and devise mechanisms to prevent them.
  • You will propose a security vision for the business that delivers security that protects our customers.
  • A day in the life
  • In this highly dynamic role, you'll be accountable for deciding where your time investments provide the most value. You will have a blend of proactive and reactive work. Teams will reach out for ideas on how to handle a wide variety of security problems. You can anticipate implementation questions like
  • "What's the right way to handle authentication tokens in service to service communications?"
  • "We need to define security requirements for a confidential new product launch."
  • "We've experienced an incident and need to perform 5 why's analysis to identify and correct the problem that produced the incident."
  • When you're not working on responding to the questions of your builder teams, you will be evaluating overall org performance to identify architectural defects and proposing new security initiatives to correct problems in the org. You will help Amazon maintain a high bar for customer security.

Additional Information

Project Leo is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world. Have you wanted an opportunity to secure an advanced satellite based broadband telecom service? The Leo Security team owns the security of product and operations of Project Leo end-to-end. We provide the necessary infrastructure and mechanisms to ensure the security of our satellite constellation and to protect the integrity and confidentiality of our customer data. Our team drives the research & development, deployment and operation of several mission-critical security systems and mechanisms. You will work in a start-up like environment, backed by Amazon's infrastructure to bootstrap security mechanisms, and help instill the security culture in the organization. Export Control Requirement Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum. Key job responsibilities You will be responsible for driving scalable security patching mechanisms across a heterogeneous product and enterprise environment, and advise on security priorities. These will aide builders in ensuring consistent security execution across the business. You'll support product development processes by ensuring builders start with secure by default assets and infrastructure. You will collaborate with business leaders to define security priorities. You will support product leaders by acting as a trusted advisor. You will support leaders by providing them with direction that makes security easy. You will help leaders measure their org's security execution. You'll guide teams towards outcomes that produce products that safely handle customer data. You will collaborate with builder teams to assess technical debt and risk. You will provide strategic direction that addresses vulnerabilities and fortifies our products. You will be a resource that leads the burn down of long-term risk. You will guide teams towards solutions that are secure by default. If secure-by-default solutions don't exist, you will invent & propose them. You will leverage support from automation teams that find discoverable vulnerabilities. You will advocate for the creation & deployment of new testing tools, and detection mechanisms. You will enable builder teams to become proactive & self-sufficient on security. You will work with builder teams to understand their build processes. You'll ensure that they use appropriate security linting & static analysis tools. You'll help our builders find security solutions that reduce security operations costs over time. You will instill a security culture in builder teams. You will mentor builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours. You will assist Red Teams in identifying security testing priorities. You will assist in scoping penetration tests and help deep-dive on these engagements. You will investigate emerging security issue, root cause them, and devise mechanisms to prevent them. You will propose a security vision for the business that delivers security that protects our customers. A day in the life In this highly dynamic role, you'll be accountable for deciding where your time investments provide the most value. You will have a blend of proactive and reactive work. Teams will reach out for ideas on how to handle a wide variety of security problems. You can anticipate implementation questions like "What's the right way to handle authentication tokens in service to service communications?" "We need to define security requirements for a confidential new product launch." "We've experienced an incident and need to perform 5 why's analysis to identify and correct the problem that produced the incident." When you're not working on responding to the questions of your builder teams, you will be evaluating overall org performance to identify architectural defects and proposing new security initiatives to correct problems in the org. You will help Amazon maintain a high bar for customer security.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at Amazon.com Services LLC? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect