Amazon

Security Engineer II, AppRank

Amazon Austin, Texas, United States · $159K–$202K/yr

Software Development · 10,001+ employees

19 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Engineer will design and build scalable solutions to assess application criticality and identify systemic security vulnerabilities across business units. They will collaborate with engineering teams to implement preventative security controls and integrate security insights into developer pipelines.

What they look for

Python Ruby Go Swift Java C++ Application Security Threat Modeling Secure Code Review AWS Cloud Security Penetration Testing Identity And Access Controls Incident Response Automation System Architecture

Requirements

Candidates must have at least 3 years of programming experience in object-oriented languages and 4 years of experience in application security domains. A bachelor's degree in a technical field or equivalent work experience is required.

Benefits

Health Insurance Dental Insurance Vision Insurance Prescription Insurance Basic Life & AD&D Insurance Supplemental Life Plans Employee Assistance Program Mental Health Support Medical Advice Line Flexible Spending Accounts Adoption And Surrogacy Reimbursement 401(k) Matching Paid Time Off Parental Leave Restricted Stock Units Sign-on Payments

Full description

In Amazon Stores, we develop and operate some of the most diverse and high-scale technologies in the world — from Amazon.com’s global retail platform to advanced machine learning systems and next-generation retail experiences. With the scale and innovation we drive comes the responsibility to build secure systems from the ground up.

We are seeking a Security Engineer to join the AppSec organization and support Application Ranking AppRank (application criticality measurement) — a critical initiative to identify Amazon's most critical applications and criteria. In this role, you will leverage your application architecture excellence to engineer scalable, innovative solutions to assess application criticality criteria for the identification of systemic patterns across business units. Your work will directly impact the security posture of Amazon's most strategic lines of business.

You will collaborate closely with software engineering teams, product managers, and security leadership to ensure the most critical applications are identified early in the software development lifecycle at scale.

The ideal candidate blends strong technical execution with security intuition, and thrives in environments where they can influence, automate, and scale security impact. You should be comfortable translating complex application architecture into actionable insights and driving adoption of security best practices across a large and distributed engineering organization.

At Amazon, we invest in our people and empower our teams to focus on high-leverage work over reactive tasks. Join us to work on some of the most innovative and impactful security challenges in the industry—and help keep our customers safe by preventing security issues before they happen.

Key job responsibilities Engineer AI-driven solutions to assess and classify security findings across business units

Identify root causes of recurring vulnerabilities and develop systemic remediation strategies

Design and build internal tools to analyze patterns in security findings and prevent recurrence

Collaborate with application teams to implement preventative security controls earlier in the development lifecycle (Shift-Left)

Develop automated workflows to integrate security insights into developer pipelines

Perform targeted code reviews and static/dynamic analysis to validate findings and guide mitigations

Contribute to the creation of security dashboards and metrics for visibility into finding trends and remediation velocity

Partner with security leadership and engineering stakeholders to define and prioritize high-impact prevention efforts

Investigate and eradicate classes of vulnerabilities through scalable solutions

Guide teams through remediations by providing technical mentorship and secure design best practices

Maintain deep awareness of emerging threats, and proactively adapt tooling and processes to address them

A day in the life You split your time between building, investigating, and advising. Some mornings you're deep in the risk-prioritization engine; refining how it classifies and scores risk so application reviews are focused on what actually matters. Other days you may be fielding questions, helping teams understand their risk posture and working through disagreements with technical depth.

You collaborate as much as you code; pairing with application teams to help understand and resolve risk for their applications at scale.

About the team Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security? At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications: - 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience - 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience - Knowledge of industry-based security vulnerabilities and remediation techniques - Experience in scripting, programming, and security code reviewing in a common programming language (non-internship) - Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience) - 4+ years of any combination of the following: application security frameworks, identity and access controls, incident response, mobile security, cloud computing and security, AI security, threat intelligence, and penetration testing experience - Knowledge of one or more of the following domains: access-control system and methodology, network security, application- and system-development security, security architecture and models, cryptography, and operations security - Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or equivalent work experience

Preferred Qualifications: - Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing - Experience with AWS products and services - Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, TX, Austin - 159,300.00 - 202,400.00 USD annually

Similar roles