Senior Security Engineer, Device Platform Security Team
Amazon Sunnyvale, California, United States · $178K–$248K/yr
Software Development · 10,001+ employees
About the role
The role involves guiding the software development lifecycle for Amazon devices through threat modeling, security testing, and code reviews. You will also research and develop security tools while providing technical expertise to product teams to mitigate security risks.
What they look for
Requirements
Candidates must have a bachelor's degree and at least 5 years of experience in identifying security risks and developing mitigation plans. Proficiency in operating system internals, specifically Linux and RTOS, along with experience in C and network security protocols is required.
Benefits
Full description
Amazon Devices is an inventive research and development organization that designs and engineers high-profile consumer electronics. Starting with the best-selling Kindle family of products, Amazon Devices developed and produced ground-breaking devices like Amazon Echo products, Fire tablets, Fire TV, Astro, Halo, Ring Doorbells, Blink Cameras and more.
The Role Are you interested in being part of a top-notch security team covering all Amazon devices? If you want to keep customers safe, then we have a job for you! Amazon’s Device Security Platform team is growing and looking for strong leaders.
In this role, you will work in the OS platform Security team for Amazon devices like Echo, FireTV, Fire tablets, Ring and Blink doorbells, cameras, drones, wearables, Kindle readers, and automotive security.
Key job responsibilities * Help guide the software development lifecycle of devices at Amazon, from security design, threat modeling to code reviews, security testing and fuzzing * Be responsible for analyzing the security of the platform components of consumer devices * Propose, research and develop tools and techniques to improve the security posture of devices at scale * Provide technical security expertise and consultation to device product teams * Identify security risks and work with product engineers to create mitigations * Develop new security policies and procedures * Empower others to improve their security acumen by promoting awareness and developing training materials
About the team We are responsible for empowering and enabling the organizations of Amazon Devices to develop and build secure products, including responding to public vulnerabilities and reviewing or co-developing security features to protect customers.
Basic Qualifications: - Bachelor's degree - 5+ years of work in identifying security issues and risks, and developing mitigation plans experience - Knowledge of operating system internals, with emphasis on Linux and common RTOS environments - Familiarity with system security vulnerability research and remediation techniques and the development of exploit PoCs - Experience with network security and authentication protocols, cryptography, and application security - Security code review experience in C
Preferred Qualifications: - Experience applying threat modeling or other risk identification techniques or equivalent - Knowledge of Android OS internals - Experience with coding in C/C++, assembly languages and scripting (e.g. , Ruby, Perl, Python, Bash) - Experience with fundamentals of common wireless connectivity protocols (e.g. Bluetooth, WiFi, Zigbee, Thread) - Knowledge of hardware security mechanisms, including secure boot and trusted execution environments
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, Sunnyvale - 183,000.00 - 247,600.00 USD annually USA, WA, Seattle - 178,400.00 - 226,700.00 USD annually
Similar roles
-
Lead Strategic Services Consultant (Application Security)
Black Duck Software, Inc. Burlington, Massachusetts, United States · $124K–$185K/yr
-
Cybersecurity & Governance Engineer
CALIBRE Systems, Inc. Washington, District of Columbia, United States · $125K–$145K/yr
-
Cybersecurity Project Manager
Sancorp Consulting LLC Arlington, Virginia, United States · $110K–$170K/yr
-
Lead Application Security/Information Security Engineer
VBest Software Inc Charlotte, North Carolina, United States · $156K–$166K/yr
-
Cybersecurity Specialist (RMF/IL-6) - ACWS
Data Systems Analysts, Inc. Fort Dix, New Jersey, United States · $160K–$170K/yr
-
College Co-Op Cybersecurity
Synovus Columbus, Georgia, United States