Amazon

Security Engineer, AWS Security

Amazon London, England, United Kingdom

Software Development · 10,001+ employees

20 h ago
security Mid (2-5 yrs) Full-time United Kingdom
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Engineer evaluates service architecture and performs deep-dive security assessments to ensure applications meet high security standards. They also conduct threat modeling, coordinate penetration testing, and provide remediation guidance to development teams.

What they look for

Application Security Threat Modeling Penetration Testing AWS Python Security Architecture Vulnerability Assessment Secure Coding Cryptography Identity And Access Management Cloud Security Incident Response Linux Bash Network Security Data Protection

Requirements

Candidates must have a bachelor's degree in a technical field and experience with web protocols, security vulnerabilities, and remediation. Proficiency in at least one programming language and knowledge of application security frameworks are required.

Full description

The AppSec Security Engineer evaluates service design and architecture and performs deep-dive security assessments to ensure applications and services meet a high security bar before launch. This role works alongside senior engineers to identify issues, drive remediation, and validate that security requirements are met.

Key job responsibilities - Security Reviews: Conduct design reviews for new and existing services, evaluating architecture documents and system designs for security risks. - Threat Modelling: Identify attack vectors and security weaknesses in application architectures through structured threat modelling exercises. - Penetration Testing: Coordinate penetration testing to validate security controls and identify exploitable vulnerabilities. - Finding Management: Document, track, and communicate security findings to service teams with clear remediation guidance, and verify fixes are implemented. - Security Guidance: Advise development teams on secure coding practices, authentication/authorization mechanisms, cryptographic implementations, and data protection strategies. - Escalation Support: Identify and escalate high-severity issues through appropriate channels, ensuring timely remediation aligned with launch timelines. - Documentation: Maintain clear documentation of review outcomes, security decisions, and risk assessments. - Tool Improvements: Leverage automated tools to support reviews and improve efficiency.

About the team Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Basic Qualifications: - Experience with web protocols, common security attacks, and remediation (non-internship) - Bachelor's degree or above in Computer Science, Computer Engineering, or related fields - Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent - Experience in any combination of the following: application security frameworks, security code reviews, incident response, secure infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls, threat modeling, cryptography, threat intelligence, or secure software development - Experience with coding/scripting in one or more languages (e.g., Python, C, C++, Java, Ruby, or PowerShell)

Preferred Qualifications: - Experience with AWS services or other cloud offerings - Knowledge of one or more of the following domains: web application development, penetration testing, mobile security, cryptography, public key infrastructure, forensic security, IP security, SSL/TLS, computer viruses and malware, network security, trusted security, trusted execution, threat intelligence, IoT security implications, or authentication - Experience using scripting languages, such as Python, Perl, Linux bash - Experience triaging and developing security alerts and response automation, conducting front-line analysis, and providing escalation support

Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice (https://www.amazon.jobs/en/privacy_page) to know more about how we collect, use and transfer the personal data of our candidates.

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Similar roles