Share
Global Services Security is looking for a Security Engineer to inspect, design, develop, and implement security guidance, mechanisms, and processes to improve the overall security posture of AWS interactions with our internal and external customers. You will build and automate security mechanisms and manual processes that help us inspect, monitor, and alert on the activities and interactions AWS Global Services have when working hand-in-hand with our customers.You will have the combination of troubleshooting, technical, and communication skills, as well as the ability to handle a mix of disparate tasks which may include project and software development work. This role will provide career growth opportunities as you gain new security skills in the course of your duties.
Key job responsibilities
• Security tool automation and development
• Application security reviews
• Secure architecture design
• Threat modeling
• Projects and research work as needed
• Security training and outreach to internal development teams
• Security guidance documentation
• Security metrics delivery and improvements
• Assistance with recruiting activities and administrative work
A day in the life
You will enhance existing automation to improve operational efficiency, building new insights from existing data. Identify, evaluate, and prioritize opportunities for automating mechanisms across diverse landscapes of tools, systems, and architectures. Meet with other teams across Global Services to collaborate on security mechanisms, like partner security, improving reviews of security plans, reducing sales to delivery timelines, and improving scoping for high-risk datatypes. Contribute to security training, best practices documentation, and security policies tailored for internal teams engaging with regulated data. You will implement scalable processes and tooling solutions to facilitate regular audits of security controls, guidance,
and compliance standards.
About the team
Diverse Experiences
AWS values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Mentorship & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life Balance
- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Knowledge of commonly found software security vulnerabilities (like OWASP top 10) and remediation techniques
- 2+ years of programming in one of the following or similar: Python, Typescript, Ruby, Go, Java, .Net, C++. Our code is a mixture of Python, Typescript, shell, and CloudFormation.
- Experience with AWS products and services
- Experience with any combination of the following: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration and network security
- Experience with Security Engineering (building tools) and Assurance methodologies e.g. fuzzing, static and dynamic code analysis
These jobs might be a good fit