Share
Key job responsibilities
* Creating, updating, and maintaining threat models for a wide variety of software projects
* Security architecture and design guidance
* Manual and Automated Secure Code Review, primarily in Java, Python and Javascript
* Development of security automation tools
* Adversarial security analysis using innovative tools to augment manual effort
* Security training and outreach for internal development teams
* Independently solve security problems that require novel methods or approaches
* Influence your team’s and partners’ process, priorities, and choices to improve outcomesAbout the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Work/Life Balance
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Mentorship and Career growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
- BS in Computer Science, Information Security, 3+ years of demonstrated experience of comprehensive application security assessments, including both automated and manual assessment.
- Hands on experience in threat modelling, architecture review, manual source code review, attacker exploit techniques, and methods for their remediation.
- Have good understanding of network architecture, enterprise IT systems and cloud such as AWS and programming or Scripting skills (E.g: Java, Python, Perl, Bash, Ruby, PowerShell, etc.) and can explain complex technical risks in simple, clear language that non-technical stakeholders can easily understand and act upon.
These jobs might be a good fit