Security Engineer, Corporate Services Security
Amazon
- Location
- US, WA, Seattle
- Employment
- Full Time
- Work model
- On-Site
- Level
- Mid
- Posted
- 19h ago
Skills
About this role
The Corporate Services Security (CPSS) Finance and Communication Security (FCS) Team is responsible for securing the applications, infrastructure and data developed across Finance & Global Business Services (FGBS) and Communications and Corporate Responsibility (CCR). We partner with builder teams to minimize security risks across their applications while being a business enabler. Our team is responsible for the following: 1.Security consultations and guidance - Get security subject matter expert advice on security best practices and implementation strategies. 2.Application security reviews and threat modeling -Comprehensive security assessments for new features and applications 3.Security architecture decisions - Design reviews and architectural guidance to build security in from the start of the software development lifecycle 4.Issue remediation - Support for addressing security findings, vulnerabilities, and compliance gaps 5.Security backlog management - Prioritization and tracking of security improvements and technical backlog 6.Compliance and security standards questions - Guidance on meeting organizational security policies and industry standards 7.Security tooling and automation - Help with integrating security tools into your development workflows Key job responsibilities A successful candidate will possess demonstrated combination of application security, GenAI Security, technical, and communication skills, as well as the ability to handle a mix of disparate tasks and include projects in addition to managing security review activities. This role will provide career growth opportunities as you gain new security skills in the course of your duties. Perform Design and Security Reviews to determine the level of risk they present to our customers, and then accordingly prioritize their remediation in conjunction with the service team. Participate in efforts to promote security throughout the Company and build good working relationships within the team and with others across Amazon Demonstrate high capacity and tolerance for context switching and interruptions while remaining productive and effective Escalate issues and provide recommendations to senior leadership when issues are not progressing at the correct pace based on impact to ensure we are putting customers first. Explore building and improving our tooling to make your own life easier and share that benefit with all our engineers globally. Contribute to recruiting activities, mentoring and administrative work Create, update, and maintain threat models for a wide variety of software projects Perform Manual and Automated Secure Code Review, primarily in Java, Python and Javascript Develop security automation tools Adversarial security analysis using tools to augment manual effort Provide Security training and outreach for internal development teams Provide Security architecture and design guidance to application development teams Independently solve systemic, complex security problems that require novel methods or approaches Influence your team’s and partners’ process, priorities, and choices by using data to improve security outcomes Provide technical and strategic guidance to senior leaders and stakeholders through effective oral and written communications A day in the life As a Security Engineer, you will collaborate with application development teams to ensure we keep our customers safe while developing novel services using GenAI. In a given day, you might be inspecting an application’s code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service. The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security specialist with one or more areas of deep expertise within application security or software development. They will clearly articulate risks to technical and