Product Security Engineer III
Internship Austin (Travis) Design / Civil engineering / Industrial engineering
Job description
DESCRIPTION
Are you experienced with vulnerability management tools and industry compliance standards? If so, then the Amazon Third Party Security team has an exciting opportunity for you. Our third-party security team is looking for Security Engineer with a strong security background, problem-solving abilities, and customer obsession. You help us design new security services and features to support our internal customers’ use of third-party solutions. We are looking for someone who can balance technical risks against business risks and consistently drive for the right results. You must have the passion for engineering solutions to complex security challenges, and recognize and fill gaps in capabilities. The ability to quickly design and build internal-facing tools that enable scaled programmatic automation is core to our organization. You should have a good mix of deep technical knowledge and a demonstrated background in information security. We value broad and deep technical knowledge, specifically in the fields of operating system security, network security, cryptography, software security, malware analysis, forensics, security operations, incident response, and emergent security intelligence.
Job responsibilities include defining customer use cases and requirements, designing and prototyping security solutions, driving security value into software services, educating customers on product features and best practices, and educating stakeholders on best practices and standards. Successful candidates will be strong leaders who are well versed in vulnerability detection and management, vulnerability remediation tools and practices, and compliance standards and government certifications. Additionally, successful candidates will be excellent communicators, have a history of successful collaboration with development teams, and be experienced prototyping security software solutions.
As a security engineer on the team, you will:
· Identify and drive continuous process improvements across security programs and services
· Lead security projects (including security reviews, tool development, and creation of new security practices) with end-to-end ownership
· Evaluate complex business and technical requirements, communicating inherent security risks and solutions to technical and non-technical business owners.
· Conduct security reviews for new products, technologies, and services within targeted 3P SaaS applications
· Apply secure development life-cycle (SDLC) practices including threat modeling and security testing
· Influence decision-makers and stakeholders throughout the organization in multiple teams to achieve a consistently high security bar
· Create security guidance and documentation
· Develop security tools and automation
· Develop and deliver security training and outreach to internal development teams
· Develop and improve metrics that drive desired behavior and security outcomes
PREFERRED QUALIFICATIONS
· MS degree in Computer Science, MIS, Computer Engineering
· Knowledge in security engineering, system and network security, security protocols, cryptography, and application security
· Experience with multiple programming languages (such as Java, C++, Ruby, Python, Perl) for both tool development and code review
· Excellent written and oral communication skills
· Meets/exceeds Amazon’s leadership principles requirements for this role
· Meets/exceeds Amazon’s functional/technical depth and complexity for this role
Desired profile
BASIC QUALIFICATIONS
· Bachelor (undergraduate) degree in a relevant field (Computer Science, Software Engineer, Security, or others) OR an equivalent combination of education, training, and experience
· Minimum of 5 years of professional experience with any combination of at least 3 technical disciplines, including the following: cloud security, network security, application security, mobile security, secure development methodologies, software development and coding, identity management, authentication and authorization, network architecture, system administration, and systems engineering
· 5+ years’ experience in security practices with a focus on vulnerability assessment and management
· 5+ years’ experience in information security and industry or government certifications and compliance
· 3+ years’ experience building automation tools and prototyping security solutions
· 3+ years of experience building or reviewing threat models
· 3+ years of experience conducting security assessments, including penetration testing or red teaming