Amazon
Posted 1w ago

Manager, Security Engineering, Corporate Services Security (CPSS)

Amazon
Arlington, Virginia, United States
$175k-$237k/yrOnsiteFull Time
Responsibilities
  • leading engineers
  • assessing risks
  • mentoring teams
Requirements
  • Bachelor's degree in computer science
  • Information security, or related field
  • 5+ years managing teams and 5+ years in software security. Requires threat modeling
  • Security architecture
  • Risk analysis, and team development experience
Technical tools mentioned
AI

Job description

Description

Lead a team of Security Engineers protecting Amazon's HR and and Legal systems.This is an inherently cross-functional role working across business and technical domains; it requires a strong ability to influence others, partner effectively, and know where to prioritize for strategic impact.

The Corporate Services Security (CPSS) Security for Employee and Legal Systems (SEALS) team protects Amazon's enterprise HR and Legal applications, ensuring they meet the high security standards. You'll elevate our security strategy through broad leadership, cross-functional collaboration, and delivery of high-quality results that push us to continuously improve for our customers. You will set the strategic direction for the entire software development lifecycle while developing and taking your team to the next level. Ideal candidates will have an established background as an application/product security engineering manager with experience spanning threat modeling, architecture reviews, scanning and assessments, and remediation/mitigation approaches. You will understand AI application security threats and embrace AI to scale delivery. You will combine technical leadership with managerial depth, with a proven track record of aligning security with the strategies of the businesses you support and collaborating effectively with builder teams throughout the phases of the SDLC.

Key job responsibilities
- Assess security risks, establish mitigation strategies, and develop technical roadmaps. Partner with PXT and Legal builder teams to understand requirements and integrate security seamlessly into their work. Align with key business stakeholders to ensure that objectives are focused on areas of key concern and change; provide technical oversight for all phases of the software development lifecycle.
- Partner with peers, partners, customers and stakeholders to prioritize and drive implementation of security-related technical and process controls to remediate risks identified during engagements. Communicate updates to senior security and business leadership on a regular cadence.
- Hire, develop, and mentor security engineers, and manage the day-to-day activities of the team. Create the organization of the future by driving a culture of inclusion where team members are encouraged to take risks and push limits to challenge organizational security assumptions.
- Drive security initiative planning, outcomes and improvements: Participate in wider leadership across CPSS and Amazon Security functions. Establish roadmap/strategic direction for the team
- Implement success metrics, reporting, and processes that measure program outcomes and effectiveness.


A day in the life
- Owning and driving large-scale programs and campaigns for awareness of policy or adoption of new security mechanisms
- Using automation to scale security mechanisms across the business and minimize friction around security controls
- Conducting threat modeling sessions, architecture reviews, and security assessments with PXT and Legal builder teams throughout the SSDLC
- Diving deep into the control landscape and operations of corporate services with builder teams
- Owning security escalation action items and informing Senior Leadership on short, medium, and long-term recommendations to triage escalations and mitigate risks
- Bar raising deliverables and mentoring team members and builders


About the team
SEALS (Security for Legal and Employee Services) supports Amazon's People eXperience & Technology (PXT) and Legal teams. We are the dedicated Business Security team responsible for protecting the critical systems that power Amazon's workforce and legal operations. Our mission is to ensure these enterprise business applications meet the high security standards required to maintain and enhance customer trust.

Basic Qualifications

- 5+ years of managing and developing teams experience
- 5+ years of progressive work within a software security team or related operating environment experience
- Bachelor's degree in Computer Science, Information Security, or a related field
- Knowledge of security of web services, video content protection technologies, cryptography, network security protocols and operating system security
- Experience in managing and developing teams
- Experience in progressive work within a software security team or related operating environment
- Experience applying threat modeling or other risk identification techniques or equivalent

Preferred Qualifications

- information security professional certification (SANS GIAC, CISSP etc.)
- Master's degree in Computer Science or a related field
- Knowledge of information security technologies such as security design review, threat modeling, risk analysis, and software testing techniques

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.



USA, VA, Arlington - 175,100.00 - 236,900.00 USD annually

About Amazon

Global online retail and cloud computing technology provider.

Similar jobs

Security Engineering Manager roles near Arlington, Virginia
6d
Save
Mark Applied
Hide
Security Engineering Manager - AI for Security, web and mobile techstack
Bellevue or Menlo Park or Seattle or Washington or United States or New York City
$184k-$257k/yr HybridFull Time
Meta
MetaNASDAQ: META: Develops social networking platforms and virtual reality technologies.
8+ YOE3+ MgmtRequires a computer science bachelor's degree or equivalent security experience, 8+ years in security/software engineering, 3+ years managing security engineering, scripting, and broad security expertise.
PHP, Python, Perl, Ruby
3w
Save
Mark Applied
Hide
Senior Manager, Security Engineering
Reston or Nashville or Seattle
OnsiteFull Time
Oracle
OracleNYSE: ORCL: Provides cloud infrastructure and enterprise software for global businesses.
10+ YOE3+ Mgmt10+ years IT security experience (cloud, endpoint, logging), incident response, threat modeling, cloud security; 3 years people leadership; programming experience with Go/Java/Python/C/C++; information security certifications preferred.
Go, Java, Python, C/C++, AWS, Azure, OCI
7mo
Save
Mark Applied
Hide
Manager, Security Engineering
Leesburg, Virginia, United States
OnsiteFull Time
VB Spine
VB Spine: A healthcare focused on medical devices.
8+ YOE3+ MgmtLead security engineering; develop security architecture; manage vulnerabilities and patching; cloud and on-prem security; mentor teams.
Microsoft Sentinel, Defender XDR, EDR, XDR, SOAR, SIEM, Azure Security, AWS Security
1w
Save
Mark Applied
Hide
Security Risk & Engineering - Tech and Cyber Risk & Compliance -Manager
New York City or Atlanta or Chicago or Washington or Boston or Dallas or San Francisco or Seattle or Houston
$99k-$232k/yr OnsiteFull Time
PwC
PwC: Providing audit, tax, and management consulting services to businesses.
5+ YOEBachelor's degree and 5+ years of experience required. Experience with cybersecurity risk management, compliance frameworks, ISO/IEC 27001, NIST Cybersecurity Framework, risk assessments, and regulatory reporting.
ISO/IEC 27001, NIST Cybersecurity Framework
1mo
Save
Mark Applied
Hide
AI Security & Trust Engineering Manager
Bethesda or Richmond or Cleveland or Raleigh or Philadelphia or Boston or Atlanta or Jacksonville or Houston
$160k-$175k/yr RemoteFull Time
3E
3E: Provides software and data for chemical regulatory compliance management.
6+ YOE2+ MgmtBachelor's degree or equivalent, 6+ years technical engineering experience, 2+ years leading or mentoring engineers, deep knowledge of trust engineering/AI security, stakeholder influence, and strong communication skills.
SOC 2, ISO 27001, ISO 42001