Amazon
Posted 2w ago

Manager, Security Engineering, Secure Third Party Tools

Amazon
Arlington, Virginia, United States
$175k-$237k/yrOnsiteFull Time
Responsibilities
  • leading team
  • defining controls
  • conducting reviews
Requirements
  • 5+ years managing security engineering teams
  • 5+ years in software/security roles
  • Bachelor's in CS or related
  • Expertise in threat modeling
  • Security architecture
  • Cryptography, and risk assessment
  • Information security certs preferred

Job description

Description

We're looking for an experienced Security Engineering Manager to join our Secure Third Party Tools team. Our team builds the standards, controls, and expert review processes that ensure external vendors, software providers, and services meet Amazon's security bar before they interact with our data or systems.

In this role, you'll manage a team of Security Engineers who define and maintain the security controls that 3P are assessed against, conduct expert security reviews for complex engagements, and provide continuous feedback that improves the accuracy of our assessment automation. You'll be responsible for both the technical quality of your team's output and the professional growth of your team.

This is a role where security expertise meets people leadership. You'll set direction for your team while partnering closely with Product, Software Engineering and Applied Science, to ensure that security standards are effectively translated into scalable, automated tooling. Your team's work directly determines whether Amazon can move fast with 3P while maintaining the highest security standards.

Key job responsibilities
- Lead a team of Security Engineers who define and enforce Amazon's third-party security controls.

- Set the security vision and strategy for your team's domain—defining which security controls to prioritize, how to evolve them against emerging threats, and how to integrate them into automated assessment systems.

- Partner with Product and Engineering to translate security requirements into tool capabilities, providing subject-matter expertise that shapes product roadmaps and feature priorities.

- Drive the feedback loop between manual expert reviews and automated assessment outputs, continuously improving precision and reducing the need for human intervention.

- Conduct threat modeling, security architecture reviews, and risk assessments for complex or novel third-party integrations.

- Develop and maintain security guidance, runbooks, and documentation for internal teams and third-party vendors.

- Author documents for leadership reviews, communicating security risks, resource needs, and strategic priorities clearly and concisely.

- Build mechanisms for operational excellence—tracking team capacity, review throughput, quality metrics, and backlog health.

About the team
About Amazon Security

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

- 5+ years of managing and developing teams experience
- 5+ years of progressive work within a software security team or related operating environment experience
- Bachelor's degree in Computer Science, Information Security, or a related field
- Knowledge of security of web services, video content protection technologies, cryptography, network security protocols and operating system security
- Experience applying threat modeling or other risk identification techniques or equivalent

Preferred Qualifications

- information security professional certification (SANS GIAC, CISSP etc.)
- Master's degree in Computer Science or a related field
- Knowledge of information security technologies such as security design review, threat modeling, risk analysis, and software testing techniques

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.



USA, VA, Arlington - 175,100.00 - 236,900.00 USD annually

About Amazon

Global online retail and cloud computing technology provider.

Similar jobs

Security Engineering Manager roles near Arlington, Virginia
4d
Save
Mark Applied
Hide
Security Engineering Manager - AI for Security, web and mobile techstack
Bellevue or Menlo Park or Seattle or Washington or United States or New York City
$184k-$257k/yr HybridFull Time
Meta
MetaNASDAQ: META: Develops social networking platforms and virtual reality technologies.
8+ YOE3+ MgmtRequires a computer science bachelor's degree or equivalent security experience, 8+ years in security/software engineering, 3+ years managing security engineering, scripting, and broad security expertise.
PHP, Python, Perl, Ruby
3w
Save
Mark Applied
Hide
Senior Manager, Security Engineering
Reston or Nashville or Seattle
OnsiteFull Time
Oracle
OracleNYSE: ORCL: Provides cloud infrastructure and enterprise software for global businesses.
10+ YOE3+ Mgmt10+ years IT security experience (cloud, endpoint, logging), incident response, threat modeling, cloud security; 3 years people leadership; programming experience with Go/Java/Python/C/C++; information security certifications preferred.
Go, Java, Python, C/C++, AWS, Azure, OCI
7mo
Save
Mark Applied
Hide
Manager, Security Engineering
Leesburg, Virginia, United States
OnsiteFull Time
VB Spine
VB Spine: A healthcare focused on medical devices.
8+ YOE3+ MgmtLead security engineering; develop security architecture; manage vulnerabilities and patching; cloud and on-prem security; mentor teams.
Microsoft Sentinel, Defender XDR, EDR, XDR, SOAR, SIEM, Azure Security, AWS Security
1w
Save
Mark Applied
Hide
Security Risk & Engineering - Tech and Cyber Risk & Compliance -Manager
New York City or Atlanta or Chicago or Washington or Boston or Dallas or San Francisco or Seattle or Houston
$99k-$232k/yr OnsiteFull Time
PwC
PwC: Providing audit, tax, and management consulting services to businesses.
5+ YOEBachelor's degree and 5+ years of experience required. Experience with cybersecurity risk management, compliance frameworks, ISO/IEC 27001, NIST Cybersecurity Framework, risk assessments, and regulatory reporting.
ISO/IEC 27001, NIST Cybersecurity Framework
1mo
Save
Mark Applied
Hide
AI Security & Trust Engineering Manager
Bethesda or Richmond or Cleveland or Raleigh or Philadelphia or Boston or Atlanta or Jacksonville or Houston
$160k-$175k/yr RemoteFull Time
3E
3E: Provides software and data for chemical regulatory compliance management.
6+ YOE2+ MgmtBachelor's degree or equivalent, 6+ years technical engineering experience, 2+ years leading or mentoring engineers, deep knowledge of trust engineering/AI security, stakeholder influence, and strong communication skills.
SOC 2, ISO 27001, ISO 42001