Amazon
Posted 1w ago

Security Engineer II, US Amazon Dedicated Cloud Security

Amazon
Jessup, Maryland, United States
OnsiteFull Time
Responsibilities
  • identifying vulnerabilities
  • testing security
  • developing tools
Requirements
  • Requires a bachelor's degree or listed security credential
  • Active US TS/SCI clearance with polygraph, and US citizenship. Preferred qualifications include OSCP and GXPN or higher
Technical tools mentioned
AWS

Job description

Description

AWS Security is looking for a Red Team Security Engineer to help ensure that our systems and processes are secured against the latest threats. You will be on a team responsible for conducting offensive campaigns, emergent threat testing, creating/maintaining automated threat emulation solutions, and helping security and service teams add offensive insight to their development, deployment, monitoring, and response processes. Offensive security at scale is a unique challenge - AWS possesses both scale of systems and scale of staff and processes. This position will provide you with a challenging opportunity.

A Security Engineer at Amazon is expected to be strong in multiple domains. This is a leadership role within the AWS IT Security team and will be sought out for advice on technical and business issues. Efficient time management skills are required along with the ability to deliver results in the face of uncertainty. A Security Engineer II will proactively share knowledge across the Amazon community and will be a key company resource in one or more of the core areas of security. They will lead security reviews of large Amazon projects while setting standards and defining best practices for the AWS IT Security team.

Engineers in this role must show exemplary judgment in making technical trade-offs between short versus long term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. Conflicts should be addressed by listening, finding the best way forward and persuading one’s colleagues. Successful engineers in this role will regularly analyze their own performance with a critical eye. A broad understanding of the AWS business and its interconnections is required. This position will also provide training, advice, and mentorship to other engineers throughout AWS.

This role will be expected to provide thought leadership for the organization as you invent and innovate in the course of your duties.

This position requires that the candidate selected be a US Citizen and must currently possess and maintain an active TS/SCI security clearance with polygraph.


Key job responsibilities
* Vulnerability Identification and Tracking
* Offensive security testing & vulnerability research
* Emergent threat testing
* Creating/maintaining automated threat emulation solutions
* Recommendation of findings and threat mitigations
* Produce high quality red team reports
* Projects and research work as needed
* Security training and outreach to internal development teams
* Security guidance documentation
* Security tool development
* Security metrics delivery and improvements
* Assistance with recruiting activities

About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

- Bachelor's degree, or CCSP (Certified Cloud Security Professional) or CEH (Certified Ethical Hacker) or CFR (CyberSec First Responder) or Cloud+ or CySA+ (CompTIA Cybersecurity Analyst) or GCED (GIAC Certified Enterprise Defender) or GICSP (Global Industrial Cyber Security Professional) or PenTest+
- Current, active US Government Security Clearance of TS/SCI with Polygraph

Preferred Qualifications

- Offensive Security Certified Professional (OSCP) equivalent, or higer
- GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) equivalent, or higher

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

About Amazon

Global online retail and cloud computing technology provider.

Similar jobs

Security Engineer roles near Jessup, Maryland
7h
Save
Mark Applied
Hide
Senior Security Engineer - Splunk
National Harbor or Washington
$140k-$155k/yr HybridFull Time
UltraViolet Cyber
UltraViolet Cyber: Provider of unified offensive and defensive managed cybersecurity services.
7+ YOEBachelor's degree, 7+ years of security engineering experience, 3+ years of advanced Splunk implementation, Splunk certification, federal security controls expertise, and U.S. citizenship required.
Splunk, Splunk Enterprise Security, Cribl, SPL, FISMA, RMF, NIST SP 800-53, CISA, CDM
22h
Save
Mark Applied
Hide
Senior Engineer
Washington, District of Columbia, United States
$115k-$140k/yr OnsiteFull Time
The Atlantic
The Atlantic: Publishes a magazine and digital journalism on politics and culture.
5+ YOERequires 5+ years of software engineering experience with security engineering, backend programming, DevOps, secure software design, IAM, WAFs, data access controls, and security incident ownership.
CI/CD, AWS, GCP, Azure, Terraform, Datadog, Sentry, IAM, WAFs, LLM
1d
Save
Mark Applied
Hide
Staff Security Engineer
Tysons, Virginia, United States
$168k-$181k/yr HybridFull Time
Alarm.com
Alarm.comNasdaq: ALRM: Provides cloud-based smart home security and automation solutions.
10+ YOE10+ years of information security experience focused on offensive security, penetration testing, or vulnerability research; IoT, embedded systems, firmware, reverse engineering, and security testing expertise required. Degree preferred.
oscilloscopes, logic analyzer, UART, I2C, SPI, JTAG, IDA Pro, Ghidra, Binary Ninja, ARM, x86, RISC-V, Linux
2d
Save
Mark Applied
Hide
Sovereign Cloud Security Engineer Expert
Reston, Virginia, United States
$176k-$374k/yr HybridFull Time
SAP
SAPFrankfurt Stock Exchange: SAP: Sells enterprise resource planning and business management software solutions.
7+ YOEBachelor's or master's degree in computer science, information technology, engineering, or equivalent experience; 7+ years software development; cloud security, infrastructure, Terraform, Ansible, CI/CD, Git, Kubernetes, AWS, and Azure experience.
Terraform, Ansible, CI/CD, GIT, Kubernetes, AWS, Azure, GCP, NIST, ISO, Open Source, ERP
3d
Save
Mark Applied
Hide
Senior Security Engineer, National Security
Maryland or Fort Meade
$174k-$252k/yr OnsiteFull Time
Google
GoogleNASDAQ: GOOGL: Provides online search, advertising, cloud computing, and consumer electronics.
5+ YOEBachelor's degree or equivalent, 5 years in security engineering and assessments, 5 years of coding, active Top Secret/SCI clearance with current polygraph, and US citizenship.
Mandiant, Continuous Integration (CI), Continuous Deployment (CD), Security Information and Event Management (SIEM), Intrusion Detection System (IDS), Intrusion Prevention System (IPS), Software Development Life Cycle (SDLC), LLMs
3d
Save
Mark Applied
Hide
Security Engineer 
Bethesda, Maryland, United States
$100k-$120k/yr OnsiteFull Time
Chickasaw Nation Industries
Chickasaw Nation Industries: Provides federal contracting, engineering, and technology services.
4+ YOEBachelor's degree and 4+ years supporting enterprise endpoint management. Requires Public Trust eligibility, cybersecurity and endpoint security expertise, Intune, MECM, security baselines, Defender, PowerShell, and federal cybersecurity knowledge.
Microsoft Intune, Microsoft Endpoint Configuration Manager, MECM, Jamf Pro, CIS, Microsoft Security Baselines, Microsoft Defender for Endpoint, BitLocker, Windows Firewall, PowerShell, Entra ID, Conditional Access, RBAC, NIST 800-53, Zero Trust Architecture, Azure Virtual Desktop, Microsoft Intune Administrator Associate, Microsoft Security Administrator, Autopilot, Active Directory Group Policy, FileVault, Credential Guard, Application Control
1w
Save
Mark Applied
Hide
Senior Security Engineer
Rockville or Washington or Tysons or Colorado or Florida or Texas or Illinois or Pennsylvania or Massachusetts or New York or New Jersey
HybridFull Time
FINRA
FINRA: Regulates brokerage firms and exchange markets in the United States.
10+ YOE5+ MgmtBachelor's degree and 10 years in securities or financial services, 5 years of supervision, project management, regulatory knowledge, analytics platforms, and excellent communication skills.
Cribl Stream, Splunk, AWS, Azure, GCP, SQS, SNS, Amazon S3, Azure Event Hubs, GCP Pub/Sub, Splunk Edge Processor, SPL2, Python, Appgate SDP, Terraform, Ansible, CI/CD, Kubernetes, Power BI, Dataiku
1w
Save
Mark Applied
Hide
Security Engineer
Linthicum, Maryland, United States
$100k-$200k/yr OnsiteFull Time
Applied Network Solutions: Providing cybersecurity and network engineering services for government agencies.
6+ YOERequires 6+ years of information assurance experience, TS/SCI with polygraph, high school diploma or GED, security architecture, cloud security, STIG, data governance, and stakeholder engagement knowledge.
AWS, Azure, RMF, NIST 800-53, STIGs