This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

Amazon
Posted 1mo ago

Security Engineer, Infrastructure Application Security

Amazon
Herndon, Virginia, United States
OnsiteFull Time
Responsibilities
  • conducting reviews
  • performing reviews
  • building automation
Requirements
  • Bachelor's in engineering/CS
  • Knowledge of system vulnerabilities and remediation
  • Experience with web protocols and threat modeling
  • Coding/scripting experience
  • Penetration testing knowledge
Technical tools mentioned
AWSPythonPerlBashPowerShellHTTPDNSTCP/IP

Job description

Description

AWS Security protects the cloud computing environment that millions of customers rely on every day. Our infrastructure security team works directly with the engineers who design, build, and operate AWS data center and infrastructure services, helping them ship securely from the start.

We're looking for a Security Engineer to join our team and provide hands-on security engineering support to infrastructure builders across AWS. You will review architectures, identify security risks, guide teams toward secure designs, and help build tooling that scales security across a broad portfolio of services. You'll work across a range of technologies: networking, hardware lifecycle systems, procurement systems, data center automation, and cloud infrastructure services.

This is a role where you'll grow fast. You will work alongside experienced security engineers who will help you develop depth in threat modeling, secure design review, and security automation. You'll gain exposure to systems operating at massive scale, and you'll build the judgment to prioritize what matters most when everything looks urgent.

We're looking for someone who communicates clearly, asks good questions, digs into problems with persistence, and brings genuine curiosity about how systems fail.

Key job responsibilities
As a Security Engineer supporting infrastructure teams, you will:
- Conduct security design reviews and threat modeling for infrastructure services, identifying risks and providing clear remediation guidance to partner teams
- Perform manual and automated secure code review across infrastructure codebases
- Provide security architecture and design guidance to builders at the ideation and implementation stages
- Develop and maintain security automation tools that scale review processes across the infrastructure portfolio
- Document findings, track remediation progress, and verify fixes with partner teams
- Deliver security training and outreach to internal infrastructure development teams
- Identify and escalate high-severity security issues through appropriate channels, aligned to launch timelines

A day in the life
You'll collaborate with infrastructure engineering teams to help them build secure services from the start. On any given day, you might be threat modeling a new architecture, reviewing code for security issues, building automation to scale security practices, or guiding a partner team through a secure design decision. Senior engineers on your team will help you develop depth in application security and sharpen your ability to communicate risk clearly. Over time, you'll own relationships with partner teams and become their trusted security resource.

About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

- Bachelor's degree in Engineering, Computer Science, or a related field
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
- Experience with web protocols, common security attacks, and remediation (non-internship)
- Experience solving basic problems by writing code or scripts with some assistance
- Experience applying threat modeling or other risk identification techniques or equivalent

Preferred Qualifications

- Experience with AWS services or other cloud offerings
- Experience in one or more of the following: application security frameworks, security code reviews, incident response, security infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls
- Experience scripting with Python, Perl, Bash or PowerShell
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

About Amazon

Global online retail and cloud computing technology provider.

Similar jobs

Security Engineer roles near Herndon, Virginia
4h
Save
Mark Applied
Hide
Staff Security Engineer
Tysons, Virginia, United States
$168k-$181k/yr HybridFull Time
Alarm.com
Alarm.comNasdaq: ALRM: Provides cloud-based smart home security and automation solutions.
10+ YOE10+ years of information security experience focused on offensive security, penetration testing, or vulnerability research; IoT, embedded systems, firmware, reverse engineering, and security testing expertise required. Degree preferred.
oscilloscopes, logic analyzer, UART, I2C, SPI, JTAG, IDA Pro, Ghidra, Binary Ninja, ARM, x86, RISC-V, Linux
1d
Save
Mark Applied
Hide
Sovereign Cloud Security Engineer Expert
Reston, Virginia, United States
$176k-$374k/yr HybridFull Time
SAP
SAPFrankfurt Stock Exchange: SAP: Sells enterprise resource planning and business management software solutions.
7+ YOEBachelor's or master's degree in computer science, information technology, engineering, or equivalent experience; 7+ years software development; cloud security, infrastructure, Terraform, Ansible, CI/CD, Git, Kubernetes, AWS, and Azure experience.
Terraform, Ansible, CI/CD, GIT, Kubernetes, AWS, Azure, GCP, NIST, ISO, Open Source, ERP
2d
Save
Mark Applied
Hide
Senior Security Engineer, National Security
Maryland or Fort Meade
$174k-$252k/yr OnsiteFull Time
Google
GoogleNASDAQ: GOOGL: Provides online search, advertising, cloud computing, and consumer electronics.
5+ YOEBachelor's degree or equivalent, 5 years in security engineering and assessments, 5 years of coding, active Top Secret/SCI clearance with current polygraph, and US citizenship.
Mandiant, Continuous Integration (CI), Continuous Deployment (CD), Security Information and Event Management (SIEM), Intrusion Detection System (IDS), Intrusion Prevention System (IPS), Software Development Life Cycle (SDLC), LLMs
2d
Save
Mark Applied
Hide
Security Engineer 
Bethesda, Maryland, United States
$100k-$120k/yr OnsiteFull Time
Chickasaw Nation Industries
Chickasaw Nation Industries: Provides federal contracting, engineering, and technology services.
4+ YOEBachelor's degree and 4+ years supporting enterprise endpoint management. Requires Public Trust eligibility, cybersecurity and endpoint security expertise, Intune, MECM, security baselines, Defender, PowerShell, and federal cybersecurity knowledge.
Microsoft Intune, Microsoft Endpoint Configuration Manager, MECM, Jamf Pro, CIS, Microsoft Security Baselines, Microsoft Defender for Endpoint, BitLocker, Windows Firewall, PowerShell, Entra ID, Conditional Access, RBAC, NIST 800-53, Zero Trust Architecture, Azure Virtual Desktop, Microsoft Intune Administrator Associate, Microsoft Security Administrator, Autopilot, Active Directory Group Policy, FileVault, Credential Guard, Application Control
6d
Save
Mark Applied
Hide
Senior Security Engineer
Rockville or Washington or Tysons or Colorado or Florida or Texas or Illinois or Pennsylvania or Massachusetts or New York or New Jersey
HybridFull Time
FINRA
FINRA: Regulates brokerage firms and exchange markets in the United States.
10+ YOE5+ MgmtBachelor's degree and 10 years in securities or financial services, 5 years of supervision, project management, regulatory knowledge, analytics platforms, and excellent communication skills.
Cribl Stream, Splunk, AWS, Azure, GCP, SQS, SNS, Amazon S3, Azure Event Hubs, GCP Pub/Sub, Splunk Edge Processor, SPL2, Python, Appgate SDP, Terraform, Ansible, CI/CD, Kubernetes, Power BI, Dataiku
1w
Save
Mark Applied
Hide
Security Engineer (Active Top Secret Clearance)
Herndon or Virginia or United States or India
$90k-$120k/yr HybridFull Time
UltraViolet Cyber
UltraViolet Cyber: Provider of unified offensive and defensive managed cybersecurity services.
3+ YOEThree years of security-focused IT engineering and network security operations experience; Linux administration, Ansible, Splunk, VMware, high school diploma, certification, US citizenship, and active Top Secret clearance required.
Ansible, Splunk, VMware, Linux, Red Hat Enterprise Linux, Windows, OS X, Microsoft, Cisco, SELinux, PKI
1w
Save
Mark Applied
Hide
Security Engineer
Linthicum, Maryland, United States
$100k-$200k/yr OnsiteFull Time
Applied Network Solutions: Providing cybersecurity and network engineering services for government agencies.
6+ YOERequires 6+ years of information assurance experience, TS/SCI with polygraph, high school diploma or GED, security architecture, cloud security, STIG, data governance, and stakeholder engagement knowledge.
AWS, Azure, RMF, NIST 800-53, STIGs
1w
Save
Mark Applied
Hide
Principal Security Engineer
Reston, Virginia, United States
$200k-$269k/yr HybridFull Time
Fannie Mae
Fannie MaeOTCQB: FNMA: Providing liquidity and stability to the U.S. housing market.
8+ YOEBachelor's degree and 8+ years in cybersecurity or related engineering. Requires multi-cloud security expertise across AWS, Google Cloud, and Microsoft Azure, infrastructure security, automation, application security, AI security, and cross-functional leadership.
AWS, Google Cloud, Microsoft Azure, Terraform, CloudFormation, Bicep, ARM templates, Python, Go, Java, JavaScript, TypeScript, C#, PowerShell, Bash, Ruby, SIEM, EDR, CSPM, CWPP, CIEM, DSPM, Kubernetes, NIST Cybersecurity Framework, NIST 800-53, CIS Benchmarks, ISO 27001, SOC 2, PCI DSS, OWASP, MITRE ATT&CK, MITRE ATLAS
This job has expired