Amazon
Posted 2d ago

Senior Security Engineer, Device Platform Security Team

Amazon
Sunnyvale or Seattle
$178k-$248k/yrOnsiteFull Time
Responsibilities
  • analyzing security
  • developing mitigations
  • promoting awareness
Requirements
  • Bachelor's degree and 5+ years identifying security issues
  • Assessing risks, and developing mitigations. Requires Linux and RTOS knowledge
  • Vulnerability research
  • Network security
  • Cryptography
  • Application security, and C code review
Technical tools mentioned
LinuxCC++RubyPerlPythonBashAndroidBluetoothWiFiZigbeeThread

Job description

Description

Amazon Devices is an inventive research and development organization that designs and engineers high-profile consumer electronics. Starting with the best-selling Kindle family of products, Amazon Devices developed and produced ground-breaking devices like Amazon Echo products, Fire tablets, Fire TV, Astro, Halo, Ring Doorbells, Blink Cameras and more.

The Role
Are you interested in being part of a top-notch security team covering all Amazon devices? If you want to keep customers safe, then we have a job for you! Amazon’s Device Security Platform team is growing and looking for strong leaders.

In this role, you will work in the OS platform Security team for Amazon devices like Echo, FireTV, Fire tablets, Ring and Blink doorbells, cameras, drones, wearables, Kindle readers, and automotive security.


Key job responsibilities
* Help guide the software development lifecycle of devices at Amazon, from security design, threat modeling to code reviews, security testing and fuzzing
* Be responsible for analyzing the security of the platform components of consumer devices
* Propose, research and develop tools and techniques to improve the security posture of devices at scale
* Provide technical security expertise and consultation to device product teams
* Identify security risks and work with product engineers to create mitigations
* Develop new security policies and procedures
* Empower others to improve their security acumen by promoting awareness and developing training materials

About the team
We are responsible for empowering and enabling the organizations of Amazon Devices to develop and build secure products, including responding to public vulnerabilities and reviewing or co-developing security features to protect customers.

Basic Qualifications

- Bachelor's degree
- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
- Knowledge of operating system internals, with emphasis on Linux and common RTOS environments
- Familiarity with system security vulnerability research and remediation techniques and the development of exploit PoCs
- Experience with network security and authentication protocols, cryptography, and application security
- Security code review experience in C

Preferred Qualifications

- Experience applying threat modeling or other risk identification techniques or equivalent
- Knowledge of Android OS internals
- Experience with coding in C/C++, assembly languages and scripting (e.g. , Ruby, Perl, Python, Bash)
- Experience with fundamentals of common wireless connectivity protocols (e.g. Bluetooth, WiFi, Zigbee, Thread)
- Knowledge of hardware security mechanisms, including secure boot and trusted execution environments

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.



USA, CA, Sunnyvale - 183,000.00 - 247,600.00 USD annually
USA, WA, Seattle - 178,400.00 - 226,700.00 USD annually

About Amazon

Global online retail and cloud computing technology provider.

Similar jobs

Security Engineer roles near Sunnyvale, California
3h
Save
Mark Applied
Hide
Security Engineer - Security Risk Management
Menlo Park, California, United States
$154k-$217k/yr OnsiteFull Time
Meta
MetaNASDAQ: META: Develops social networking platforms and virtual reality technologies.
5+ YOEBachelor's degree or equivalent, 5+ years securing enterprise-scale infrastructure, 3–5+ years programming with Python, PHP, Ruby, or similar scripting languages, and experience with security automation, compliance, and cross-functional influence.
Python, PHP, Ruby, Linux, Windows, macOS
5h
Save
Mark Applied
Hide
Staff Security Engineer, Google Distributed Cloud, Federated Security
New York or Kirkland or Seattle or Sunnyvale
$207k-$300k/yr OnsiteFull Time
Google
GoogleNASDAQ: GOOGL: Provides online search, advertising, cloud computing, and consumer electronics.
8+ YOEBachelor's degree or equivalent, 8 years in security assessments, design reviews, threat modeling, security engineering, and coding, plus 3 years of cloud security experience.
CI/CD, Software Development Life Cycle (SDLC), Infrastructure as Code, GPUs, TPUs
6h
Save
Mark Applied
Hide
Security Engineer III
San Jose or Georgia
$209k-$348k/yr HybridFull Time
Veeam
Veeam: Data resilience and security for hybrid cloud environments
5+ YOERequires 5+ years in security engineering, cloud operations, or detection engineering; production Terraform; hands-on Azure and AWS security; detection development; cloud security fundamentals; query and Python automation skills.
Microsoft Azure, AWS, Microsoft Sentinel, Log Analytics, KQL, Defender for Cloud, Entra ID, Key Vault, Azure Policy, Azure Monitor, Event Hubs, CloudTrail, GuardDuty, Security Hub, IAM, Config, CloudWatch, Terraform, GitHub Actions, Azure DevOps, Wiz, ADLS, S3, OCSF, Azure Data Explorer, Azure Functions, Lambda, Python, PowerShell, Bash, Sigma, SQL, Kubernetes, AKS, EKS, SOC 2 Type 2, ISO 27001, FedRAMP, HITRUST, Microsoft LinkedIn Learning, O'Reilly
23h
Save
Mark Applied
Hide
Security Engineer
San Francisco or New York City
$250k-$300k/yr OnsiteFull Time
Town
Town: AI-powered productivity assistant that automates workplace workflows.
Extensive security engineering experience, production coding ability, multi-tenant SaaS security expertise, cloud security knowledge, and experience with authentication, authorization, secrets, encryption, and threat modeling.
AWS, GCP, Google, Slack, CRM
1d
Save
Mark Applied
Hide
Security Engineer
Mountain View, California, United States
$120k-$150k/yr HybridFull Time
DataVisor
DataVisor: AI-powered fraud and financial crime detection for enterprises.
5+ YOERequires 5+ years of security engineering experience, including 2+ years in AI/ML security, AWS and GCP expertise, CSPM, AI/LLM security, threat modeling, cloud security, networking, and compliance knowledge.
AWS, GCP, IAM, EC2, S3, VPC, Compute Engine, Cloud Storage, CSPM, Claude, Amazon Bedrock, MCP, OWASP, OAuth, NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, SIEM, SOAR, SOC 2, PCI DSS, ISO 27001, IPv4/IPv6, TCP/UDP, DHCP, HTTPS, FTP
1d
Save
Mark Applied
Hide
Lead Security Engineering - Terminals
Mountain View or San Diego
OnsiteFull Time
Logos Space
Logos Space: Develops secure LEO satellite networks for enterprise connectivity.
7+ YOEBachelor's degree in a related field, 7–10 years of security engineering experience, embedded hardware security expertise, and C/C++/Rust/Python programming skills. Knowledge of FIPS, Common Criteria, CSfC and secure provisioning required.
C, C++, Rust, Python, FIPS, Common Criteria, CSfC, 4G, 5G, PDCP, IPSEC, MACSEC, SDR
1d
Save
Mark Applied
Hide
Security Engineer
San Francisco, California, United States
$134k-$180k/yr RemoteFull Time
Check Point Software Technologies
Check Point Software TechnologiesNASDAQ: CHKP: Provides network, cloud, and mobile cybersecurity solutions.
4+ YOERequires 4–8 years of engineering and pre-sales experience, strong analytical, problem-solving, communication, and presentation skills, network knowledge, and ability to design end-to-end security solutions.
RFI, RFP, CCNP, CISSP, CCSA, CCSE
3d
Save
Mark Applied
Hide
Security Engineer
San Mateo, California, United States
$155k-$190k/yr HybridFull Time
Cala Health
Cala Health: Develops non-invasive wearable neuromodulation therapies for chronic movement disorders.
3+ YOERequires 3+ years in security engineering, application security, or incident response; security tooling, CI/CD, cloud security, Python and Bash experience. U.S. work authorization or eligible sponsorship required.
Software Composition Analysis (SCA), Common Vulnerabilities and Exposures (CVEs), CI/CD, Snyk, Dependabot, Burp Suite, Splunk, Datadog, OWASP Top 10, CWE, Jenkins, GitHub Actions, GitLab CI, Python, Shell, Bash, Go, JavaScript, TypeScript, Rust, Docker, AWS, GCP, AWS Inspector, GuardDuty, Vanta, Checkov, TFLint, BugCroud, SIEM, EDR, IAM