Amazon
Posted 5mo ago

Sr. Security Engineer, Stores Application Security

Amazon
Bengaluru, Karnataka, India
OnsiteFull Time
Responsibilities
  • threat modeling
  • secure code review
  • security automation
Requirements
  • 5+ years of security experience
  • Mentor/tech lead
  • BS in CS or Information Security
  • Strong threat modeling
  • Architecture review, and secure SDLC knowledge
Technical tools mentioned
JavaPythonJavaScriptAWS

Job description

Description

In Amazon Stores, we ship some of the widest arrays of technology found at any company. From amazon.com to world class machine learning pipelines, from innovative digital healthcare to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.

As an AppSec engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services. In a given day, you might be inspecting an application’s code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service alongside its software developers.

The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security generalist with one or more areas of deep expertise. In their communication, they will clearly articulate risks to technical and non-technical audiences alike. Interpersonally, successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions.

Our organization prizes its employees, and we show it through investing in work-life harmony. We have dedicated resources that consistently innovate in reducing on-call time and ensuring the team spend their time on the highest-value tasks. Join the stores AppSec organization to work hard, have fun, and make history!

Our team puts a high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren’t focused on how many hours you spend at work or online. Instead, we’re happy to offer a flexible schedule so you can have a more productive and well-balanced life—both in and outside of work.


Key job responsibilities
- Creating, updating, and maintaining threat models for a wide variety of software projects
- Security architecture and design guidance
- Manual and Automated Secure Code Review, primarily in Java, Python and Javascript
- Development of security automation tools
- First party application security research
- Adversarial security analysis using innovative tools to augment manual effort
- Security training and outreach for internal development teams
- Independently solve security problems that require novel methods or approaches
- Influence your team’s and partners’ process, priorities, and choices to improve outcomes
- First party application security research

About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Mentorship and Career growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

#Joinstoresappsec

Basic Qualifications

- 5+ years of work in identifying security issues and risks, and developing mitigation plans experience
- Experience working in identifying security issues and risks, and developing mitigation plans
- Experience as a mentor, tech lead or leading an engineering team
- BS in Computer Science, Information Security, 5+ years of demonstrated experience in areas such as application security, offensive security and/or systems security and have a strong application security background with a focus on scalable solutions
- Solid understanding of threat modeling, design and architecture review, manual source code review, security vulnerabilities, attacker exploit techniques, and methods for their remediation and have excellent understanding of network architecture, enterprise IT systems and cloud such as AWS
- Programming/Scripting skills (E.g: Java, Python, Perl, Bash, Ruby, PowerShell, etc.) Excellent written and verbal communication skills and strong problem-solving ability and the ability to work in ambiguous and constantly evolving environment
- Can identify and remove bottlenecks for your teammates, both in process and technology and collaborate with security stakeholders to develop security strategies and Can explain complex technical risks in simple, clear language that non-technical stakeholders can easily understand and act upon.

Preferred Qualifications

- Experience applying threat modeling or other risk identification techniques or equivalent
- Experience with security in service-oriented architectures/microservices and web services
- Demonstrated strong judgment in assessing and prioritizing technical risk, with a solid application security background and a focus on scalable solutions.
- Proven experience designing, building, and securing complex AWS architectures.
- Excellent written and verbal communication skills, with the ability to convey complex technical concepts effectively.
- Proactive in identifying and eliminating bottlenecks across processes and technology to enhance team productivity.
- Experience in one or more of the following areas: threat modeling, secure coding, identity and access management (IAM), authentication, software development, cryptography, or security research.
- Strong expertise in AWS services, network architecture, and enterprise IT environments.
- Hands-on experience performing security activities across one or more phases of the Software Development Lifecycle (SDLC), including security design reviews, threat modeling, secure code reviews, and security testing.
- Proven ability to drive continuous, scalable improvements in security controls and practices, and to collaborate effectively with stakeholders to develop and implement security strategies.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

About Amazon

Global online retail and cloud computing technology provider.

Similar jobs

Security Engineer roles near Bengaluru, Karnataka
10h
Save
Mark Applied
Hide
Senior Security Engineer - Customer Engineering
Bengaluru, Karnataka, India
OnsiteFull Time
Harness
Harness: AI-powered platform for automating software delivery and DevOps.
4+ YOERequires 4–6 years in security engineering or related work, coding and automation skills, API and AI security expertise, black-box penetration testing, threat hunting, and enterprise customer communication.
ModSecurity, WAF, REST, GraphQL, gRPC, OAuth 2.0, OIDC, JWT, Burp Suite, Postman, OWASP ZAP, Python, Akamai, Cloudflare, LLMs, MITRE ATT&CK, MITRE ATLAS
13h
Save
Mark Applied
Hide
Senior Security Engineer II - Confluent
Bangalore, Karnataka, India
RemoteFull Time
IBM
IBMNew York Stock Exchange: IBM: Global technology providing enterprise software, cloud, and consulting.
8+ YOEBachelor's degree and 8+ years of relevant experience in security detection and response, telemetry, incident response, logging, security event management, distributed teams, and scripting.
AWS, GCP, Azure
13h
Save
Mark Applied
Hide
Sr. Engineer – Security Engineering
Bengaluru, Karnataka, India
HybridFull Time
CBTS
CBTS: Provider of managed cloud, infrastructure, and cybersecurity services.
Cybersecurity experience with technical ownership of security solutions across applications, cloud, and infrastructure; ability to manage security tools, assess vulnerabilities, respond to incidents, and mentor engineers.
IDS/IPS, SIEM
21h
Save
Mark Applied
Hide
Associate - Security Engineer
Bangalore South, Karnataka, India
OnsiteFull Time
Crossbow Labs
Crossbow Labs: Provides professional cybersecurity consulting, compliance, and managed security services.
2+ YOERequires 2+ years in security, penetration testing expertise, secure code review, strong technical writing and communication, OWASP knowledge, and proficiency with security testing tools; certifications are requested.
Burp Suite Pro, WebInspect, Acunetix, OWASP
1d
Save
Mark Applied
Hide
Senior Security Engineer (Application Security)
Bengaluru, Karnataka, India
OnsiteFull Time
Tekion
Tekion: Cloud-native platform for automotive retail operations.
6+ YOEBachelor's or master's degree in computer science, cybersecurity, or related field; 6–9 years in application security or security engineering; secure coding, DevSecOps, threat modeling, CI/CD, and security automation experience.
DevSecOps, SAST, DAST, SCA, IaC, CI/CD, OWASP Top 10, OWASP ASVS, Python, Bash, Java, JavaScript, Go, IAM
1d
Save
Mark Applied
Hide
Engineering Division - Global Cyber Defense & Intel - Vice President - Bengaluru
Bengaluru, Karnataka, India
OnsiteFull Time
Goldman Sachs
Goldman SachsNYSE: GS: Global investment banking, securities, and investment management firm.
7+ YOERequires cybersecurity experience, strong Windows, Linux, network security, incident response, detection engineering, Python and PowerShell skills, SIEM expertise, and relevant security certification. Preferred: 7+ years cybersecurity and 3+ years detection engineering.
Windows, Linux, MITRE ATT&CK, NIST, Splunk, Elastic, BQL, Python, PowerShell, Microsoft Defender for Endpoint (MDE), CrowdStrike Falcon, AWS, Google Cloud, Azure
1d
Save
Mark Applied
Hide
Senior Security Engineer - Product Security
Bangalore, Karnataka, India
OnsiteFull Time
Ecolab
EcolabNYSE: ECL: Provides water, hygiene, and infection prevention solutions and services.
6+ YOEBachelor's degree in computer science, information technology, or related discipline; 6–8 years in product security; expertise in application security, penetration testing, secure code review, AI security, and DevSecOps.
Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Python, JavaScript, TypeScript, Java, C#, .NET, Apex, Web Application Firewall (WAF), Fastly, Cloudflare, Akamai, Snyk, Qualys, Burp Suite, Wiz, Postman, MobSF, Elastic, Agentic Scanner, Azure, AWS, GCP, ADO, GitHub, OWASP Top 10, CWE Top 25, OWASP Top 10 for LLMs, CI/CD, DevSecOps, API Security, Infrastructure as Code (IaC) Security, Secrets Management, Prompt Injection, Data Poisoning, Model Theft
1d
Save
Mark Applied
Hide
Staff Security Engineer (Vulnerability Management)
Bengaluru, Karnataka, India
OnsiteFull Time
Guidewire
GuidewireNYSE: GWRE: Provides a software platform for property and casualty insurers.
Experience managing vulnerability tools and cloud workloads at scale in AWS or Azure; scripting with Perl, Python, PowerShell, or Bash; strong security, communication, automation, and stakeholder management skills.
Rapid7, Tenable, Qualys, Brinqa, Perl, Python, PowerShell, Bash, AWS, Azure, Windows, Linux