Experience Inc. Jobs

Job Information

Amazon Corporate LLC Senior Security Engineer, WWCS Application Security in Seattle, Washington

This role can be in Seattle, Austin, Nashville, Arlington, or Toronto Amazon is seeking a talented and seasoned Senior Applications Security Engineer to focus on securing the ecosystem that powers Amazon Customer Service (CS). CS is one of the largest customer service organizations in the world. Our business operations include tens of thousands of Customer Service Associates around the globe who provide world-class support to customers 24 hours a day, 7 days a week, and in over 15 languages (and growing). This position will provide you with a challenging opportunity to solve difficult security problems at planetary scale. As a senior security engineer, you will help define short-term and long-term security strategy. You will balance your efforts between strategic and operational deliverables. You will have the opportunity to work with talented engineering teams within Amazon to ensure applications are designed and built securely. You care deeply about keeping Amazon customers secure and therefore are passionate about finding, and mitigating vulnerabilities/risks by providing actionable guidance to product teams and drive long term security improvements. You\'re well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization (technical and non-technical). The successful candidate must be autonomous, comfortable operating in highly ambiguous situations, and must deliver results in a fast-paced environment. Your responsibilities will include: Perform security reviews including secure design and architecture, threat modeling, threat assessments, secure code reviews, security testing, and security certifications Identify security gaps in applications, services, and products including internally developed, as well as third party solutions Determine findings criticality taking into account the relevant business, technical, and threat environment Produce reports that describes the work perform for a variety of audiences including technical and non-technical stakeholders Communicate findings to relevant stakeholders through a combination of verbal and written reports. Identify owners, and drive mitigation of findings within established SLAs Record findings and supporting evidence, work product, and testing results following established policies and procedures Design, develop, deploy, and maintain security automation, secure-by-default solutions, and other solutions that will enable developer and security engineering productivity using scripting or programming languages Develop a broad and deep technical understanding of the services, architectures, and products pertaining to the Customer Service organization Contribute to the long-term and short-term security strategy to ensure that applications are designed and built securely Comfortably transition between big picture, strategic thinking and tactical, day-to-day operational execution Review technical solutions to provide guidance to help mitigate security vulnerabilities as well as provide actionable long-term and short-term risk mitigation recommendations Improve secure software development life-cycle (SSDLC) practices across multiple organizations in Amazon Influence decision-makers and stakeholders to achieve a consistently high security bar Create relevant documentation, security guidance, and metrics to report to your stakeholders and business leaders and deliver these in a clear, concise manner Lead security initiatives with end-to-end ownership Participate in security escalations support including on-call rotation Evaluate and recommend new and emerging security products and technologies Support for mentoring, team building, recruiting activities, onboarding of new team members Own and carry out new, reoccurring, or ad-hoc security engineering projects and consultations Deliver practical security solutions providing the most customer-ce