Sr. Security Engineer, Leo Security
Amazon.com Services LLC•1d ago
United StatesHybridFull-timeMid Level5+ yrs exp
H-1B verified · 2310 LCAs
Top focus
Security EngineerCloud Security Engineer
- We are open to hiring candidates to work out of one of the following locations: Redmond, WA, USA Leo is an initiative to launch a constellation of Low Earth Orbit satellites that will provide low-latency, high-speed broadband network connectivity to unserved and underserved communities around the world. Have you wanted an opportunity to secure an advanced satellite based broadband telecom service? The Leo Security team owns the security of product and operations of Leo end-to-end. We provide the necessary infrastructure and mechanisms to ensure the security of our satellite constellation and to protect the integrity and confidentiality of our customer data. Our team drives the research & development, deployment and operation of several mission-critical security systems and mechanisms. You will work in a start-up like environment, backed by Amazon’s infrastructure to bootstrap security mechanisms
- help instill the security culture in the organization. Export Control Requirement Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder)
- lawfully admitted into the U.S. as a refugee or granted asylum. Key job responsibilities You will help define develop and implement Leo's vulnerability management program. You will advocate for the creation & deployment of new testing tools
- detection mechanisms. You will leverage support from automation teams that find discoverable vulnerabilities. You’ll identify design & implementation defects and build compensating security controls. You'll support product development processes by providing consultation services on difficult security decisions. You will collaborate with business leaders to define security priorities. You will support product leaders by acting as a trusted advisor. You will support leaders by providing them with direction that makes security easy. You will help leaders measure their org's security execution. You'll guide teams towards outcomes that produce products that safely handle customer data. You will collaborate with builder teams to assess technical debt and risk. You will provide strategic direction that addresses vulnerabilities and fortifies our products. You will be a resource that leads the burn down of long-term risk. You will instill a security culture in builder teams. You will mentor builders who aspire to become security advocates & security engineers via 1-1 sessions & office hours. And last of all, you will hack some really cool bleeding edge tech! A day in the life In this highly dynamic role, you'll be accountable for deciding where your time investments provide the most value. You will have a blend of building preventive and detective controls. Teams will reach out for ideas on how to handle a wide variety of security problems. You can anticipate implementation questions like "What's the paved path for vulnerability management?" "We've experienced an incident and need to perform 5 why's analysis to identify and correct the problem that produced the incident." When you're not working on responding to the questions of builder teams, you will be evaluating overall org performance to identify architectural defects and proposing new security scanning capability to correct problems in the org. You will help Amazon maintain a high bar for customer security. About the team Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path
- includes alternative experiences, don’t let it stop you from applying. Why Amazon Security? At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations
- physical stores. Inclusive Team Culture In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives
- voices. Training & Career Growth We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training
- other career-advancing resources here to help you develop into a better-rounded professional. Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home
- is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
- 5+ years of work in identifying security issues and risks
- developing mitigation plans experience - 5+ years of non-internship background in troubleshooting systems issues, analyzing logs
- automating complex tasks using command line tools experience - Experience (non-internship) in industry-based security vulnerabilities identification, attack patterns
- remediation techniques - 5+ years of (non-internship) scripting, programming
- security code review in common programming languages experience - Experience as a mentor, tech lead or leading an engineering team
- Experience applying threat modeling or other risk identification techniques or equivalent - Experience with security in service-oriented architectures/microservices and web services - Master's degree in Cybersecurity, Information Security
- a related field - Experience using data and metrics to back up assumptions, evaluate outcomes
- make data-driven decisions - Experience triaging security risks or vulnerabilities and ensuring that they are properly understood by the business and fixed or mitigated - Experience in Space Vehicle/Satellite Operations, Space Communications or related industry - Experience with embedded systems - 8+ years Experience in performing and/or participating in technical security assessments, e.g. code level, application level
- network/infrastructure assessments - Familiarity with programming and scripting or experience developing security tools & processes that work at scale Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability
- other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications
- location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off
- parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits . USA, WA, Redmond - 178,400.00 - 226,700.00 USD annually
Required skills
SecurityVulnerability ManagementAutomationScriptingProgrammingSecurity Code ReviewThreat ModelingMicroservicesWeb Services