Security Engineer, Software Supply Chain Security
Amazon - seattle, WA
Apply NowJob Description
Description The Amazon Information Security team is looking for a Security Engineer to help ensure our services, applications, and websites are designed and implemented to the highest security standards. You have breadth and depth of security knowledge and can identify and advise on risks across multiple areas of an organization. You will join a team working on Software Supply Chain Security (SSC-S) initiatives and drive transformative changes on how thousands of Amazon dev teams consumes, build, operate and ship secure software. You will work with limited guidance in the face of ambiguity. You will take a long-term view of Amazon's software development security processes and tools. Key job responsibilities Evaluating and recommending new and emerging security products and technologies Identifying security issues and risks, and developing mitigation plans Through security risk assessments, identify repeatable work streams and influence automation of such streams to reduce cycle times and drive efficiency. Participate in the design discussions and development of user stories for automation Positively influence Security Governance initiatives; partner with engineering teams to develop a Security dashboard that provides ongoing Leadership visibility of the security posture, threats and risks. Establish credibility and maintain strong working relationships with technical groups involved with security including but not limited to Security Teams, AWS (Amazon Web Services), Legal, Compliance, and Developer Community Build and influence supply chain software security as a core competency throughout InfoSec's relationships with internal Amazon teams, partners, and vendors. About the team Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying. Why Amazon Security At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores. Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve. Inclusive Team Culture In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices. Training and Career growth We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional. Basic Qualifications BS in Computer Science or related field, or equivalent work experience At least 3 years of experience in application security, threat modeling, secure coding, software development, secure software or system design At least 3 years of experience in a development or security role working with development team(s) that delivered commercial software or software-based services Advanced knowledge and understanding of any combination of the following: security engineering, system and network security, authentication and security protocols, cryptography, or application security Experience with multiple programming languages (such as, Java, C++, Ruby, Python, Perl, etc.) Preferred Qualifications Experience managing and delivering security solutions at scale. Experience with DevOps, Software Build and Deployment systems, Software Composition Analysis Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit This position will remain posted until filled. Applicants should apply via our internal or external career site.
Created: 2024-11-05