Security Engineer II, Stores AppSec
Core
Conducting application security reviews and penetration tests to discover and remediate security issues in Amazon's services, applications, and websites.
Role type
Senior IC application security engineer (penetration testing)
Builds
Secure services, applications, and websites for Amazon customers
Domain
E-commerce / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Python, Ruby, Go, Swift, Java, .Net, C++, scripting, security code review, troubleshooting systems issues, log analysis, automation, networking protocols (HTTP, DNS, TCP/IP), vulnerability assessment
Preferred skills
threat modeling, secure coding, identity management, authentication, cryptography, system administration, network security, AWS products, SDLC security activities
Technologies
Python, Ruby, Go, Swift, Java, .Net, C++, AWS, HTTP, DNS, TCP/IP
Responsibilities
Conduct high quality application security reviews and penetration tests independently or as part of a team; Create detailed engagement plans and document findings, gaps, and remediation recommendations; Contribute to team tooling, innovation, and improvements; Communicate and collaborate with partner teams and leadership to drive resolution of security findings
Seniority
Senior, hands-on IC
