Security Engineer, Identity and Access Management
Core
Design, implement, and secure identity and access management (IAM) systems for Amazon's global business units, focusing on authentication and authorization workflows.
Role type
Senior IC Security Engineer (Identity and Access Management)
Builds
Secure authentication and authorization infrastructure for Amazon's Stores, Digital, and Other organizations
Domain
Cloud Security / Identity and Access Management
Deliverable
production ML models | product features | infrastructure
Required skills
Python, Ruby, Go, Swift, Java, .Net, C++, networking protocols (HTTP, DNS, TCP/IP), security code review, threat modeling, automated security auditing (SAST/DAST), identity lifecycle management, FIDO2/WebAuthn, Kerberos, Single Sign-On, Passwordless Authentication, OAuth 2.0, OpenID Connect, SAML
Preferred skills
AWS products and services, cryptography, system administration, network security, software development lifecycle (SDLC) security activities
Technologies
Python, Ruby, Go, Swift, Java, .Net, C++, HTTP, DNS, TCP/IP, FIDO2, WebAuthn, Kerberos, SSO, Passwordless Authentication, OAuth 2.0, OpenID Connect, SAML, AWS
Responsibilities
Participate in architectural reviews and threat models for identity systems; Develop and support requirements for IAM security initiatives; Implement and maintain automated security audits for identity workflows; Collaborate with business teams on technologies such as FIDO2, Kerberos, Single Sign-On, and Passwordless Authentication; Analyze, troubleshoot, investigate, and remediate identity security events; Create and maintain scripts to automate reporting and security operations
Seniority
Senior, hands-on IC