Application Security Engineer, Proactive Security
Core
Conduct security assessments, threat modeling, and penetration testing for applications and services to identify vulnerabilities and ensure adherence to security standards before launch.
Role type
Application Security Engineer (Proactive Security)
Builds
Secure application architectures and services for Amazon's diverse product lines
Domain
Cloud security, web application security, threat modeling
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
web protocols, common security attacks, remediation techniques, penetration testing, application security architecture, security code reviews, incident response, security infrastructure, coding/scripting (Python, C, C++, Java, Ruby, PowerShell)
Preferred skills
AWS services, application security frameworks, mobile security, cloud security, AI security, identity and access controls, cryptography, public key infrastructure, forensic security, IP security, SSL/TLS, network security, threat intelligence, IoT security, authentication, security alert triaging, response automation
Technologies
Python, C, C++, Java, Ruby, PowerShell, AWS
Responsibilities
Conduct security design reviews for new and existing services, perform threat modeling exercises, execute or coordinate penetration testing activities, document and track security findings with remediation guidance, provide security consultation on secure coding and data protection, escalate high-severity security issues, maintain documentation of review outcomes and risk assessments, leverage automated security scanning tools
Seniority
Mid-level, hands-on IC