Security Engineer

3+ months agoSeattle, WA


Amazon Payments Services build systems that process payments at an unprecedented scale, with accuracy, speed, and mission-critical availability. We process millions of transactions every day worldwide across various payment methods. Over 100 million customers and merchants send hundreds of billions of dollars moving at light-speed through our systems annually. We are re-inventing the vision of our platform to provide the best payment gateway service, benchmarked against the top external alternatives.

As a Security Engineer, you will solve some of the most challenging and interesting problems to effectively mitigate large-scale threats. You'll secure the design and implementation of several internal and external payments services. If you enjoy analyzing the security of secure channels, services, mobile and web applications, but also creating and implementing secure designs and protocols, working within development teams to innovate, finding solutions to security problems at scale, this position will provide you with a challenging opportunity. Paramount to our success is ensuring that customer data is secure.
A Security Engineer in Amazon, expected to be strong in multiple domains will be sought out for advice on technical issues. Efficient time management skills are required along with the ability to deliver results in the face of uncertainty. A Security Engineer will proactively share knowledge across the Amazon service owners and will be a key company resource in one or more of the core areas of security.
Engineers in this role must show exemplary judgment in making technical trade-offs between short versus long term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. The successful candidate must be one that can handle several difficult challenges and problems, can make risk-based assessments founded on data and facts rather than older static based security paradigms, though being aware of the older best practices.
Additionally, the successful candidate will be:

• Methodically empirical and experimental in approach and evaluation without being bound by over paralysis-by-analysis
• Be an enthusiastic learner and curiosity seeker, focusing on what can be done rather than hindered by notions of what cannot be
• Work ceaselessly to improve knowledge of the security field, threat landscape, security intelligence, moving proactively toward prevention and detection of threats
• Possess effective verbal and written communication skills, be passionate about sharing knowledge, tactics, strategy, as well as advocating for the project mission
• Great logic and problem-solving skills.
• Work with development teams to own design and implementation of security related components and services.
• Provide expert advice and consultancy to internal customers on risk assessment, threat modeling and fixing vulnerabilities
• Evangelize security within and be an advocate for customer trust
• Develop training materials for general security awareness and specific security technology training

Amazon is an Equal Opportunity-Affirmative Action Employer Minority / Female / Disability / Veteran / Gender Identity / Sexual Orientation as this must appear on all our external job postings.


• BS in computer science, networking, information systems, computer engineering, or 3+ years' equivalent experience

• Minimum of 3 years experience in identifying security issues and risks, and developing mitigation plans

• Minimum of 2 years experience in network, system, or software architecture; design, implementation, support, and evaluation of security-focused tools and services

• Minimum of 2 years scripting or programming experience in Ruby, Python, Shell/BASH scripting, Java, C/C++, C#, Perl, or other languages

• Minimum of 2 years experience in three or more of the following areas: cryptography, application security, authentication, web and network protocols, data structures and algorithms, software development, threat modelling, pen tests, or vulnerability assessments

• Minimum of 2 years experience in executive communications or technical writing; clear, concise, and thorough written and oral communication skills.

• Results oriented, high energy, self-motivated


• MS in Computer Science, Networking, Information Systems, Computer Engineering, Systems Engineering or 6+ years' equivalent experience

• Two plus years experience on a security engineering or application security or penetration testing

• Three plus years experience dealing with computing security issues and threat vectors

• Security related certifications

• Four plus years experience in evaluating, recommending, and implementing new and emerging security products and technologies

• Three plus years experience with large enterprise environments

• Three plus years experience with cross-organizational collaboration and negotiation

• Meets/exceeds Amazon's leadership principles requirements for this role.

• Meets/exceeds Amazon's functional/technical depth and complexity for this role
Amazon is an Equal Opportunity-Affirmative Action Employer Minority / Female / Disability / Veteran / Gender Identity / Sexual Orientation

Job ID: Amazon-1449960