Security Engineer, WSM Crew
Amazon
Description
The AWS Security Operations manages the security and availability of AWS Cloud services. We operate on the ‘AWS’ side of the Shared Responsibility Model to ensure “Security of the Cloud” and to protect our customers. This role requires engineers to work tactically with both internal and external stakeholders to solve security challenges at massive scale, and to think strategically to develop and implement changes to drive automation, scalability and continuous progress for the organization.
As part of the WSM Crew team under SecOps Risk, this role will involve working hand in hand with Security Operations and TPMs in executing and enhancing the Weekly Security Meeting (WSM) program which is responsible for prioritizing top security issues and working with multiple stakeholders (Service teams, Security teams, Legal, Support teams, and Executive leadership) to present a concise narrative of the issues weekly to AWS Executive Leadership.
The role will involve driving the right Incident Response outcomes, bottoming out on scope of impact, and bar raising action items related to the security issues.
Key job responsibilities
A successful candidate will need a combination of troubleshooting, technical, and communication skills, as well as the ability to handle a mix of disparate tasks which may include small-projects in addition to managing incident response activities. This role will provide career growth opportunities as you gain new security skills in the course of your duties.
• Operate as an escalation and technical expert for engineers or service teams when performing impact assessment and risk analysis to help define the scope of the problem
• Evaluate common risk tradeoffs such as evaluating tactical compensating controls versus directly addressing broad root causes.
• Conduct deep dives to independently gather information that helps you assess the risk, impact and scope of the security issue
• Identify and create solutions or automation that improves the business, optimizes process or drives efficiency on a global scale
• Conduct special projects as assigned by AWS SecOps leadership
• Participate in efforts to promote security throughout the company and build good working relationships with partner security teams and service teams across Amazon
• Operate as technical mentor, drive consistency and continually raise the technical bar.
• Communicate the state of issues to various audiences, both technical and non-technical, at various levels of seniority (up to and including the AWS Chief Information Security Officer).
A day in the life
This position supports AWS with security operations and incident response activities. You will be responsible for coordinating and facilitating security response activities for all AWS products and services. You will drive security related issues to resolution across numerous service teams, interacting directly with those teams and other AWS Security engineers.
About the team
The WSM Crew owns the Weekly Security Meeting (WSM) program which is responsible for prioritizing top security issues and working with multiple stakeholders (Service teams, Security teams, Legal, Support teams, and Executive leadership) to present a concise narrative of the issues weekly to AWS Executive Leadership for the right security risk reduction outcomes.
We work with AWS security and service teams to ensure security issues are addressed and resolved with the right level of urgency, while keeping our key stakeholders informed and engaged as necessary throughout the issue lifecycle.
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
Basic Qualifications
- Bachelor's degree in engineering, cybersecurity, or 4+ years’ equivalent professional experience.
- 3+ years of experience on a Security Operations team, coordinating responses to security events which involve multiple teams across an organization, and programmatically preventing recurrence.
- 2+ years or more of demonstrated experience with a focus in areas such as systems, network, and/or application security.
- Understanding of best practices across multiple security disciplines/domains.
Preferred Qualifications
- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Strong demonstrated knowledge of web protocols, common attacks, and an in-depth knowledge of Linux/Unix tools and architecture.
- 2+ years experience with scripting or programming languages such as Python, Bash, JavaScript, or Java
- Possess strong security judgment, critical thinking, and leadership skills in order to build trust, collaborate with, and influence partner teams to understand security and business impacts of issues.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Confirm your E-mail: Send Email
All Jobs from Amazon