Security Engineer, Stores Application Security

Amazon Amazon · Big Tech · IN, KA, Bengaluru · Systems, Quality, & Security Engineering

Security Engineer role at Amazon Stores focused on application security, collaborating with development teams to ensure customer safety. Responsibilities include threat modeling, code review, security research, developing automation tools, and providing security guidance. Requires experience in application security assessments, threat modeling, secure code review, and programming in languages like Python or Java. Preferred qualifications include experience with AWS, SDLC security phases, and building scalable security solutions.

What you'd actually do

  1. Creating, updating, and maintaining threat models for a wide variety of software projects
  2. First party application security research
  3. Manual and Automated Secure Code Review, primarily in Java, Python and Javascript
  4. Identifying and mitigating security issues at scale
  5. Development of security automation tools

Skills

Required

  • comprehensive application security assessments
  • automated and manual assessment
  • threat modelling
  • architecture review
  • manual source code review
  • attacker exploit techniques
  • remediation
  • programming or scripting in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language

Nice to have

  • threat modeling experience
  • secure coding
  • identity management and authentication
  • software development
  • cryptography
  • security research
  • AWS services
  • network architecture
  • enterprise IT systems
  • security design review
  • security testing
  • building scalable solutions for application security challenges

What the JD emphasized

  • novel methods or approaches
  • secure coding
  • security research