Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Engineer, Pre-Launch Security Testing image - Rise Careers
Job details

Security Engineer, Pre-Launch Security Testing

Description

Are you interested in security and supporting penetration testing at a global scale? Do you strive to achieve a deep understanding of systems and apply a hacker mindset to determine how they can be broken? As a pre-launch Security Engineer, you are part of a testing team that evaluates AWS services and features to help builders maintain a high security bar. When builders have implemented fixes to security issues, you review their proposed corrections to determine efficacy before final release. You work closely with testers to understand their approaches and methodologies so you can quickly reproduce them in a variety of customer environments. You recognize the value of automation and are comfortable with scripting languages to develop tools that improve the speed and quality of your team's verification work.

Our team is responsible for the manual assessment of all products, services and software released by AWS. To accomplish this, we support and write a variety of automated tooling (e.g. fuzzers, scanners, analyzers, etc.) to verify security fixes related to penetration testing. We specialize in digging deep to find security issues that static analysis tools can’t, and write the tooling to help with these goals whenever possible. The AWS surface area is large and diverse, and we use results found in manual analysis to help improve our enterprise-wide automation to proactively spot and fix potential security issues to protect customers.

Key job responsibilities
• Automate the verification and remediation of security issues
• Manually audit the source code of web services and software authored in house by Amazon
• Write proof of concept code to demonstrate the severity of a potential security issue
• Provide clear communication on issues to developers that suggest and help to test the fix
• Partner with AWS developers to drive improvement in application security as a result of security review engagements
• Provide actionable long term risk mitigation guidance

A day in the life
As a Security Engineer supporting verifications for pre-launch testing, you have the opportunity to review and dive deep into builder-proposed fixes. You'll access development environments for upcoming AWS services and features to dive deep into their code to learn how security issues were discovered and how the builders intend to address them. You perform static code analysis and dynamic reproduction of issues to make the final decision on whether the builder's proposed fix is sufficient to allow their code release.

About the team
About Amazon Security

• Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

• Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores

• Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

• Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

• Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

- A Bachelor’s degree in Computer Science, Cybersecurity, similar degree, or equivalent professional experience can be used in lieu of a degree.
- Minimum of 1 year of experience with manually auditing source code (One or more of: Java, Ruby, Python, JavaScript, Rust, C, others) to find security issues.
- Minimum of 1 years of experience scripting in Python or other equivalent interpreted languages.
- Minimum of 1 years of professional experience with security engineering practices such as in web application security, network security, authentication and authorization protocols, cryptography, automation and other software security disciplines.

Preferred Qualifications

- Experience with AWS technologies and services (e.g. S3, Lambda, EC2, KMS, IAM, etc.)
- Experience with bug hunting, bug bounties, capture the flag, software development
- Experience with multiple programming languages

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $125,500/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Average salary estimate

$169150 / YEARLY (est.)
min
max
$125500K
$212800K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Engineer, Pre-Launch Security Testing, Amazon

Are you ready to join an innovative team at Amazon as a Security Engineer focused on Pre-Launch Security Testing in Washington, USA? If you have a passion for cybersecurity and a knack for finding vulnerabilities before they become a problem, this role might be your perfect opportunity! You'll be diving deep into AWS services and features, collaborating with builders to maintain a high security standard. Your mission will involve manually auditing source code and automating verification processes to ensure your team's effectiveness. This means you'll not only get to flex your coding skills in languages like Python, Rust, or Java but also utilize your creativity to develop tools that enhance our security testing suite. We pride ourselves on proactively identifying security issues that may elude static analysis, all while fostering a cooperative environment with developers to drive improvements in application security. And don’t worry if you’re at the beginning of your career or come from a non-traditional background; we value diverse experiences! At Amazon Security, we believe in work-life balance and ongoing professional development, helping you grow not just in your role but as an individual. Join a culture that encourages learning, supports your well-being, and celebrates every member's unique contributions. If you're looking for a dynamic role that combines technical challenge with a strong sense of purpose, consider applying for the Security Engineer position and be part of a team that plays a crucial role in securing AWS's vast array of services.

Frequently Asked Questions (FAQs) for Security Engineer, Pre-Launch Security Testing Role at Amazon
What are the responsibilities of a Security Engineer at Amazon for Pre-Launch Security Testing?

As a Security Engineer focusing on Pre-Launch Security Testing at Amazon, your primary responsibilities include manually auditing the source code for potential security issues, automating verification and remediation processes, and working closely with AWS developers to enhance application security. You'll also write proof-of-concept code to highlight security vulnerabilities and provide guidance to developers on effective solutions before code release.

Join Rise to see the full answer
What qualifications are needed for the Security Engineer, Pre-Launch Security Testing position at Amazon?

To qualify for the Security Engineer role at Amazon, candidates should have at least a Bachelor’s degree in Computer Science, Cybersecurity, or a similar field, or equivalent professional experience. Additionally, you will need a minimum of one year of experience in manual source code auditing and security engineering practices, along with proficiency in scripting languages like Python or Ruby.

Join Rise to see the full answer
What technologies should a Security Engineer at Amazon be familiar with?

In the Security Engineer role for Pre-Launch Security Testing at Amazon, familiarity with AWS technologies and services such as S3, EC2, Lambda, and KMS is preferred. Experience with multiple programming languages, and practices in web application security, network security, and automation will also be highly beneficial.

Join Rise to see the full answer
How does Amazon support diversity and inclusion in the Security Engineer role?

Amazon is committed to creating a diverse and inclusive workplace, encouraging individuals from various backgrounds to apply for the Security Engineer position. The company actively seeks out diverse experiences and perspectives, believe it can enhance problem-solving and creativity within their teams, while also providing continuous learning and personal growth opportunities.

Join Rise to see the full answer
What benefits does Amazon offer for the Security Engineer role?

For the Security Engineer, Pre-Launch Security Testing position, Amazon offers a comprehensive benefits package that includes competitive salaries reflecting geographic market conditions, equity and sign-on payments, health and financial benefits, as well as a focus on work-life balance through flexible work arrangements. Continuous training and professional development opportunities are also an integral part of the employment package.

Join Rise to see the full answer
Common Interview Questions for Security Engineer, Pre-Launch Security Testing
Can you describe your experience with manual code audits in relation to security?

In answering this question, emphasize specific projects where you performed code audits, the tools used, and the types of security issues you identified and resolved. Be sure to share the impact of your findings on the project's overall security posture.

Join Rise to see the full answer
What scripting languages are you proficient in, and how have you used them in a security context?

Discuss your experience with languages such as Python or Ruby, providing examples of how you’ve scripted tools for automating security assessments or enhancing manual testing processes. Highlight any unique solutions you've developed that significantly improved efficiency.

Join Rise to see the full answer
How do you approach collaborating with developers to ensure fixes for security vulnerabilities?

Share your strategies for effective communication and teamwork with developers, including methods for discussing vulnerabilities, providing actionable feedback, and testing proposed fixes. Illustrate with a scenario that showcases your collaborative approach.

Join Rise to see the full answer
What automated tools have you developed or used in your previous roles?

Mention any custom tools you've developed or industry-standard tools you've utilized. Explain their purpose in your security workflow and any substantial outcomes they delivered, such as reduced manual workload or improved error detection.

Join Rise to see the full answer
Can you give an example of a security challenge you found difficult and how you overcame it?

Choose a challenging security issue you faced in a previous position. Describe the situation, your thought process, the steps you took to resolve it, and what you learned from the experience. It's important to show your problem-solving skills and resilience.

Join Rise to see the full answer
What do you believe are the top security concerns for cloud services?

Discuss prevalent security issues in cloud computing, such as data breaches, configuration mistakes, or inadequate access controls. Provide insights on how these can be mitigated and link your knowledge to Amazon’s security initiatives.

Join Rise to see the full answer
How do you ensure that you stay updated with the latest security trends and vulnerabilities?

Make sure to mention your commitment to continuous learning through resources like industry blogs, publications, security conferences, and participation in bug bounties. This helps demonstrate your enthusiasm for the field and staying current with evolving threats.

Join Rise to see the full answer
In your opinion, how does manual testing complement automated security tools?

Articulate the importance of manual testing in identifying nuanced vulnerabilities that automated tools might miss. Discuss a balanced approach where both manual and automated methods are essential in ensuring robust security coverage.

Join Rise to see the full answer
Why do you want to work as a Security Engineer at Amazon?

Explain your passion for security and why Amazon's mission aligns with your career goals. Discuss how Amazon’s culture of diversity, inclusion, and continuous growth resonates with you and what you aim to achieve in your role.

Join Rise to see the full answer
What security best practices do you think should be implemented during the development lifecycle?

Mention best practices such as secure coding guidelines, regular security training for developers, continuous security testing, and integrating security into CI/CD pipelines. This shows your understanding of the importance of proactive security measures.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
City of Philadelphia Hybrid 1234 Market St, Philadelphia, PA 19107, USA
Posted 11 hours ago
Posted 2 days ago
Photo of the Rise User
Impinj Hybrid Seattle, Washington, United States
Posted yesterday
Photo of the Rise User
Coface Remote Șoseaua Pipera Nr. 42, București 020309, Romania
Posted 2 days ago
CodeNinja Remote No location specified
Posted 9 hours ago

Amazon is guided by four principles: customer obsession rather than competitor focus, passion for invention, commitment to operational excellence, and long-term thinking.

2109 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
BENEFITS & PERKS
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 18, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Columbus just viewed Strategy and Corporate Development Intern at SoundCloud
Photo of the Rise User
Someone from OH, Milford just viewed Visual Designer (Contract to Hire) at Abridge
Photo of the Rise User
Someone from OH, Dublin just viewed User Researcher III at Fearless
Photo of the Rise User
Someone from OH, Dublin just viewed Senior UX Designer at Nox Health
Photo of the Rise User
Someone from OH, Dublin just viewed US Product Designer at Praxent
Photo of the Rise User
19 people applied to IT Intern at USAA
Photo of the Rise User
Someone from OH, Solon just viewed QA Analyst at Two Circles
Photo of the Rise User
Someone from OH, Cincinnati just viewed Shift Lead - Downtown Cincinnati at DoorDash USA
Photo of the Rise User
Someone from OH, Cleveland just viewed Getinge is hiring: UI/UX Developer in Streetsboro at Getinge
Photo of the Rise User
Someone from OH, Loveland just viewed Inside Sales Co-Op at VEGA Americas
B
Someone from OH, Painesville just viewed Administrative Assistant at BlkVision Media
Photo of the Rise User
Someone from OH, Cincinnati just viewed Marketing Customer Support (Automotive) at Publicis Groupe
Photo of the Rise User
Someone from OH, Columbus just viewed Event Campaign Manager at Smartling
H
Someone from OH, Chesterland just viewed Client Success Manager at HR Force International
Photo of the Rise User
Someone from OH, Dublin just viewed Junior PMO Analyst at Rentokil Initial Group
Photo of the Rise User
Someone from OH, Doylestown just viewed Associate Sub-editor at Third Bridge
Photo of the Rise User
Someone from OH, Pickerington just viewed Layout Artist at Powerhouse Animation Studios
Photo of the Rise User
Someone from OH, Cortland just viewed Exploring Post-Grad Rotational Programs at Evonik at Evonik
B
Someone from OH, Powell just viewed Salesforce Admin (Part Time) at Bullpen Talent