Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Security Engineer, Application Security Team​/MAST image - Rise Careers
Job details

Senior Security Engineer, Application Security Team​/MAST

Senior Security Engineer, Maximum Application Security Team (MAST)Job | Services LLCIn Amazon Stores, we ship some of the widest arrays of technology found at any company. From to world class machine learning pipelines, from cutting-edge digital healthcare to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As an App Sec engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services. In a given day, you might be inspecting an application’s code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service alongside its software developers.The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security generalist with one or more areas of deep expertise. In their communication, they will clearly articulate risks to technical and non-technical audiences alike. Interpersonally, successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions.Our organization prizes its employees, and we show it through investing in work-life harmony. We have dedicated resources that consistently innovate in reducing on-call time and ensuring the team spends their time on the highest-value tasks. Join the Stores App Sec organization to work hard, have fun, and make history!Key job responsibilities• Creating, updating, and maintaining threat models for a wide variety of software projects• Manual and automated secure code review, primarily in Java, Python and Java script• Development of security automation tools• Adversarial security analysis using cutting-edge tools to augment manual effort• Security training and outreach for internal development teams• Security architecture and design guidance• Lead execution and definition of security strategy for your team• Mentor and develop teammates both technically and professionally• Seek out, develop, and advocate for new technology to identify and mitigate complex risks• Effectively navigate novel situations and problems that do not have a defined solutionBASIC QUALIFICATIONS- BS in Computer Science or related field, or equivalent work experience- Minimum of 5 years of experience with at least three of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, penetration testing, cloud security, mobile security, and network security- Advanced knowledge and understanding of security engineering, system and network security, authentication and security protocols, cryptography, or application security- Experience reading and writing in at least one programming languagePREFERRED QUALIFICATIONS- You demonstrate excellent judgement in assessing and prioritizing technical risk- You have a strong application security background with a focus on scalable solutions- You have experience building and securing complex AWS architecture- You have excellent written and verbal communication skills- You effectively negotiate priorities across teams to achieve challenging goals and security debt reduction- You have experience creating processes that drive consistent security outcomesAmazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.#J-18808-Ljbffr

Average salary estimate

Estimate provided by employer
$147500 / ANNUAL (est.)
min
max
$110K
$185K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Security Engineer, Application Security Team​/MAST, Amazon

As a Senior Security Engineer on the Application Security Team (MAST) at Amazon in Austin, TX, you will play an essential role in safeguarding our innovative services. In this dynamic position, you’ll collaborate closely with software development teams to ensure robust security measures are in place while they create groundbreaking technology, from machine learning pipelines to no-checkout retail solutions. Each day could involve inspecting application code for vulnerabilities, crafting frameworks that enable developers to code securely and efficiently, or refining security designs for new applications. The ideal candidate will have a solid technical foundation intertwined with the ability to effectively communicate risks to both technical and non-technical audiences. You’ll lead with influence and harmonize diverse opinions within your team while expertly prioritizing security risks. You’ll be part of a culture that values work-life balance, supported by dedicated resources that aim to reduce on-call times. We aim to ensure that your expertise is utilized for the highest-value tasks. This is an exciting opportunity to join a team that not only aims to build secure applications but also encourages you to innovate while having fun and making history.

Frequently Asked Questions (FAQs) for Senior Security Engineer, Application Security Team​/MAST Role at Amazon
What responsibilities does a Senior Security Engineer have on the Maximum Application Security Team at Amazon?

As a Senior Security Engineer on the Maximum Application Security Team at Amazon, you will be tasked with creating and maintaining threat models, conducting both manual and automated secure code reviews primarily in Java, Python, and JavaScript, and developing security automation tools. Your role will also involve performing adversarial security analysis, providing security training and mentorship to development teams, and contributing to security architecture design.

Join Rise to see the full answer
What qualifications are needed to become a Senior Security Engineer at Amazon?

To qualify for the Senior Security Engineer position on Amazon's Application Security Team, candidates should possess a BS in Computer Science or a related field or equivalent work experience. A minimum of 5 years of experience in areas like threat modeling, secure coding, and cloud security is preferred, along with advanced knowledge of security engineering principles.

Join Rise to see the full answer
How does Amazon support work-life balance for Senior Security Engineers?

Amazon places a high value on work-life harmony, especially for roles such as Senior Security Engineer on the Maximum Application Security Team. The organization has dedicated resources that strive to reduce on-call times, ensuring that engineers can concentrate on high-impact work while maintaining their personal commitments.

Join Rise to see the full answer
What skills are essential for a Senior Security Engineer working at Amazon in Austin?

Essential skills for a Senior Security Engineer at Amazon include a strong application security background, proficiency in secure coding practices, and the ability to assess and prioritize technical risks effectively. Excellent written and verbal communication skills are also crucial to articulate security risks clearly to diverse audiences.

Join Rise to see the full answer
What does the application security landscape look like at Amazon?

The application security landscape at Amazon is diverse and ever-evolving. As a Senior Security Engineer, you will be engaged in assessing complex AWS architectures, collaborating on security strategy execution, and advocating for cutting-edge technology to mitigate risks, all while working in a team that values innovation and security consistency.

Join Rise to see the full answer
Common Interview Questions for Senior Security Engineer, Application Security Team​/MAST
Can you elaborate on your experience with threat modeling in application security?

When discussing your experience with threat modeling, highlight specific projects where you've developed threat models. Discuss the frameworks you employed, the challenges you faced, and how your models contributed to enhanced application security.

Join Rise to see the full answer
How do you perform secure code reviews?

In your response, outline your process for secure code reviews, including the tools and methodologies you utilize. Mention how you prioritize security issues and communicate findings to developers effectively.

Join Rise to see the full answer
What programming languages are you comfortable with, and how do you apply them in security?

Identify the programming languages you are proficient in and provide examples of how you've used them to contribute to security initiatives. Highlight any relevant hands-on coding experience in secure applications.

Join Rise to see the full answer
Describe a challenging security problem you solved as a Senior Security Engineer.

When detailing a challenging security problem, focus on a specific incident that showcases your analytical and problem-solving skills. Explain the context, your approach to resolving it, and the resulting impact on the organization.

Join Rise to see the full answer
How do you stay current with the latest application security threats?

Discuss your strategies for staying informed on security threats, such as following industry publications, participating in forums, and attending conferences. Show your commitment to continuous learning in application security.

Join Rise to see the full answer
Can you explain a time when you had to negotiate security priorities across teams?

Share a scenario where you had to advocate for security needs among competing interests. Outline your approach, how you communicated, and the eventual outcome to demonstrate your negotiation skills.

Join Rise to see the full answer
What tools do you find most effective for adversarial security analysis?

List the tools you find most effective for adversarial security analysis, explaining why you favor them. Describe a situation where these tools played a critical role in your assessment.

Join Rise to see the full answer
How would you conduct a security training session for developers?

Outline your plan for a successful security training session, including the critical topics you would cover, how you would engage participants, and follow-up methods to ensure learning retention.

Join Rise to see the full answer
What do you believe is the most significant risk in application security today?

Express your thoughts on current application security risks, basing your answer on recent trends or breaches. Suggest mitigation strategies to showcase your critical thinking.

Join Rise to see the full answer
How do you evaluate and implement new security technologies?

Discuss your approach to evaluating new security technologies, including criteria you consider essential. Share an instance where you successfully integrated a new tool into your security practices.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
Posted 5 days ago

Amazon is guided by four principles: customer obsession rather than competitor focus, passion for invention, commitment to operational excellence, and long-term thinking.

1822 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
BENEFITS & PERKS
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 17, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!