Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Security Engineer, Application Security Team​/MAST image - Rise Careers
Job details

Senior Security Engineer, Application Security Team​/MAST - job 1 of 2

Senior Security Engineer, Maximum Application Security Team (MAST)Job | Services LLCIn Amazon Stores, we ship some of the widest arrays of technology found at any company. From to world class machine learning pipelines, from cutting-edge digital healthcare to no-checkout retail, we push the boundaries of technology in every direction using the globe’s largest AWS deployment.As an App Sec engineer, you will collaborate with software development teams to ensure we keep our customers safe while developing these novel services. In a given day, you might be inspecting an application’s code for security issues, building a new framework to help our software developers build faster and more securely, or fine-tuning the design for a new service alongside its software developers.The ideal candidate combines technical acumen with an ability to lead by influence and communicate clearly. Technically, this person will be a security generalist with one or more areas of deep expertise. In their communication, they will clearly articulate risks to technical and non-technical audiences alike. Interpersonally, successful candidates will effectively harmonize disparate opinions while effectively prioritizing risks to guide their partners towards secure solutions.Our organization prizes its employees, and we show it through investing in work-life harmony. We have dedicated resources that consistently innovate in reducing on-call time and ensuring the team spends their time on the highest-value tasks. Join the Stores App Sec organization to work hard, have fun, and make history!Key job responsibilities• Creating, updating, and maintaining threat models for a wide variety of software projects• Manual and automated secure code review, primarily in Java, Python and Java script• Development of security automation tools• Adversarial security analysis using cutting-edge tools to augment manual effort• Security training and outreach for internal development teams• Security architecture and design guidance• Lead execution and definition of security strategy for your team• Mentor and develop teammates both technically and professionally• Seek out, develop, and advocate for new technology to identify and mitigate complex risks• Effectively navigate novel situations and problems that do not have a defined solutionBASIC QUALIFICATIONS- BS in Computer Science or related field, or equivalent work experience- Minimum of 5 years of experience with at least three of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, penetration testing, cloud security, mobile security, and network security- Advanced knowledge and understanding of security engineering, system and network security, authentication and security protocols, cryptography, or application security- Experience reading and writing in at least one programming languagePREFERRED QUALIFICATIONS- You demonstrate excellent judgement in assessing and prioritizing technical risk- You have a strong application security background with a focus on scalable solutions- You have experience building and securing complex AWS architecture- You have excellent written and verbal communication skills- You effectively negotiate priorities across teams to achieve challenging goals and security debt reduction- You have experience creating processes that drive consistent security outcomesAmazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.#J-18808-Ljbffr

Average salary estimate

Estimate provided by employer
$80000 / ANNUAL (est.)
min
max
$70K
$90K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Security Engineer, Application Security Team​/MAST, Amazon

As a Senior Security Engineer on the Maximum Application Security Team (MAST) at Amazon, based in vibrant Austin, TX, you'll play a pivotal role in safeguarding our innovative technology. You'll collaborate closely with software development teams to ensure security is baked into every stage of development, ultimately protecting our customers as we deliver cutting-edge solutions ranging from machine learning to no-checkout retail experiences. Each day may bring new challenges, whether you're diving into application code for security vulnerabilities, enhancing security frameworks, or brainstorming designs with development teams. We’re looking for a blend of a security generalist with deep expertise in key areas and someone who can effectively communicate complex risks to both technical and non-technical audiences. Here, at MAST, we believe in the importance of work-life harmony, and we’re proactive about minimizing on-call duties so that you can engage in the most rewarding tasks. This is a chance to make a significant impact while collaborating with like-minded professionals in a fun and innovative environment. Join us on this journey to work hard, have fun, and make history!

Frequently Asked Questions (FAQs) for Senior Security Engineer, Application Security Team​/MAST Role at Amazon
What responsibilities does a Senior Security Engineer at Amazon's Application Security Team have?

The Senior Security Engineer at Amazon's Maximum Application Security Team (MAST) is responsible for maintaining security frameworks, conducting secure code reviews, developing security automation tools, and providing security architecture guidance. They play a crucial role in threat modeling for various software projects and engage in security training for internal teams, creating a culture of security awareness throughout the organization.

Join Rise to see the full answer
What qualifications are needed for a Senior Security Engineer at Amazon's MAST?

To qualify for the Senior Security Engineer position at Amazon's Maximum Application Security Team (MAST), candidates need a Bachelor's degree in Computer Science or a related field, alongside a minimum of 5 years of relevant experience. Skills in secure coding, cloud security, threat modeling, and a solid understanding of security engineering principles are essential. Familiarity with programming languages is also required.

Join Rise to see the full answer
What is the work environment like for a Senior Security Engineer at Amazon?

The work environment for a Senior Security Engineer at Amazon's Maximum Application Security Team (MAST) is collaborative and dynamic. The team prides itself on work-life harmony, continuously innovating to reduce on-call duties and ensure engineers can focus on impactful security tasks. The culture fosters innovation, mentorship, and open communication across teams.

Join Rise to see the full answer
What programming languages should a Senior Security Engineer at Amazon be familiar with?

A Senior Security Engineer at Amazon's Maximum Application Security Team (MAST) should be proficient in at least one programming language, with skills particularly beneficial in Java, Python, and JavaScript. This knowledge is crucial for conducting secure code reviews and developing effective security automation tools.

Join Rise to see the full answer
How does Amazon support the professional growth of Senior Security Engineers?

Amazon actively supports the professional growth of its Senior Security Engineers at the Maximum Application Security Team (MAST) through mentorship opportunities and continuous learning. Engineers are encouraged to seek new technologies and develop skills that can help mitigate complex risks while participating in internal training and outreach initiatives.

Join Rise to see the full answer
Common Interview Questions for Senior Security Engineer, Application Security Team​/MAST
Can you describe your experience with threat modeling in application security?

When answering this question, focus on specific projects where you've successfully implemented threat modeling processes. Highlight the tools and methodologies you used, the types of threats you assessed, and how your findings led to enhanced security measures in the application lifecycle.

Join Rise to see the full answer
How do you approach secure coding practices, and what languages are you most familiar with?

Discuss your knowledge of secure coding principles and techniques, and don’t forget to touch on your experience with specific programming languages, particularly those relevant to the position such as Java, Python, or JavaScript. Providing examples of how you have applied secure coding practices in past work will add depth to your response.

Join Rise to see the full answer
What security tools have you used for automated code reviews?

Be prepared to discuss specific automated code review tools you have experience with, such as SonarQube, Checkmarx, or Fortify. Describe how you integrated these tools into the CI/CD pipeline and how they contributed to identifying vulnerabilities early in the development process.

Join Rise to see the full answer
Can you give an example of a successful collaboration with software development teams?

Use a specific example that showcases your interpersonal skills and collaborative approach. Describe the project, your role, how you communicated security requirements, and the outcome of the collaboration in terms of improved security posture.

Join Rise to see the full answer
How do you stay up-to-date with the latest security vulnerabilities and trends?

Discuss your strategies for staying informed, such as attending conferences, participating in webinars, following reputable security blogs, or being active in professional security communities. Mention any certifications or continuous learning courses you pursue to maintain your expertise.

Join Rise to see the full answer
Describe a challenging security issue you’ve dealt with and how you resolved it.

Narrate a detailed example of a security challenge, including the context, your analysis, the decisions you made, and the eventual solution. Highlight the importance of teamwork and how collaboration played a role in your resolution efforts.

Join Rise to see the full answer
What is your experience with mentoring other engineers in security practices?

Share your experiences as a mentor, the methods you’ve used to educate others about security principles, and how you’ve tailored your mentorship to different skill levels. Highlight any structures you put in place for regular training or hands-on workshops.

Join Rise to see the full answer
How would you prioritize security tasks across different projects?

Discuss your criteria for assessing risk, the methodologies you use to evaluate security needs, and how you communicate priorities to stakeholders. Providing an example of a time when you had to balance competing priorities will illustrate your reasoning.

Join Rise to see the full answer
What security standards or frameworks are you most familiar with?

Name specific security standards or frameworks such as OWASP, NIST, or CIS controls. Discuss how you have applied them in your previous roles and how they have influenced your approach to security in application development.

Join Rise to see the full answer
How do you handle conflicts between security requirements and business needs?

Explain your approach to balancing security and business objectives by focusing on effective communication and negotiation. Provide an example of a situation where you successfully navigated this conflict to achieve a win-win outcome.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Amazon Hybrid Texas, USA
Posted 8 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Posted 9 days ago
Photo of the Rise User
Nagarro Remote Remote, Portugal
Posted 2 days ago
Photo of the Rise User
Nuvei Remote No location specified
Posted 6 days ago
Photo of the Rise User
Posted 5 days ago
Photo of the Rise User
Posted 8 days ago

Amazon is guided by four principles: customer obsession rather than competitor focus, passion for invention, commitment to operational excellence, and long-term thinking.

1824 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
BENEFITS & PERKS
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 19, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!