Logo
Amazon

Security Engineer, Software Supply Chain Security

Amazon, Austin, Texas, us, 78716


Security Engineer, Software Supply Chain Security

Job ID: 2747427 | Amazon.com Services LLCThe Amazon Information Security team is looking for a Security Engineer to help ensure our services, applications, and websites are designed and implemented to the highest security standards. You have breadth and depth of security knowledge and can identify and advise on risks across multiple areas of an organization.

You will join a team working on Software Supply Chain Security (SSC-S) initiatives and drive transformative changes on how thousands of Amazon dev teams consume, build, operate, and ship secure software. You will work with limited guidance in the face of ambiguity. You will take a long-term view of Amazon's software development security processes and tools.

Key job responsibilities

Evaluating and recommending new and emerging security products and technologies.Identifying security issues and risks, and developing mitigation plans.Through security risk assessments, identify repeatable work streams and influence automation of such streams to reduce cycle times and drive efficiency.Participate in the design discussions and development of user stories for automation.Positively influence Security Governance initiatives; partner with engineering teams to develop a Security dashboard that provides ongoing Leadership visibility of the security posture, threats, and risks.Establish credibility and maintain strong working relationships with technical groups involved with security including but not limited to Security Teams, AWS (Amazon Web Services), Legal, Compliance, and Developer Community.Build and influence supply chain software security as a core competency throughout InfoSec’s relationships with internal Amazon teams, partners, and vendors.

About the teamDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the preferred qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon SecurityAt Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training and Career growthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional. BASIC QUALIFICATIONS

- BS in Computer Science or related field, or equivalent work experience.- At least 3 years of experience in application security, threat modeling, secure coding, software development, secure software or system design.- At least 3 years of experience in a development or security role working with development team(s) that delivered commercial software or software-based services.- Advanced knowledge and understanding of any combination of the following: security engineering, system and network security, authentication and security protocols, cryptography, or application security.- Experience with multiple programming languages (such as Java, C++, Ruby, Python, Perl, etc.).PREFERRED QUALIFICATIONS

- Experience managing and delivering security solutions at scale.- Experience with DevOps, Software Build and Deployment systems, Software Composition Analysis.

#J-18808-Ljbffr