Application Security Engineer

Brisbane, Queensland, AUS

Applications have closed

Free shipping on millions of items. Get the best of Shopping and Entertainment with Prime. Enjoy low prices and great deals on the largest selection of everyday essentials and other products, including fashion, home, beauty, electronics, Alexa...

View company page

AWS Security is looking for a Product Security Engineer to design security controls and help validate that our services, applications, and emerging technologies are designed and implemented to the highest security standards. You will be responsible for analyzing the security of applications and services, discovering and addressing security issues, building security automation, and decisively taking action to mitigate emerging threats throughout a full secure development life-cycle (SDLC).

This role will provide career growth opportunities as you gain new security skills in the course of your work. Security engineers at AWS have an opportunity to experiment, learn, build tools, and work with teams building new technology and services at massive scale.
A successful candidate will need a combination of troubleshooting, technical, and communication skills. An AWS Product Security engineer must have the ability to take ownership and deliver on multiple complex objectives which may include project and software development work.

Key job responsibilities
- Security reviews for new products, technologies, and services
- Secure design, architecture, and implementation
- Secure development life-cycle (SDLC) practices including threat modeling and security testing
- Influence decision-makers and stakeholders throughout the organization in multiple teams to achieve a consistently high security bar
- Lead penetration testing engagements and create new testing methods and exploits
- Create security guidance and documentation
- Develop security tools and automation
- Develop and deliver security training and outreach to internal development teams
- Develop and improve metrics that drive desired behavior and security outcomes
- Lead security projects (including security reviews, tool development, and creation of new security practices) with end-to-end ownership
- Support for mentoring, team building and recruiting activities

About the team
Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded professional and enable them to take on more complex tasks in the future.
At AWS, we embrace our differences. We are committed to furthering our culture of inclusion.

We are open to hiring candidates to work out of one of the following locations:

Brisbane, QLD, AUS

Basic Qualifications

- Bachelor (undergraduate) degree in a relevant field (Computer Science, Software Engineer, Security, or others) OR an equivalent combination of education, training, and experience
- Minimum of 5 years of professional experience with application security.
- Minimum 4 years of experience with any combination of at least 2 technical disciplines, including the following: cloud security, network security, mobile security, security development methodologies, software development and coding, identity management, authentication and authorization, network architecture.
- Experience with system administration and systems engineering.

Preferred Qualifications

- Professional experience with applied cryptography
- Professional experience building or reviewing threat models
- Professional experience conducting security assessments, including penetration testing
- Ability to lead through influence within a secure development life-cycle for multiple products and technologies, meeting customer expectations for security
- Experience implementing security solutions that resolve security and business risk trade-offs
- An understanding of networking and communication protocols (such as TCP/IP, UDP, SSL/TLS, IPSEC, HTTP, HTTPS, BGP)
- An understanding of cryptography, web service frameworks, mobile application architectures, and service architectures (such as event-driven, service-oriented, or serverless architectures)
- Familiarity with reverse engineering or vulnerability research
- Familiarity with physical, infrastructure, or hardware security
- Experience with one or more programming languages (such as Java, C++, Ruby, Python, Perl) for the purpose of code review.

Acknowledgement of country:
In the spirit of reconciliation Amazon acknowledges the Traditional Custodians of country throughout Australia and their connections to land, sea and community. We pay our respect to their elders past and present and extend that respect to all Aboriginal and Torres Strait Islander peoples today.

IDE statement:
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer, and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, disability, age, or other legally protected attributes.

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Application security Automation AWS C Cloud Computer Science Cryptography Exploits Java Mobile security Network security Pentesting Perl Product security Python Reverse engineering Ruby SDLC Security assessment TCP/IP TLS

Perks/benefits: Career development Team events

Region: Asia/Pacific
Country: Australia
Job stats:  21  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.