Application Security Engineer, Buy With Prime
Singapore, SGP
Amazon.com
Free shipping on millions of items. Get the best of Shopping and Entertainment with Prime. Enjoy low prices and great deals on the largest selection of everyday essentials and other products, including fashion, home, beauty, electronics, Alexa...This role will provide career growth opportunities as you gain new security skills in the course of your work. Security engineers at Amazon have an opportunity to experiment, learn, build tools, and work with teams building new technology and services at massive scale.
A successful candidate will need a combination of troubleshooting, technical, and communication skills. An Application Security Engineer must have the ability to take ownership and deliver on multiple complex objectives which may include project and software development work.
Key job responsibilities
- Lead security projects with end-to-end ownership, including security reviews (including threat modelling, secure design and implementation of security controls), tool development, and creation of new security practices
- Influence decision-makers and stakeholders throughout the organization in multiple teams to achieve a consistently high security bar
- Develop security tools and automation
- Develop and deliver security training or knowledge sharing to internal development teams
- Create security guidance and documentation
- Support the development and improvement of metrics that drive desired behavior and security outcomes
- Support penetration testing engagements and work with software teams to remediate findings
- Support for mentoring, team building and recruiting activities
About the team
Our team is geographically dispersed, with members across Australia and North America. We thrive on both autonomy and collaboration. We’re flexible in how we approach work and always seek to improve things, no matter how small they may first appear to be. We hold a high bar in everything we do. We embrace challenges and always do right by our customers, even if it’s the difficult thing to do. We’re dedicated to supporting new members, with a broad mix of experience levels and tenures, and we’re fostering an environment that celebrates knowledge sharing and mentorship. Our team primarily focuses on supporting the Buy with Prime product.
Buy with Prime is helping people re-imagine the way they shop... wherever they do! Our vision is to enable every entrepreneur in the world to reach every customer in the world through every channel they can imagine. Buy with Prime is a new way to extend Prime shopping benefits—including fast, free shipping, a seamless checkout experience, and free returns—to merchants’ own online stores, ultimately increasing selection for Prime members. For over 20 years, Amazon been empowering small and medium-sized businesses with opportunities to grow. Buy with Prime is an exciting next step in our mission to help merchants of all sizes grow their business—whether on Amazon or beyond.
We are open to hiring candidates to work out of one of the following locations:
Singapore, SGP
Basic Qualifications
- Bachelor (undergraduate) degree in a relevant field (Computer Science, Software Engineer, Security, or others) OR an equivalent combination of education, training, and experience
- Minimum of 5 years of professional experience either in, or working closely with application security.
- Minimum 4 years of experience with any combination of at least 2 technical disciplines, including the following: code review, cloud security, network security, application security, mobile security, secure development methodologies, software development and coding, identity management, application penetration testing, authentication and authorization, network architecture, system administration, and systems engineering
- Experience with building or reviewing threat models
- Experience defining security controls with product/service teams
- Experience with one or more programming languages (such as Java, Python, etc) for the purpose of code review
Preferred Qualifications
- Professional experience conducting security assessments, including penetration testing- Ability to lead through influence within the software development life-cycle for multiple products and technologies, meeting customer expectations for security
- Experience implementing security solutions that resolve security and business risk trade-offs
- An understanding of networking and communication protocols (such as TCP/IP, UDP, SSL/TLS, IPSEC, HTTP, HTTPS, BGP)
- An understanding of cryptography, web service frameworks, mobile application architectures, and service architectures (such as event-driven, service-oriented, or serverless architectures)
- Familiarity with reverse engineering or vulnerability research
- Professional experience with applied cryptography
- Familiarity with infrastructure or hardware security
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Automation Cloud Computer Science Cryptography Java Mobile security Network security Pentesting Python Reverse engineering SDLC Security assessment TCP/IP TLS
Perks/benefits: Career development Flex hours Team events
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open SOC Analyst jobs
- Open Consultant SOC / CERT H/F jobs
- Open IT Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Senior Information Security Analyst jobs
- Open Senior Information Security Engineer jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open Ingénieur DevSecops H/F jobs
- Open Chief Information Security Officer jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open Staff Security Engineer jobs
- Open Information Security Officer jobs
- Open Cybersecurity Consultant jobs
- Open Security Operations Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Senior Security Architect jobs
- Open o365 Security Architect jobs
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Senior Cyber Security Engineer jobs
- Open Staff Product Security Engineer jobs
- Open Senior Security Analyst jobs
- Open Principal Security Engineer jobs
- Open Product Security Engineer jobs
- Open Senior SOC Analyst jobs
- Open Cyber Security Architect jobs
- Open GCP-related jobs
- Open SOC-related jobs
- Open Risk assessment-related jobs
- Open Governance-related jobs
- Open Network security-related jobs
- Open Pentesting-related jobs
- Open CISM-related jobs
- Open ISO 27001-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open Threat intelligence-related jobs
- Open IAM-related jobs
- Open Malware-related jobs
- Open Java-related jobs
- Open CISA-related jobs
- Open Security Clearance-related jobs
- Open Vulnerability management-related jobs
- Open Kubernetes-related jobs
- Open DevOps-related jobs
- Open APIs-related jobs
- Open Security assessment-related jobs
- Open Forensics-related jobs
- Open SQL-related jobs
- Open CI/CD-related jobs
- Open Splunk-related jobs