In this role you provide guidance to the Alexa and Fire TV business and engineering teams on how to protect our customers and their data. Youll participate in feature and product designs review new and existing services and help engineering teams mitigate the risks. Youll also contribute to developing detection tools and promote security automation. Your goal is to discover the risks early when theyre easier and cheaper to address automating this discovery and mitigation whenever possible.
This role is primarily blue team defensive work but it helps to have a red team point of view sometimes.
Key job responsibilities
* Develop a relationship with the business teams to understand their products the risks and the mitigations that support their goals.
* Learn and teach the security policies best practices and paved paths.
* Review application architectures. The environment will typically be a Linuxbased OS running on AWS though sometimes on a device.
* Develop threat models
* Review security controls in code and cloud configurations
* Assist teams with mitigations through documentation and proof of concept demonstrations in code and configurations.
* Assist in developing automated detection software for both prelaunch and postlaunch risks.
* Assist in gathering metrics on the effectiveness of our security work
A day in the life
Whether you work in the Seattle area or Sunnyvale youll have other security engineers around to collaborate with on novel risks and to brainstorm fixes.
Youll occasionally be oncall routing some tickets to specialists while taking ownership of other issues raised by Alexa and Fire TV engineering privacy business and security teams. Your solutions will build trust with our customer teams diving deep and delivering practical mechanisms to reduce risk finding the best solution for each unique business.
Youll regularly meet with the product engineering teams to learn about their work and to help them adopt security best practices.
3 years of programming in Python Ruby Go Swift Java .Net C or similar object oriented language experience
Bachelors degree in computer science or equivalent
Knowledge of networking protocols such as HTTP DNS and TCP/IP
2 years of any combination of the following: threat modeling experience secure coding identity management and authentication software development cryptography system administration and network security experience
Experience with AWS products and services
Experience with programming languages such as Python Java C
Knowledge of system security vulnerabilities and remediation techniques including penetration testing and the development of exploits or equivalent
Experience with streaming protocols including STUN TURN RTSP RTMP HLS WebRTC MQTT and WebSockets
Experience with Android OS security controls.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status disability or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees supervisors and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees supervisors and staff to ensure exceptional customer service; and follow all federal state and local laws and Company policies. Criminal history may have a direct adverse and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above as well as the abilities to adhere to company policies exercise sound judgment effectively manage stress and work safely and respectfully with others exhibit trustworthiness and professionalism and safeguard business operations and the Companys reputation. Pursuant to the Los Angeles County Fair Chance Ordinance we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process including support for the interview or onboarding process please visit
for more information. If the country/region youre applying in isnt listed please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136000/year in our lowest geographic market up to $212800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on jobrelated knowledge skills and experience. Amazon is a total compensation company. Dependent on the position offered equity signon payments and other forms of compensation may be provided as part of a total compensation package in addition to a full range of medical financial and/or other benefits. For more information please visit This position will remain posted until filled. Applicants should apply via our internal or external career site.