Senior Security Engineer, Application Security Testing Automation | New York |

2 months ago


New York, United States Amazon.com Services LLC Full time
As a member of the Application Security Testing Automation team, you will help provide automated security testing solutions for all of Amazon. Our team’s goal is to empower both development and security teams with accurate security detections at the highest standards of quality in order to identify and eliminate risk across Amazon’s application portfolio.

As a Senior Security Engineer on our team, you will solve interesting security challenges that arise when Amazon invents new technologies. You will lead the team to prototype and build tools that enable developers to understand their vulnerabilities and how to effectively mitigate them. You will identify and apply opportunities to build new security services, improve existing ones and update our standards and documentation to have the widest possible impact for our customers. You will work proactively and autonomously with partner orgs to develop advanced security detection capabilities to solve complex Application Security challenges at scale.

You will lead by example, proactively improve the consistency of team processes, and help guide the technical direction of the team. Be active mentor for all team members and act as the voice for the team. You will work independently across multiple teams and organizations, build consensus on the direction of security automation and inform decisions made by senior security leaders. This role will routinely challenge your technical background and critical thinking. You will be expected to collaborate with our team’s stakeholders in a fast-paced environment across many technology stacks and services to deliver scalable solutions.

Acceptable office locations:
New York, NY

Key job responsibilities
- Define and drive strategy, act as a technical lead for the team
- Develop, curate, and improve application security detections (static and dynamic) to identify vulnerabilities in Web applications and Application Programming Interface (API) at scale
- Drive security tool evaluation, development and deployment
- Perform dynamic and static application security assessments to ensure the highest quality standard for our detection development and release process
- Risk assessment and Threat Modeling
- Develop, enhance, and interpret security standards and guidance
- Demonstrate and promote security best practices, drive improvements of Amazon’s overall security architecture

A day in the life
- Educate developers on security issue remediation and best practices
- Researching prevalent vulnerabilities with other security teams
- Collaborate with multiple stakeholders to collectively raise the security posture of Amazon
- Review code, running endpoints, APIs, and other platforms to identify security issues
- Presenting findings and discussing security risk with technical and non-technical stakeholders
- Reporting on automation breadth and depth metrics while improving internal processes
- Use technical depth to provide wide coverage for the team and also be able to deep dive into specific work areas to help unblock other team members

About the team
Our team's vision is to eliminate security threats from entering the production landscape of Amazon developed applications. We strive to reduce manual security testing efforts through automation across all web and API application portfolio and inject continuous non-disruptive security testing methodologies across Amazon's SDLC phases to provide service owners actionable and useful security feedback.

About Amazon Security

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

BASIC QUALIFICATIONS

- Bachelor's degree
- Broad and deep knowledge across application security domains
- 8+ years of Application Security or Development experience
- Experience with the application of threat modeling or other risk identification techniques.
- Scripting skills (e.g., python, java)

PREFERRED QUALIFICATIONS

- MS in Computer Science or Cybersecurity
- Development experience in Python and/or Java.
- Secure software development lifecycle experience.
- Knowledge of distributed systems and security protocols.



  • New York, New York, United States Winfield Security Full time

    Winfield Security has been a trusted provider of security solutions for over 45 years and is now a proud member of the Tarian Group of Security Companies. Our operations are centered in Midtown Manhattan, delivering unarmed security services to a diverse clientele across New York City. We offer our officers competitive compensation, comprehensive training,...


  • New York, New York, United States Amazon Services LLC Full time

    About the RoleWe are seeking a highly skilled Senior Cybersecurity Engineer to join our Application Security Testing Automation team at Amazon Services LLC. As a key member of our team, you will play a critical role in providing automated security testing solutions for all of Amazon.Key ResponsibilitiesDefine and Drive Strategy: Act as a technical lead for...


  • Rome, New York, United States Advanced Automation Corporation Full time

    Job DescriptionJob Title: Senior Linux Security EngineerJob Summary:Advanced Automation Corporation is seeking a highly skilled Senior Linux Security Engineer to join our team. As a key member of our security team, you will be responsible for designing, implementing, and maintaining the security of our Linux-based systems.Key Responsibilities:Collaborate...


  • New York, New York, United States Amazon Services LLC Full time

    About the RoleWe are seeking a highly skilled Senior Cybersecurity Engineer to join our Application Security Testing Automation team at Amazon Services LLC. As a key member of our team, you will play a critical role in providing automated security testing solutions for all of Amazon.Key ResponsibilitiesDefine and Drive Strategy: Act as a technical lead for...


  • New York, New York, United States FanDuel Full time

    ABOUT FANDUELFanDuel Group is a pioneering sports-tech entertainment enterprise that is transforming the way fans engage with their beloved sports, teams, and leagues. As the leading gaming platform in the United States, FanDuel encompasses a diverse portfolio of prominent brands across gaming, sports wagering, daily fantasy sports, advance-deposit betting,...


  • New York, United States Copia Automation Full time

    Who you are We are seeking a Senior Field Applications Engineer to support the implementation of Copia’s DeviceLink product in industrial automation settings, including discrete manufacturing and material handling. This role is part of our Strategy and Operations team, partnering with sales and customer success to accelerate time to value for our...


  • New York, United States Info Way Solutions Full time

    Job Title: Senior Security EngineerLocation: New York, NY (Multiple Locations Available)Required Qualifications:• Experience: 5+ years of experience in information security, with a focus on security engineering, threat detection, and incident response.• Technical Skills:o Strong knowledge of security principles, practices, and tools.o Experience with...


  • New York, New York, United States SoFi Full time

    Employee Applicant Privacy Notice Who we are:Shape a brighter financial future with us.Together with our members, we're changing the way people think about and interact with personal finance.We're a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The...


  • New York, New York, United States Yoh Full time

    About the RoleWe are seeking a highly skilled Senior Security Engineer to join our IT Security Team at Yoh, a Day & Zimmermann company. This pivotal role entails close collaboration with the Site Reliability Engineering (SRE), Network, and Operations teams aimed at elevating our security posture.Key ResponsibilitiesCollaborate with cross-functional teams to...


  • New York, United States Celonis Full time

    The Team:Our Global information security organization is responsible for security and trust. We think security-offensively and defensively. We continuously monitor our global security posture and are always adapting to the ever-changing threat landscape. The security engineering team is looking for talented subject matter experts in application, platform and...


  • New York, United States AI Start-Up Full time

    About The RoleWe're working with a leading AI firm who are seeking a Senior Security Engineer to protect its advanced AI products. This role involves designing, implementing, and maintaining security measures to secure the company's systems, data, and users. The Senior Security Engineer will collaborate closely with the engineering and operations teams to...


  • New York, United States SSH Communications Security Full time

    Job DescriptionJob DescriptionSSH Communications Security is a European defensive cybersecurity company and a pioneer of secure communications. Our solutions gatekeep access and defend secrets when people, applications and systems need to communicate. Our technology is used in more than 90% of data centers around the world, and is trusted by many Fortune...


  • New York, United States The Rockridge Group Full time

    Job DescriptionJob DescriptionJob Title: Sr. Security EngineerDuration: 6 months Contract To HireLocation: Looking for someone near our physical NY office (NYC) and datacenter (Weehawken, NJ) who could support on-site physical equipment (powering off a firewall, checking cable connectivity, shipping equipment, configuring equipment that is not remotely...


  • New York, United States The Rockridge Group Full time

    Job DescriptionJob DescriptionJob Title: Sr. Security EngineerDuration: 6 months Contract To HireLocation: Looking for someone near our physical NY office (NYC) and datacenter (Weehawken, NJ) who could support on-site physical equipment (powering off a firewall, checking cable connectivity, shipping equipment, configuring equipment that is not remotely...


  • New York, United States Trilogy International Full time

    Role: Senior Security EngineerLocation: New York - Hybrid on-site modelMy client is looking to make their first hire within security to help protect the platform as they scale. This is a very important role and will give you the chance to work with the leadership, software and product team closely in their office.Some of the responsibilities will be:Security...


  • New York, New York, United States New York State Full time

    **Job Summary**The New York State Attorney General's Office is seeking an experienced Labor Attorney to join the Employment Security Section in the Labor Bureau. As a key member of the team, you will be responsible for defending against state and federal court challenges to the New York State Department of Labor's enforcement of labor laws.**Key...

  • Security Officer

    4 days ago


    New York, New York, United States Winfield Security Full time

    **About Winfield Security**Winfield Security is a leading provider of security services, boasting over 45 years of experience in delivering exceptional security solutions to clients across New York City.**Job Summary**We are seeking highly motivated and dedicated Security Guards to join our team. As a Security Guard, you will be responsible for providing...


  • New York, United States Motion Recruitment Full time

    Our client, a leading privately held biochemistry research company in New York City, is seeking a Founding Security Engineer to join their team. This fulltime hybrid role offers competitive compensation, generous benefits, and the opportunity to make an impact in the industry. As a Founding Security Engineer, you will play a crucial role in leading and...

  • Security Officer

    4 days ago


    New York, New York, United States Winfield Security Full time

    **About Winfield Security**We are a leading provider of security services, dedicated to delivering exceptional protection solutions to our clients. With over 45 years of experience, we have established ourselves as a trusted partner in the security industry.**Job Summary**We are seeking highly motivated and dedicated individuals to join our team as Security...


  • New York, United States RightTalents LLC Full time

    Title: Application Security Engineer Client: NYC Agency Location: Manhattan, NY - Hybrid. 3days onsite / 2 days remote Duration: 12 Months Work Hours: 35 Hours/ week (7hrs a day) Job description Work with product development, management, engineering and operational teams to develop best of breed security architectures supporting compliance (e.g. NYC...