Senior Security Engineer, Proactive Security
Listed on 2026-06-13
-
IT/Tech
Cybersecurity, Systems Engineer, Security Management & Operations
The Senior Security Engineer is a senior individual contributor responsible for independently driving security initiatives across multiple services and teams. This role requires deep technical expertise in application security, threat modeling, and secure system design, combined with the ability to influence engineering teams and deliver high-impact security outcomes with minimal guidance.
Key Job Responsibilities- Lead end-to-end security reviews for complex, high-priority services including design reviews, threat modeling, and penetration testing scoping and readout.
- Serve as a subject matter expert for assigned affinity teams, providing architectural guidance and security consultation throughout the development lifecycle.
- Independently perform and guide threat modeling exercises for complex distributed systems, identifying risks and recommending mitigations.
- Conduct targeted manual code reviews of security‑critical components, identifying vulnerabilities and insecure patterns that automated tools miss.
- Scope, coordinate, and oversee penetration testing engagements; analyze results and drive remediation with service teams.
- Identify, document, and track security findings to resolution; elevate critical issues to leadership when appropriate.
- Mentor junior engineers, contribute to team processes and tooling improvements, and raise the security bar across the organization.
- Design and build security automation, tooling, and processes that improve operational efficiency and scale the team's impact.
- Leverage generative AI and machine learning to build intelligent security automations that streamline review workflows, enhance vulnerability detection, and reduce manual toil.
- Partner with service teams to improve security posture proactively, including developing self‑service guidance, documentation, and readiness frameworks.
- Define and track security metrics that measure risk reduction, operational efficiency, and builder experience improvements.
- 4+ years of experience troubleshooting systems issues, analyzing logs, or automating complex tasks using command line tools.
- 5+ years of experience identifying security issues and risks, and developing mitigation plans.
- 4+ years of programming and security code review in common languages.
- Knowledge of at least two of the following languages:
Scala, Java, Python, C/C++, or Go. - Experience as a mentor, tech lead, or in leading an engineering team.
- Experience applying threat modeling or other risk identification techniques or equivalent.
- Experience with security in service‑oriented architectures/microservices and web services.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, please visit (Use the "Apply for this Job" box below). for more information.
The base salary range for this position is listed below. Your Amazon package will include sign‑on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, basic life & AD&D insurance and option for supplemental life plans, EAP, mental health support, medical advice line, flexible spending accounts, adoption and surrogacy reimbursement coverage), 401(k) matching, paid time off, and parental leave.
USA, WA, Seattle - - USD annually
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).