> Markdown version of [/jobs/ext/1687869-security-engineer-amsec](https://www.wearedevelopers.com/jobs/ext/1687869-security-engineer-amsec). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, AmSec - **Company:** Amazon.com, Inc. - **Location:** Seattle, WA, United States - **Experience:** Experienced - **Salary:** $159,300.0 - $202,400.0 - **Contract:** Internship / Graduate position - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Command-Line Interface, Code Review, Customer Data Management, Systems Development Life Cycle, Software Tools, Secure Coding, Software Engineering, Data Streaming, Systems Integration, Scripting, CIS Benchmarks, Programming Languages - **Published:** July 16, 2026 - **Apply:** https://www.juju.com/job/00000000ggwcvs ## About the Role Amazon Security is seeking a Security Engineer who thrives in ambiguity and is motivated to build scalable security solutions. The Secure Third Party Tools (S3T) team has bold ambitions to redefine how Amazon protects customer trust across all third-party interactions - shifting from reactive assessments to proactive, automated protection at global scale. Security Engineers are integral to this mission, combining deep technical review expertise with a builder's mindset to influence the AI-powered tooling that scales our impact. They must demonstrate excellent written and verbal communication skills, strong ownership on review engagements, integrating GenAI to improve operationally efficiency, and solid understanding of vendor security risk and effective controls., 3+ years of scripting, programming, and security code review in a common programming language (non-internship) experience, Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks - Experience with AWS products and services - Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing - Experience in identifying security risks in AI applications - Experience in using or developing AI tooling for risk assessment and enabling organizations to make security decisions - 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience ## Description * Perform technical deep-dive security reviews of third-party services across diverse and ambiguous use cases, including AI/ML integrations, cloud architectures, and services handling sensitive customer data * Identify and trace data flows through complex systems, evaluating where security controls are lacking or require supplementation * Evaluate vendor penetration test reports, assessing finding applicability and severity within the context of each engagement * Threat model third-party use cases to rapidly surface sharp edges and drive risk-proportionate decisions * Influence and contribute to AI-powered security tooling that automates and scales review decisions across the organization * Clearly communicate identified risks and recommendations to service teams and leadership, driving resolution through escalation when needed * Author and improve security baselines, decision rubrics, and implementation patterns for novel third-party use cases A day in the life Security Engineers work backwards from customer risk to identify what matters most in a third-party engagement - there is no checklist. You'll apply threat modeling, architecture analysis, and enterprise security control knowledge to bottom out on key risks quickly, then translate findings into clear, actionable guidance. When barriers arise, you focus on solutions: scripting, leveraging AI tools, and codifying decisions in S3T tooling so the next review is faster and more accur. About the team Security is central to maintaining customer trust and delivering delightful customer experiences. Our vision is that Builders raise the Amazon security bar when they use our recommended tools and processes, with no overhead to their business. S3T scales through software, not people - using high-judgment engineers to codify security decisions into automation that protects Amazon customers worldwide. ## Related Videos - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [GenAI Is a Junior Dev With Root Access](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) ## Related Articles - [What is Software Engineering in the Age of AI?](https://www.wearedevelopers.com/magazine/640-what-is-software-engineering-in-the-age-of-ai) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)