> Markdown version of [/jobs/ext/2038154-security-engineer-ii-stores-application-security](https://www.wearedevelopers.com/jobs/ext/2038154-security-engineer-ii-stores-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer II, Stores Application Security - **Company:** Amazon.com, Inc. - **Location:** New York, NY, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), .NET Framework, C++ (Programming Language), Code Review, Cyber Security, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Python (Programming Language), Ruby, Secure Coding, Transmission Control Protocol (TCP), Software Security, Swift (Programming Language), Golang - **Published:** August 12, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/security-engineer-ii-stores-application-security-new-york-ny-usa-58914856 ## About the Role to 0 apps * Collaborate with Ring 0 builder teams to integrate security guidance into workflows * Develop and maintain security documentation (threat models, risk assessments, guidelines) * Support security incident investigations related to Ring 0 systems * Perform manual and automated secure code reviews (Java, Python, JavaScript) * Identify and mitigate security issues at scale * Conduct adversarial security analysis * Provide security guidance to internal teams, stakeholders, and leaders * Independently solve complex security problems Tasks * 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar * Bachelor's degree in STEM or IT security experience * Knowledge of HTTP, DNS, TCP/IP networking * Knowledge of security vulnerabilities and remediation techniques * Experience with troubleshooting, logs, or automation via command line tools * Ability to explain complex technical risks clearly to non-technical audiences Key requirements * flexible work hours * health insurance * 401(k) matching * RSUs * paid time off * parential leave ## Description Experteer Overview As a Security Engineer at Amazon Security, you help keep customer trust by embedding secure practices into high-impact services across Ring 0 applications. You will collaborate with development teams to design proactive security controls, build scalable tooling, and lead risk-based decisions. You'll translate complex risks for technical and non-technical stakeholders while guiding partners toward secure solutions. This role offers involvement across a broad security landscape, from code reviews to threat modeling, in a fast-paced, impact-driven environment. Compensation / Benefits * Define and drive proactive security controls for Ring 0 applications * Evaluate and implement security controls to ensure secure defaults for Ring 0 developers * Assess and mitigate security risks across projects * Build and drive adoption of security tooling (threat modeling, code scanning, test generation) * Promote security guardrails, testing frameworks, and monitoring across Ring 0 apps * Collaborate with Ring 0 builder teams to integrate security guidance into workflows * Develop and maintain security documentation (threat models, risk assessments, guidelines) * Support security incident investigations related to Ring 0 systems * Perform manual and automated secure code reviews (Java, Python, JavaScript) * Identify and mitigate security issues at scale * Conduct adversarial security analysis * Provide security guidance to internal teams, stakeholders, and leaders * Independently solve complex security problems Tasks * 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar * Bachelor's degree in STEM or IT security experience * Knowledge of HTTP, DNS, TCP/IP networking * Knowledge of security vulnerabilities and remediation techniques * Experience with troubleshooting, logs, or automation via command line tools * Ability to explain complex technical risks clearly to non-technical audiences Key requirements * flexible work hours * health insurance * 401(k) matching * RSUs * paid time off * parential leave ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Stranger Danger: Your Java Attack Surface Just Got Bigger](https://www.wearedevelopers.com/videos/346-stranger-danger-your-java-attack-surface-just-got-bigger) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)