> Markdown version of [/jobs/ext/2258683-security-engineer-aws-security](https://www.wearedevelopers.com/jobs/ext/2258683-security-engineer-aws-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, AWS Security - **Company:** Amazon.com, Inc - **Location:** Greater London, UK - **Contract:** Internship / Graduate position - **Skills:** C (Programming Language), Java (Programming Language), Amazon Web Services, Software System Penetration Testing, User Authentication, Bash Shell, C++ (Programming Language), Cloud Computing Security, Code Review, Cyber Security, Web Development, Perl (Programming Language), Internet Protocol Security (IP SEC), Python (Programming Language), Network Security, Public Key Infrastructure, Windows PowerShell, Ruby, Secure Coding, Service Design, Mobile Security, Scripting, Transport Layer Security, Software Security, Malware, Cyber Threat Analysis, Information Technology, IoT Security, Vulnerability Analysis - **Published:** August 26, 2026 - **Apply:** https://www.collegerecruiter.com/job/2815090397-security-engineer-aws-security ## About the Role * Experience with web protocols, common security attacks, and remediation (non-internship). * Bachelor's degree or above in Computer Science, Engineering, or related fields. * Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent. * Experience in application security architecture, security code reviews, security testing, incident response, or security infrastructure. * Experience with coding/scripting in one or more languages (e.g., Python, C, C++, Java, Ruby, or PowerShell)., * Experience with AWS services or other cloud offerings. * Experience in one or more of the following: application security frameworks, security code reviews, incident response, security infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls. * Knowledge of one or more of the following domains: web application development, penetration testing, mobile security, cryptography, public key infrastructure, forensic security, IP security, SSL/TLS, computer viruses and malware, network security, trusted security, trusted execution, threat intelligence, IoT security implications, or authentication. * Experience scripting with Python, Perl, Bash or PowerShell. * Experience triaging and developing security alerts and response automation, conducting front-line analysis, and providing escalation support. ## Description Job ID: 10466310 | Amazon Development Centre (London) Limited The AppSec Security Engineer evaluates service design and architecture and performs deep-dive security assessments to ensure applications and services meet a high security bar before launch. This role works alongside senior engineers to identify issues, drive remediation, and validate that security requirements are met. Key job responsibilities * Security Reviews: Conduct design reviews for new and existing services, evaluating architecture documents and system designs for security risks. * Threat Modelling: Identify attack vectors and security weaknesses in application architectures through structured threat-modelling exercises. * Penetration Testing: Coordinate penetration testing to validate security controls and identify exploitable vulnerabilities. * Finding Management: Document, track, and communicate security findings to service teams with clear remediation guidance, and verify fixes are implemented. * Security Guidance: Advise development teams on secure coding practices, authentication/authorization mechanisms, cryptographic implementations, and data protection strategies. * Escalation Support: Identify and elevate high-severity issues through appropriate channels, ensuring timely remediation aligned with launch timelines. * Documentation: Maintain clear documentation of review outcomes, security decisions, and risk assessments. * Tool Improvements: Leverage automated tools to support reviews and improve efficiency. Basic Qualifications * Experience with web protocols, common security attacks, and remediation (non-internship). * Bachelor's degree or above in Computer Science, Engineering, or related fields. * Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent. * Experience in application security architecture, security code reviews, security testing, incident response, or security infrastructure. * Experience with coding/scripting in one or more languages (e.g., Python, C, C++, Java, Ruby, or PowerShell). Preferred Qualifications * Experience with AWS services or other cloud offerings. * Experience in one or more of the following: application security frameworks, security code reviews, incident response, security infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls. * Knowledge of one or more of the following domains: web application development, penetration testing, mobile security, cryptography, public key infrastructure, forensic security, IP security, SSL/TLS, computer viruses and malware, network security, trusted security, trusted execution, threat intelligence, IoT security implications, or authentication. * Experience scripting with Python, Perl, Bash or PowerShell. * Experience triaging and developing security alerts and response automation, conducting front-line analysis, and providing escalation support. Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers)