Security Engineer, AWS Security Hub, Security...

Amazon.com, Inc.
New York, NY, United States
21 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$159,300.0 - $212,800.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) .NET Framework Amazon Web Services User Authentication Microsoft Azure C++ (Programming Language) Command-Line Interface Code Review Cyber Security Computer Programming Domain Name System (DNS) Hypertext Transfer Protocols (HTTP)
+21 more
HTTP Secure Identity and Access Management Python (Programming Language) Network Security Network Protocols Object-Oriented Software Development Systems Development Life Cycle Cloud Services Ruby Secure Coding Software Engineering TCP/IP Scripting Google Cloud Multi-Cloud Swift (Programming Language) Information Technology Opsworks CIS Benchmarks Golang Programming Languages

Job description

The AWS Security Hub team is looking for a passionate and innovative security engineer with a focus on compliance and security best practices for AWS, Azure, and GCP services. AWS Security Hub is the security and compliance center for AWS customers. One of its main functions is conducting automated checks against cloud security best practices, industry standards, and regulatory frameworks. The person joining Security Hub in this position will lead the effort to define security best practices across AWS, Microsoft Azure, and Google Cloud Platform, including implementation of security controls to assess compliance, remediations to respond to non-compliant events, and mappings to industry standards and regulatory frameworks such as CIS Benchmarks for AWS, Azure, and GCP.

The successful candidate is one who has experience defining technical requirements for compliance and security best practices across multiple cloud providers. You should be comfortable looking at a cloud service - whether AWS, Azure, or GCP - and identifying what security controls should be in place to help customers be confident that they are using that service in a secure way. You should be comfortable developing requirements that developers can utilize to translate security controls into automated checks and remediation procedures. You should also be comfortable implementing automated checks in Python or a supported language, including developing multi-cloud controls that evaluate Azure and GCP resource configurations through AWS Config.

A key aspect of this job is the ability to earn trust with large network of stakeholders: AWS service owners, security expects in our solution architecture and consulting teams, Security Hub’s development team, and, most importantly, our customers. In addition to being a technical expert in security best practices and compliance, you will be a leading voice in the effort to raise the bar for security and compliance across AWS.

Our team also puts a high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren’t focused on

how many hours you spend at work or online. Instead, we’re happy to offer a flexible schedule so you can have a more productive and well-balanced life-both in and outside of work.

Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. Our senior members enjoy one-on-one mentoring and thorough, but kind, code reviews. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded engineer and enable them to take on more complex tasks in the future.

Requirements

3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience

  • 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience

  • 2+ years of troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship) experience

  • Bachelor’s degree in computer science or equivalent

  • Bachelor’s degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security

  • Bachelor’s degree in a STEM field (Science, Technology, Engineering, Mathematics), or 2+ years of IT Security experience

  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP

  • Knowledge of industry-based security vulnerabilities and remediation techniques

  • Experience in scripting, programming, and security code reviewing in a common programming language (non-internship)

  • Experience in troubleshooting systems issues, analyzing logs, or automating basic tasks using command line tools (non-internship experience)

Preferred Qualifications

  • 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience

  • 2+ years of scripting, programming, or security code review in a common language, such as Python, Java or C++ experience

  • Knowledge of command line tools to troubleshoot protocols, analyze log outputs, or automate basic tasks

  • Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP

  • Knowledge of networking protocols, to include HTTP(S), DNS, and TCP/IP

  • Experience with AWS products and services

  • Experience with programming languages such as Python, Java, C+- Experience in scripting, programming, or security code reviewing in a common language, such as Python, Java, or C+- Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing

Benefits & conditions

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits .

USA, NY, New York - 159,300.00 - 212,800.00 USD annually

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:08 min

Building solutions with open source GoLang infrastructure tools

Jad Wahab · LIVE

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

6:16 min

Event-driven Golang backend architecture and cloud deployment

Irina Branovic Irina Branovic · World Congress 2026 Europe

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

Videos

See all

Related articles

See all