Descrizione Lavoro
Security Engineer II, Vulnerability Management and Response - Strategic Enablement
Amazon Security's Vulnerability Management and Response - Strategic Enablement team is looking for a Security Engineer II. This team is revolutionizing vulnerability management through advanced remediation automation, innovative vulnerability detection solutions, and data‑driven insights. Be part of a dynamic group that bridges security operations and development, creating measurable impact across Amazon's vast ecosystem.
Key responsibilities
Develop and optimize security automation workflows to operationalize new capabilities, integrating with existing security tools and platforms across Amazon's infrastructure.
Design, script, and implement quick proof‑of‑concepts for vulnerability detection, assessment, and remediation across host and container environments, enabling rapid validation of new solutions.
Collaborate with TPMs and SDE teams to translate program requirements into technical specifications, ensure seamless integration with existing systems, and conduct user acceptance testing.
Build queries and analyze data to extract actionable insights on vulnerability management effectiveness, supporting data‑driven decision making and program improvements.
Conduct security research and analysis on emergent vulnerabilities to identify new threats and detection opportunities.
Mentor junior engineers and contribute to technical growth and knowledge sharing within the team.
A day in the life
Start your morning reviewing last night's vulnerability scan data and building SQL queries to analyze patterns across thousands of Amazon hosts. Collaborate with VMR Operations on technical specifications for a new container vulnerability detection pattern, then code Lambda scripts to integrate new capabilities with the workflow management platform. Mid‑day brings a design review with SDE teams to ensure custom detection logic scales seamlessly. Mentor a junior engineer on API integration techniques, and end the day testing your automation workflow and preparing actionable insights for tomorrow's leadership review.
About the team
The VMR Strategic Enablement team bridges security operations and development, transforming vulnerability data into measurable security outcomes. We embrace a "Think Fast, Learn Faster" culture where rapid prototyping validates new solutions and data drives every decision. Our diverse team of security engineers and TPMs collaborates across the full vulnerability lifecycle, building custom detection capabilities, operationalizing security programs, and creating metrics that demonstrate real impact across Amazon's infrastructure.
Basic Qualifications
3+ years of programming experience in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object‑oriented language.
Bachelor's degree in computer science or equivalent.
Knowledge of networking protocols such as HTTP, DNS, and TCP/IP.
Preferred Qualifications
2+ years of experience in threat modeling, secure coding, identity management, authentication, software development, cryptography, system administration, or network security.
Experience with AWS products and services.
Experience with programming languages such as Python, Java, C++.
Experience with data engineering concepts, including data pipelines, ETL processes, and working with large‑scale security datasets.
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job‑related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign‑on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits.
This position will remain posted until filled. Applicants should apply via our internal or external career site.
#J-18808-Ljbffr