Jobs / Ama***
Senior Security Engineer, AWS Human Access Security
Ama*** · Arlington, VA, United States
Visa sponsorship details are locked. Unlock company name and apply link with .
Arlington, VA, United States178,400-226,700 USD/yearlyRemote
Remuneration
178,400-226,700 USD/yearly
Location
Arlington, VA, United States
Visa sponsorship
Sponsors visa
Job summary
DESCRIPTION AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds — tooling that engineers across AWS depend on to request, scope, and audit their access.
Benefits
Learn more about ourAt https://amazon.jobs/en/USA, VA, Arlington - 178,400.00 - 226,700.00 USD annually
Qualifications
- 5+ years of non-internship background in troubleshooting systems issues, analyzing logs, or automating complex tasks using command line
- Experience applying threat modeling or other risk identification techniques or equivalent
- Experience with security in service-oriented architectures/microservices and web services
- Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
- Our inclusive culture empowers Amazonians to deliver the best results for our customers.
- If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
- The base salary range for this position is listed below.
- Your Amazon package will include sign-on payments and restricted stock units (RSUs).
- Final compensation will be determined based on factors including experience,
- and location.
- Amazon also offers comprehensive
Responsibilities
- Define what counts as high-risk human access to production systems and the data they hold.
- You identify the access patterns (standing credentials, broad emergency access, unscoped remote sessions, unreviewed privilege elevation) that carry the greatest risk, and you rank them with data rather than opinion.
- Partner with engineering teams across the organization to reduce risky access.
- You turn your risk model into concrete remediation, negotiate adoption, and measure the reduction over time.
- Build the measurement and detection capabilities that show where risky access exists and whether it is trending down, and use that data to prioritize the work.
- Investigate security issues involving human access and turn each one into a durable improvement in the tooling or the risk model, not a one-off fix.
- Mentor software and security engineers, raise the bar through design and code review, and represent your team's security posture to leadership and partner teams.
- A day in the life
- Most days come down to one question: who can reach critical production systems, and how do we make that access safer?
- You dig into the data, find the access patterns that carry the most risk, and decide what to tackle first.
- Then the part that matters most: you take each finding to the software engineers you work with and build the fix into the tooling, so the identification becomes automatic instead of something you teams have to discover.
- You'll also win over teams across the company to build
Skills
Leadership
Degrees
Associate
Industry
AutomotiveEnergyHealthcareInsuranceMediaRetail
Company size
Smb