Recherche d'emploi > Toronto, ON > Application engineer

Senior Application Security Engineer, Wwcs Application Security

Amazon
Toronto, ON
170K $-215K $ / an (estimé)
Temps plein

DESCRIPTION

This role can be in Seattle, Austin, Nashville, Arlington, or Toronto

Amazon is seeking a talented and seasoned Senior Applications Security Engineer to focus on securing the ecosystem that powers Amazon Customer Service (CS).

CS is one of the largest customer service organizations in the world. Our business operations include tens of thousands of Customer Service Associates around the globe who provide world-class support to customers 24 hours a day, 7 days a week, and in over 15 languages (and growing).

This position will provide you with a challenging opportunity to solve difficult security problems at planetary scale. As a senior security engineer, you will help define short-term and long-term security strategy.

You will balance your efforts between strategic and operational deliverables. You will have the opportunity to work with talented engineering teams within Amazon to ensure applications are designed and built securely.

You care deeply about keeping Amazon customers secure and therefore are passionate about finding, and mitigating vulnerabilities / risks by providing actionable guidance to product teams and drive long term security improvements.

You're well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization (technical and non-technical).

The successful candidate must be autonomous, comfortable operating in highly ambiguous situations, and must deliver results in a fast-paced environment.

Your responsibilities will include :

  • Perform security reviews including secure design and architecture, threat modeling, threat assessments, secure code reviews, security testing, and security certifications
  • Identify security gaps in applications, services, and products including internally developed, as well as third party solutions
  • Determine findings criticality taking into account the relevant business, technical, and threat environment
  • Produce reports that describes the work perform for a variety of audiences including technical and non-technical stakeholders
  • Communicate findings to relevant stakeholders through a combination of verbal and written reports. Identify owners, and drive mitigation of findings within established SLAs
  • Record findings and supporting evidence, work product, and testing results following established policies and procedures
  • Design, develop, deploy, and maintain security automation, secure-by-default solutions, and other solutions that will enable developer and security engineering productivity using scripting or programming languages
  • Develop a broad and deep technical understanding of the services, architectures, and products pertaining to the Customer Service organization
  • Contribute to the long-term and short-term security strategy to ensure that applications are designed and built securely
  • Comfortably transition between big picture, strategic thinking and tactical, day-to-day operational execution
  • Review technical solutions to provide guidance to help mitigate security vulnerabilities as well as provide actionable long-term and short-term risk mitigation recommendations
  • Improve secure software development life-cycle (SSDLC) practices across multiple organizations in Amazon
  • Influence decision-makers and stakeholders to achieve a consistently high security bar
  • Create relevant documentation, security guidance, and metrics to report to your stakeholders and business leaders and deliver these in a clear, concise manner
  • Lead security initiatives with end-to-end ownership
  • Participate in security escalations support including on-call rotation
  • Evaluate and recommend new and emerging security products and technologies
  • Support for mentoring, team building, recruiting activities, onboarding of new team members
  • Own and carry out new, reoccurring, or ad-hoc security engineering projects and consultations
  • Deliver practical security solutions providing the most customer-centric experience on the planet
  • Must be a kind human who enjoys working in a fun team

We are open to hiring candidates to work out of one of the following locations :

Toronto, ON, CAN

BASIC QUALIFICATIONS

  • BS in Computer Science, Information Security, or equivalent professional experience
  • 8+ years of experience in application security, product security, or systems security
  • 5+ years writing production-level code in at least one scripting or compiled language such as Java, Python, JavaScript, Go, Ruby, C# or C / C++
  • Proven experience in threat modeling, code reviews, security testing, vulnerability detection, attacker exploit techniques, and methods for their remediation.
  • 5+ years of experience securing cloud services such as AWS, Azure, and Google Cloud

PREFERRED QUALIFICATIONS

  • Master's degree in Computer Science, Information Security, Computer Engineering, Electrical Engineering or equivalent
  • Relevant industry certifications from SANS, GIAC, CISSP, OSCP, etc.
  • 3+ years of software development experience with at least one programing language such as Java, Python, JavaScript, Go, Ruby, C# or C / C++
  • 3+ years of experience in penetration testing, offensive security, or red teaming
  • Deep technical understanding of OWASP Top 10, and SANS 25 vulnerability identification and remediation
  • Excellent written and verbal communication skills with the ability to adapt messaging to technical and non-technical audiences at all levels including senior leadership
  • History of working autonomously and delivering results in a fast-paced, highly ambiguous environment
  • Experience driving multiple technically complex security initiatives while remaining effective at providing security guidance to stakeholders

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, disability, age, or other legally protected status.

If you would like to request an accommodation, please notify your Recruiter.

Il y a plus de 30 jours
Emplois reliés
Morson Talent
Toronto, Ontario

Senior Security and Emergency Preparedness Engineer. The Senior Level Security and Emergency Preparedness Engineer performs a leadership role on the Plant Integration Team for the research and development phase for the new nuclear reactors within a team environment, working with partner organization...

Litens Automotive Group
Canada

Founded in 1979, Litens has a proud history of being an innovative and highly respected engineering company specializing in powertrain system design and component supply. This team uses the APQP process and sound engineering principles to provide award winning solutions to our global customer base a...

Wawanesa Insurance
Anywhere - Canada

Maintain the operation of business systems and applications. Diagnose, troubleshoot, and resolve application incidents. ...

Deloitte
Toronto, Ontario

The Network Security Consultants/Senior Consultants are responsible for delivering projects and/or deliverables specific to network security. Our services help organizations address timely and pervasive issues such as identity theft, data security breaches, data leakage, cyber security, and system o...

Intact Financial Corporation
Toronto, Ontario

Together, with our strong team of Cybersecurity risk advisory and Cybersecurity Supply Chain Risk Management, you will work with state-of-the-art technologies to promote a strong cybersecurity governance and compliance culture for Intact Financial Corporation. Our growing team is looking for a Secur...

Crypto.com
Canada, Other, Canada,

Operations Management: Monitor and automate application and infrastructure alerts to ensure timely actions are taken to maintain system stability and uptime for all the applications. User Management: Provide technical support to Sales, Business Users, Institutional and Retail customer base with focu...

S.i. Systems
Toronto, Ontario

Senior JavaScript (ReactJS, NodeJS) Developer to support the TSYS program in building front-end web applications for one of our major banking clients -. Business group: Client Engineering - Mobile and Web - part of the Digital Group, focusing on Mobile Web application to all BNS customers. You will ...

Royal Bank of Canada>
Toronto, Ontario

As a  Senior Network and Security Analyst you will provide consistent levels of organizational and technical expertise necessary for the successful implementation, maintenance and support of the critical network and security infrastructure services across all global RBC Intranet (Core, LAN/WAN, Serv...

Sobeys
Mississauga, Ontario

Sobeys is full of exciting opportunities and we are always looking for bright new talent to join our team! We currently have a full-time opportunity for a Senior Application Systems Analyst to join the Tech Solutions - Masterdata Team in our Information Technology department. Provides remote support...

Coinbase
Canada
Télétravail

At least 5 years of experience in security domains such as Application Security, Product Security, Infrastructure Security, Cloud Security, Security Engineering, etc. Manage Product Security incidents specially onchain security incidents with Product/Engineering teams and or ecosystem partners . Our...