Security Engineer, AWS Security


Location
London
Hours
Full Time
Salary
Competitive, based on experience
About the Role
The AppSec Security Engineer evaluates service design and architecture and performs deep-dive security assessments to ensure applications and services meet a high security bar before launch. You will work alongside senior engineers to identify security issues, drive remediation efforts, and validate that security requirements are met. Key responsibilities include conducting security design reviews, performing threat modelling to identify attack vectors, coordinating penetration testing, managing security findings with clear remediation guidance, advising development teams on secure coding and data protection strategies, escalating high-severity issues to ensure timely remediation, maintaining clear documentation of security decisions and risk assessments, and leveraging automated tools to improve review efficiency. This role is critical in helping Amazon maintain a strong security posture across its services.
Experience
- Experience with web protocols, common security attacks, and remediation (non-internship)
- Experience in application security architecture, security code reviews, security testing, incident response, or security infrastructure
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and exploit development or equivalent
- Experience with coding or scripting in one or more languages such as Python, C, C++, Java, Ruby, or PowerShell
About you
- Passionate about security with strong analytical and problem-solving skills
- Able to work collaboratively with development teams and senior engineers
- Comfortable identifying and escalating high-severity security issues
- Enthusiastic about learning and applying new security tools and methodologies
- Values diversity and inclusion in the workplace
Qualifications
- Bachelor's degree or above in Computer Science, Engineering, or related fields
- Preferred experience with AWS services or other cloud platforms
- Preferred knowledge in one or more of the following: application security frameworks, mobile security, cloud security, AI security, identity and access controls, cryptography, penetration testing, forensic security, network security, threat intelligence, or IoT security
- Preferred scripting experience with Python, Perl, Bash, or PowerShell
- Preferred experience triaging security alerts, developing response automation, and providing escalation support

