Security Engineer II, Vulnerability Management and Remediation Operations


Location
London, UK
Hours
Full Time
Salary
Competitive salary commensurate with experience
About the Role
Embark on a mission to fortify Amazon's defences as a Security Engineer II within the Vulnerability Management and Remediation Operations (VMRO) team. The VMRO team is responsible for discovering, assessing, triaging, detecting, and driving the remediation of vulnerabilities across the Amazon ecosystem. You will analyse public and private vulnerability disclosures and exploit code, deeply understand and assess the technical details and potential impact of vulnerabilities across Amazon's infrastructure, services, and applications. Your role includes investigating and triaging vulnerabilities to identify severity and scope of impact, supporting response and remediation efforts by assisting builder teams to fix security issues promptly, and engineering high quality, scalable, and accurate vulnerability detection mechanisms. You will design and implement automation, tools, and workflows to enhance operational capabilities and participate in a global team with periodic on-call responsibilities to ensure continuous monitoring and remediation of vulnerabilities.
About the Team
Amazon Security values diverse experiences and encourages candidates from all backgrounds to apply. Whether your career is just starting, has followed a non-traditional path, or includes alternative experiences, your unique perspective is welcomed. Amazon Security is central to maintaining customer trust and delivering exceptional customer experiences by setting a high bar for security across all products and services. The team offers opportunities to build experience across cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Culture and Growth
Amazon Security fosters an inclusive team culture that embraces curiosity and continuous learning. Ongoing diversity, equity, and inclusion events inspire innovation and celebrate diverse ideas and perspectives. We provide extensive knowledge-sharing, training, mentorship, and career development resources to help you grow into a well-rounded professional. We also value work-life harmony and offer flexibility to support success both at work and at home.
Experience
- Minimum 5 years of security engineering experience in system, network, and/or application security
- 5 years experience developing vulnerability assessment tests using Python or Java
- 5 years experience improving accuracy of vulnerability detection mechanisms across diverse technical ecosystems
- 3 years experience troubleshooting networking, operating systems, applications, or cloud services
- 3 years experience building cloud-based services
- Knowledge of networking protocols such as HTTP, DNS, and TCP/IP
- Experience programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object-oriented languages
About You
You are an innovative and experienced security engineer with a passion for identifying and remediating vulnerabilities. You thrive in a collaborative global team environment and are committed to continuous learning and improvement. You value diversity and inclusion and are motivated to contribute to a culture that embraces unique perspectives and ideas.
Qualifications
- Bachelor's degree in computer science or equivalent
- Preferred experience with AWS products and services
- Preferred experience with threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, and network security

