Experience Level: 3 to 5 Years
Job Description:
Successful candidates should:
- be able to assess technical vs. business risks and consistently drive internal engineering teams to take the right actions in the appropriate time frames to mitigate risks.
- have a good mix of broad and deep technical knowledge and a demonstrated background in information security.
- be technically proficient in the fields of network and operating system security, cryptography, software security, security operations, incident response, and emergent security intelligence.
- possess a combination of troubleshooting, technical, and communication skills, as well as the ability to manage a mix of disparate tasks which may include small-project and software development work.
- be comfortable challenging and escalating to senior leadership to always ensure the best outcome for customers.
An ideal candidate should be able to conduct most of the following:
- Triage/assess security issues and engage with internal service teams to ensure prompt remediation of issues, escalating internally as necessary to ensure the right level of urgency and engagement.
- Participate in efforts to promote security throughout the Company and build good working relationships within the team and with others across Amazon.
- Demonstrate high ability and tolerance for extreme context switching and interruptions while staying productive and effective.
- Develop pragmatic solutions that achieve business requirements while keeping an acceptable level of risk.
- Help with recruiting activities and administrative work.
- Mentoring of junior staff and proactively share knowledge sharing within the team and across the company.
- Fulfill regular on-call responsibilities.
Key Responsibilities:
-
Supply oversight of in-flight security issues.
-
Triage new incoming issues to determine the level of risk they present to AWS, and then accordingly prioritize its remediation in conjunction with the impacted service team.
-
Communicate the state of these issues to various audiences, both technical and non-technical, at various levels of seniority (up to and including AWS’ Chief Information Security Officer).
-
Escalate issues to senior AWS leadership if you feel your issues are not being treated at the correct pace due to their impact to ensure that we are putting customers first.
-
Explore building and improving our tooling to make your own life easier, and at the same time, sharing that benefit with all our engineers globally.
-
A day in the life In the morning you will take handover from the previous site and be delegated ownership of various security issues presently in flight. The issues could relate to any of our service or application, so you will often need to learn on the go. You will engage various stakeholders, such as the internal service team who actually needs to fix the issue, along with Security Leadership, Legal, and the leadership from the impacted service team. As the day progresses, new issues will be automatically assigned to you based on your workload and you will be responsible for triaging them, determining their level of impact, and work towards resolving them at the appropriate pace. At the end of the day, you will document all the issues you are tracking so they can be taken over by the site relieving you.
BASIC QUALIFICATIONS
- BS degree in Computer Science, Computer Engineering, Electrical Engineering, or 3+ years’ equivalent technology experience.
- 3+ years or more of proven experience with a focus in areas such as systems, network, and/or application security.
PREFERRED QUALIFICATIONS
- 5+ years or more of proven experience with a focus in areas such as systems, network, and/or application security.
- Understanding of best practices across multiple security disciplines/domains.
- Extensive knowledge of Internet security issues, cloud architectures, and threat landscape.
- Experience with virtualization technologies, especially with AWS services.
- Strong proven knowledge of web protocols, common attacks, and an in-depth knowledge of Linux/Unix tools and architecture.
- Relevant industry certifications from SANS, ISC2, etc.
- Demonstrated ability to work autonomously with a bias for action, critical and creative thinking.
- Demonstrated ability to collaborate, develop partnerships and work effectively as a member of a team.
- Maturity, judgment, negotiation/influence skills, analytical skills, and leadership skills.
- Ability to prioritize multiple tasks and projects in a dynamic environment.
- Effective written and oral communication with multiple levels of leadership involving both business and technical sides of the business.