Security Engineer, Vulnerability Management and Remediation Operations

Amazon is one of the world's largest and most complex technology ecosystems, focusing on customer trust and delivering delightful customer experiences.
Security
Mid-Level Software Engineer
In-Person
5,000+ Employees
2+ years of experience
Cybersecurity · Enterprise SaaS
This job posting may no longer be active. You may be interested in these related jobs instead:
Software Development Engineer II, Defensive Security - Security Pipeline Engineering

Software Development Engineer II role at Amazon's Security Pipeline Engineering team, building large-scale security applications and data processing pipelines.

Software Development Engineer, Amazon Privacy, Amazon Privacy Engineering

Software Development Engineer role at Amazon Privacy Engineering, focusing on building and maintaining secure privacy solutions across Amazon's ecosystem.

Software Development Engineer II, AWS Web Application Firewall (WAF)

AWS WAF team seeks Security Engineer to build and maintain global web application firewall systems, offering competitive pay and comprehensive benefits.

Security Program Manager (Saudi Arabian/GCC national), DCC Communities

Security Program Manager role at AWS managing physical security systems and infrastructure for data centers, requiring 3+ years of program management experience.

Systems Engineer, ESCAPE

Systems Engineer position at Amazon's ESCAPE team, focusing on endpoint security solutions and infrastructure protection across Amazon's global network.

Description For Security Engineer, Vulnerability Management and Remediation Operations

Amazon Security is seeking a Security Engineer to join our Vulnerability Management and Remediation Operations (VMRO) team in London, UK. The VMRO team is responsible for discovering, assessing, triaging, detecting, and driving the remediation of vulnerabilities across the Amazon ecosystem.

Key responsibilities include:

  • Analyzing public and private vulnerability disclosures and exploit code
  • Assessing technical details and potential impact of vulnerabilities across Amazon's infrastructure, services, and applications
  • Investigating and triaging vulnerabilities, identifying severity and scope of potential impact
  • Supporting response and remediation efforts, assisting builder teams to fix security issues
  • Engineering high-quality, scalable, and accurate vulnerability detection mechanisms
  • Designing and implementing automation, tools, and workflows to enhance operations capabilities
  • Participating in periodic on-call responsibilities for continuous monitoring and remediation of vulnerabilities

The ideal candidate will have:

  • BS degree in Computer Science, Computer Engineering, Software Engineering, Cybersecurity or related technical degree; or 4+ years equivalent technology experience
  • 2+ years engineering experience in system, network, and/or application security or security product development
  • Deep knowledge of vulnerabilities, exploits, and vulnerability management systems
  • Experience developing vulnerability assessment tests, tools, and exploits in Python, Java, etc.
  • Experience building applications or systems on cloud-based services

Amazon Security values diverse experiences and encourages candidates from all backgrounds to apply. The team offers flexible work hours, ongoing DEI events, mentorship, and career growth opportunities. Join us in making a significant impact on the security of one of the world's largest technology ecosystems!

Last updated 2 months ago

Responsibilities For Security Engineer, Vulnerability Management and Remediation Operations

  • Analyse public and private vulnerability disclosures and exploit code
  • Deeply understand and assess the technical details and potential impact of vulnerabilities across Amazon's infrastructure, services, and applications
  • Investigate and triage vulnerabilities, identifying severity and the scope of potential impact to Amazon
  • Support response and remediation efforts, assisting builder teams to fix their security issues in a timely manner
  • Engineer high quality, scalable, and accurate vulnerability detection mechanisms
  • Design and implement automation, tools and workflows to enhance our operations capabilities
  • Be part of a global team and participate in periodic on-call responsibilities to ensure the continuous monitoring and remediation of vulnerabilities

Requirements For Security Engineer, Vulnerability Management and Remediation Operations

Python
Java
  • BS degree in Computer Science, Computer Engineering, Software Engineering, Cybersecurity or related technical degree; or 4+ years equivalent technology experience
  • 2 years engineering experience in system, network, and/or application security or the development of security products
  • 2 years experience improving accuracy of vulnerability detection mechanisms across a diverse technical ecosystem
  • 2 years experience and deep knowledge of vulnerabilities, exploits and vulnerability management systems
  • 2 years experience developing vulnerability assessment tests, tools and exploits in Python, Java, etc
  • 2 years experience building applications or systems on cloud-based services

Benefits For Security Engineer, Vulnerability Management and Remediation Operations

  • Flexible work hours
  • Ongoing DEI events
  • Mentorship
  • Career growth opportunities

Interested in this job?