Security Engineer, Vulnerability Management and Remediation Operations
Job ID: 2886785 | Amazon Support Services Pty Ltd
Embark on a Mission to Fortify Amazon's Defenses as a Security Engineer with the Vulnerability Management & Remediation Operations team!
Amazon Security is seeking an experienced and innovative Security Engineer to join our Vulnerability Management and Remediation Operations (VMRO) team in Sydney, Australia. The VMRO team is responsible for discovering, assessing, triaging, detecting, and driving the remediation of vulnerabilities across the Amazon ecosystem.
Key job responsibilities:
1. Review and analyse common vulnerability disclosures and assist in evaluating potential impacts.
2. Understand technical details of vulnerabilities affecting Amazon's infrastructure, services, and applications.
3. Help triage vulnerabilities and contribute to impact assessments and detection logic assessments.
4. Collaborate with builder teams to implement security fixes and improvements.
5. Implement and maintain vulnerability detection mechanisms using established frameworks and tooling.
6. Contribute to the development of automation tools and workflows to support team operations.
7. Contribute to detection development for hosts and containers.
8. Participate in an on-call rotation to support continuous monitoring and remediation of vulnerabilities.
BASIC QUALIFICATIONS
- Bachelor's degree in Computer Science, Computer Engineering, Software Engineering, Cybersecurity or related technical degree or equivalent; or 2+ years equivalent technology experience
- Experience programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language
- 3+ years security engineering experience in vulnerability management or vulnerability signature detection development
- 2+ years security engineering experience in system, network, and/or application security
PREFERRED QUALIFICATIONS
- Experience with AWS products and services (e.g., EC2, S3, IAM)
- Knowledge of common vulnerability scanning tools (e.g., Nessus, Qualys)
- Experience with one or more of the following:
1. Basic threat modeling concepts
2. Network security fundamentals
3. Familiarity with common security frameworks (e.g., OWASP Top 10, CIS)
4. Security certifications (e.g., Security+, SSCP, CEH)
#J-18808-Ljbffr