Secure Coding mailing list archives

Job Posting


From: "Blalock, Zebediah" <zebb () amazon com>
Date: Fri, 29 Apr 2011 12:48:34 -0700

I would like to post this opportunity to the group.  Please let me know if this isn't the right place.  Thanks!

Do you want to make online shopping safer worldwide, one secure application at a time?  If you are passionate about 
security and software development come join the application security team here at Amazon.com!

Please contact me directly with interest or questions.  zebb () amazon com<mailto:zebb () amazon com>.

Application Security Engineer

Amazon.com is looking for expert Application Security Engineers to ensure that our websites, services and applications 
are designed and implemented to the highest standards. If you enjoy analyzing the security of applications and 
services, discovering and addressing security issues and quickly reacting to new threat scenarios, this position will 
provide you with a challenging opportunity. You will participate in security audits, risk analysis, vulnerability 
testing and security reviews across all elements of Amazon.com's software systems.

Key tasks include:

 *   Work with development teams to carry out Application Security Reviews
 *   Provide expert advice and consultancy to internal customers on risk assessment, threat modeling and fixing 
vulnerabilities
 *   Design, implement and support security-focused tools and services
 *   Develop security policies and procedures
 *   Participate in security compliance efforts (e.g., PCIDSS)
 *   Evangelize security within Amazon.com and be an advocate for customer trust
 *   Develop training materials for general security awareness and specific security technology training
 *   Evaluate new and emerging security products and technologies
 *   Participate in tier 2 and tier 3 security operations support
 *   Carry out acquisition and vendor risk assessment due diligence
Requirements:

 *   BS in Computer Science or equivalent required
 *   Several years of application security experience
 *   Several years experience in vulnerability testing and auditing
 *   Experience working with development team(s) that delivered commercial software or software-based services 
(development, QA testing, or security role)
 *   Solid experience and technical knowledge in security engineering, system and network security, authentication and 
security protocols, cryptography, and application security
 *   Knowledge of threat modeling or other risk identification techniques
 *   Knowledge of system security vulnerabilities and remediation techniques
 *   Development experience in Java, C++ or C
 *   Scripting skills (e.g., Perl, Python shell scripting)
 *   Knowledge of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols)
 *   Excellent written and verbal communication skills
 *   Excellent teamwork skills
 *   Results oriented, high energy, self-motivated


Zeb Blalock  |  Recruiter | Talent Acquisition  |  Amazon
E: zebb () amazon com<mailto:jcsmith () amazon com>  P: 206.266.9846   C: 425.466.1360

Work hard. Have fun. Make history.
Amazon.com/Careers<http://www.amazon.com/careers>

_______________________________________________
Secure Coding mailing list (SC-L) SC-L () securecoding org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php
SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com)
as a free, non-commercial service to the software security community.
Follow KRvW Associates on Twitter at: http://twitter.com/KRvW_Associates
_______________________________________________

Current thread: