Amazon

Security Support Engineer, Vulnerability Management and Remediation Operations

Our mission is to be Earth's most customer-centric company. This is what unites Amazonians across teams and geographies as we are all striving to delight our customers and make their lives easier, one innovative product, service, and idea at a time.

  • Software engineering

  • Full-time

  • Office | Sydney, NSW, Australia

  • Visa sponsorship ยท No

  • Mid Level ยท A role for someone with some well-developed knowledge and skills they can bring to the role and team. Typically within 2-5 years of experience.

  • ยท

Why Amazon

The scope and scale of our mission drives us to seek diverse perspectives, be resourceful, and navigate through ambiguity. Inventing and delivering things that were never thought possible isn't easy, but we embrace this challenge every day.

About the role

DESCRIPTION

Embark on a Mission to Fortify Amazon's Defenses as a Support Engineer with the Vulnerability Management & Remediation Operations team!

Amazon Security is seeking an experienced and innovative Support Engineer specialising in cybersecurity to join our Vulnerability Management and Remediation Operations (VMRO) team in Sydney, Australia. The VMRO team is a global team that is responsible for assessing, detecting, and driving the remediation of vulnerabilities across the Amazon ecosystem.

Key job responsibilities - Support vulnerability detection campaigns by working closely with Campaign Owners to launch and continuously improve the quality of campaigns across Amazon. - Assess and negotiate with customers to drive down security risk by engaging with teams to remediate critical security vulnerabilities in their environments. - Collaborate with builder teams to implement security fixes and improvements. - Understand technical details of vulnerabilities affecting Amazon's infrastructure, services, and applications. - Review and analyse common vulnerability disclosures and assist in evaluating potential impacts. - Help triage vulnerabilities and contribute to impact and detection logic assessments. - Contribute to the development of automation of repetitive tasks. - Actively participate in updating documentation and sharing knowledge across your global peers. - Participate in an on-call rotation to support continuous monitoring and remediation of vulnerabilities.

If you're excited about the opportunity to make a significant impact on the security of one of the world's largest and most complex technology ecosystems from our Sydney office, we'd love to hear from you!

BASIC QUALIFICATIONS

- Bachelor's degree in Computer Science, Computer Engineering, Software Engineering, Cybersecurity or related technical degree or equivalent; or 3+ years equivalent technology experience - Strong understanding of security concepts with a security mindset. - Strong understanding of computer and network weaknesses and mitigating controls. - Strong ability to understand risk and prioritisation in the context of the business. - Ability to communicate effectively within technical and business settings. - Ability to document learnings and contribute to knowledge sharing and runbook building. - Experience with secure-cloud configuration, (CloudTrail, AWS Config), cloud-security technologies (VPC, Security Groups, WAF etc.), and cloud-permission systems (IAM). - Experience with identity and access concepts, with technologies to secure production and corporate access, (SSO, SAML) and with Federated Identity, RBAC, authentication and authorisation solution, encryption, SSL, and related.

PREFERRED QUALIFICATIONS

- 2+ years of experience in fields such a Security Operations, technology audit, or security vulnerability lifecycle. - Ability to prioritise multiple tasks and projects. - Have a passion to learn and thrive in a dynamic and constantly changing environment. - Experience with virtualisation technologies, especially with AWS services. - Relevant industry certifications such as CISSP, SANS, ISC2, CompTia, etc. - Maturity, judgment, negotiation/influence skills, analytical skills, and leadership skills. - Demonstrated knowledge of web protocols, common attacks, and working knowledge of Linux/Unix tools and architecture. - Understanding of best practices across multiple security disciplines/domains. - Demonstrated ability to work autonomously with a Bias for Action, critical and creative thinking. - Demonstrated ability to collaborate, develop partnerships, and work effectively as a member of a global, inclusive team.

What you'll be responsible for

  • ๐Ÿ“ฆ

    Backend application development

    Develop, test, and maintain software applications

  • ๐Ÿ”ฒ

    SQL and Databases

    Use SQL to query databases to extract and process data

  • ๐Ÿ› 

    Test Automation

    Create and implement code tests and software test automation

Skills you'll need

  • ๐Ÿ‘ฅ

    Collaboration

    Works with others by being open, clear in communication and listening to achieve goals

  • ๐Ÿงฎ

    Numerical problem solving

    Works with numerical information and performs mathematical calculations to solve problems

  • ๐Ÿ”

    Attention to detail

    Accurately identifies and rectifies discrepancies or errors that exists in information and deliverables

Meet the team

Avatar
Engineering

Amazon