Senior Security Engineer, Internal Audit
$178.4k - $226.7kAmazon Locker
Description
Amazon's Internal Audit Security team is seeking a Security Engineer III to join our mission of protecting customer data and keeping Amazon secure. You will operate as a security lead, partnering with world-class engineering teams to uncover vulnerabilities, design novel abuse scenarios, and assess large-scale security solutions across Amazon's products, services, and infrastructure.
In this role, you will leverage deep expertise in vulnerability assessment, exploitation, penetration testing, and red teaming to identify and mitigate risks across large, ambiguous problem spaces. Your work will span source code analysis, network penetration, and application exploitation. You will design, implement, and execute methodologies for security assessments of critical Amazon systems. Additionally, you will construct security frameworks, runbooks, and rubrics that enable others to apply your work in a repeatable manner. You will be exposed to the full breadth of technology used across Amazon and its subsidiaries, influence security architectures, identify opportunities to centralize security controls across the company, and communicate risks to Senior Executives. As AI accelerates development across Amazon, you will both leverage AI to enhance our audit capabilities and assess the security controls governing its use.
This role requires technical depth, strong security judgment, and the ability to lead projects spanning multiple engineers and teams. You will set a culture of robust security best practices, mentor and develop other security engineers, and drive long-term, measurable security risk reduction while balancing business need and customer experience.
Key job responsibilities
Lead independent security audits of Amazon systems, services, and infrastructure to assess whether security controls are effective
Identify security risks through penetration testing, design reviews, threat modeling, and code analysis
Investigate security control failures - determine why preventive or corrective controls didn't work, and drive root-cause resolution across team boundaries
Assess security controls around Amazon's adoption of AI/ML technologies - including model access, training data protection, output integrity, and integration into development workflows - to ensure they result in secure customer experiences
Build reusable security frameworks, runbooks, and rubrics that enable the team to assess new problem domains repeatably and at scale
Communicate security risk findings and recommendations clearly to technical teams and senior leadership
Mentor and develop other security engineers; lead engagements requiring coordination across multiple engineers and teams
About the team
Internal Audit Security executes independent assessments of the efficacy of Amazon's layered security controls. We prioritize security assessments of systems and processes that may impact foundational technologies, human safety, privacy and durability of customer data, and financial systems. We believe active tests are required to assess complex environments and emphasize custom tooling to enable safe operation at scale.
Basic Qualifications
5+ years of industry-based experience in security vulnerabilities identification, attack patterns, and remediation techniques (non-internship) experience
Bachelor's degree in Computer Science or a related field
5+ years of (non-internship) scripting, programming, and security code review in common programming languages experience
Knowledge of at least two of the following programming languages: Scala, Java, Python, C/C++, or Go
Experience as a mentor, tech lead or leading an engineering team
Experience using standard security assessment and penetration testing tools such as BurpSuite, Metasploit, and IDA Pro
Experience working directly with security and engineering teams
Experience in written and verbal communication with the ability to present complex technical information in a clear and concise manner to executives and non-technical leaders
Demonstrated ability to construct reusable security frameworks, runbooks, or rubrics for complex problem domains
Preferred Qualifications
Domain expertise in at least three of: security architecture and engineering, communication and network security, identity and access management (IAM), security assessment and testing, cryptography, software development security, and reverse engineering
Vulnerability research experience with complex software and hardware components
Cloud computing (AWS), virtualization, containerization architecture knowledge
Experience identifying and driving centralized security controls at the organization or company level
Experience with microservices, APIs, and distributed systems
Strong data analysis abilities to derive insights from security signals
Track record of mentoring or coaching security engineers
Experience resolving root causes of systemic security problems across team boundaries
Participation in bug bounty programs
Experience building scalable, reusable security frameworks and tools
Web service assessment experience with authentication controls, session management, access controls, logic flaws, injection vulnerabilities, request smuggling, cloud privilege escalation, DOS attacks
Experience using boto3
Experience leveraging AI/ML tools to enhance security testing, code analysis, or audit workflows
Demonstrated ability to navigate ambiguity, make tough technical decisions, build consensus across teams, and drive long-term security initiatives with measurable risk reduction
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at .
USA, MA, Virtual Location - Massachuset - 178,400.00 - 226,700.00 USD annually
USA, OR, Virtual Location - Oregon - 178,400.00 - 226,700.00 USD annually
USA, WA, Virtual Location - Washington - 178,400.00 - 226,700.00 USD annually
$187k - $220k
...so are the rewards. The Product and Application Security team builds and operates systems that help engineers identify and resolve security risks earlier in the... ...strengthen application security across Robinhood! As a Senior Security Engineer, Application Security, you will...SeniorWork at officeFlexible hoursShift work3 days per week$176k - $253k
...Senior Anti-Abuse Security Engineer At Snowflake, we are powering the era of the agentic enterprise. To usher in this new era, we seek AI-native thinkers across every function who are energized by the opportunity to reinvent how they work. You don't just use tools;...SeniorFlexible hours$178.4k - $226.7k
...The Ads Security organization at Amazon is dedicated to creating innovative technical solutions that detect, assess, and mitigate... ...products are inherently secure. We are seeking a talented Senior Security Engineer to join our team, where you will have the opportunity to...SeniorFlexible hours$165k - $242k
...ll Do: The Enterprise Security team at CoreWeave is... ...About the Role: As a Senior Security Engineer, Enterprise Security , you... ...and policy-based access into internal services and admin interfaces... ...DLP, sharing controls, and audit logging across the SaaS estate...SeniorPermanent employmentTemporary workFor contractorsCasual workWork at officeRemote workFlexible hours$110k - $130k
...A leading IT consultancy is seeking a Senior Security Engineer to conduct penetration testing and security assessments. This remote position requires expertise in security tools and compliance frameworks, as well as a Bachelor's degree and relevant certifications. The...SeniorRemote work- Lyft is seeking a Software Engineer with a focus on Security to join their team in Seattle. This role involves designing secure processes, improving detection pipelines, and collaborating with various teams. The ideal candidate should have over 5 years of experience in...Senior
- ...Senior Security Engineer We are seeking an experienced Security Engineer to play a pivotal role in shaping the security posture of our most critical applications and infrastructure - with a particular focus on AI/ML systems and emerging technologies. In this high-impact...SeniorShift work
- ...Integrate PAM with CI/CD pipelines, cloud systems, and enterprise applications Enforce privileged access policies and security standards Support audits, access reviews, and risk assessments Troubleshoot platform issues and drive root cause fixes Reduce privileged access...SeniorH1bRemote work
$139.5k - $258.1k
...Senior Security Engineer - Red Team We are the Apple Services Engineering (ASE) Security Red Team. We focus on deep technical security review work of critical ASE services and infrastructure. These security reviews will be scoped and focused on review depth and quality...SeniorRelocationShift work- ...Senior Offensive Security Engineer - Pentester Denver, Colorado;Seattle, Washington; Charlotte, North Carolina; Jacksonville, Florida; Jersey City, New Jersey; Boston, Massachusetts; Washington, District of Columbia; Chicago, Illinois; Jacksonville, Florida To proceed...SeniorWork at officeRemote workShift workDay shift
$90 - $97 per hour
...Senior Security Engineer - PAM Software Resources has an immediate, contract job opportunity for a Senior Security Engineer with a major media... .... - Lead PAM-related risk assessments, access reviews, and audit response activities. - Troubleshoot complex PAM platform...SeniorPermanent employmentContract workTemporary workWork experience placementImmediate start$227.76k - $267.95k
...The Trust team at Headway is focused on security and privacy for all of Headway’s customers... ...-house product and application security engineering efforts. In this role, you will partner... ...with product design decisions Auditing and surfacing vulnerabilities in our current...SeniorWork from homeFlexible hours$159k - $278.25k
...About the role Rippling is looking for a Senior Security Engineer to join our Corporate Security team.... ...employees use every day—SaaS apps, internal tools, endpoints, and email. We help the... ...privilege policies, automated approvals, and audit workflows. Deploy and tune security...SeniorWork at officeFlexible hours3 days per week$185k - $210k
...The Opportunity We are seeking an experienced Security Engineer to join our team and help secure Otter's cloud infrastructure and the systems behind our AI-powered meeting products. In this role, you will design and implement security controls, improve detection and...SeniorPermanent employment$166k - $220k
...computer vision, sensor fusion, and networking technology to the military in months, not years. ABOUT THE TEAM Anduril's Security Engineering team is looking for a security engineer to focus on building world class defensive controls to protect the infrastructure...SeniorFull timeWork experience placementImmediate start- ...Heavy use of Cursor and Claude About the Role: As our Senior Security Engineer, you will be the owner of infrastructure security at... ...requirements. What You'll Do Security & Compliance Audit our existing GCP infrastructure for security risks and vulnerabilities...SeniorWork at officeRemote workMonday to ThursdayFlexible hours
$174k - $252k
Senior Security Engineer, Chrome Product Security Google, Kirkland, WA, USA; Seattle, WA, USA Benefits Health, dental, vision, life, disability... .... Validate and triage reports of security issues from internal teams, automation, and external security reporters. Participate...SeniorFull timeTemporary work$165k - $242k
...Senior Security Engineer, SOAR CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology... ...across multiple different products and services (both internal and external) to secure the enterprise. Develop...SeniorPermanent employmentTemporary workCasual workWork at officeRemote workFlexible hours$166k - $220k
...Security Engineer Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century's most innovative companies...SeniorFull timeWork experience placementImmediate start$165k - $242k
...Senior Security Engineer, PKI & Secrets Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA/ San Francisco, CA, CoreWeave is The Essential... ...design of key management and data encryption solutions for internal and customer-facing use cases, including envelope...SeniorTemporary workCasual workWork at officeRemote workFlexible hours$178.4k - $226.7k
...Description Application deadline: Applications will be accepted on an ongoing basis We are looking for an experienced Senior Security Engineer to join our AI Red Team within Threat Operations. You will conduct sophisticated offensive security operations targeting...SeniorLocal areaFlexible hours$218.5k - $273.13k
...Senior Security Engineer (Product) New York, New York, United States; San Francisco, California, United States; Seattle, Washington, United... ...security reviews Helping with product design decisions Auditing and surfacing vulnerabilities in our current products...SeniorWork from homeFlexible hours$139k - $204k
...Senior Security Engineer I, Advanced Response CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers... ...and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary...SeniorTemporary workCasual workWork at officeRemote workFlexible hours$165k - $242k
...Senior Security Engineer II, Vulnerability Management Livingston, NJ / New York, NY / Sunnyvale,... ...security) Experience supporting customer audits (SOC 2, ISO 27001, FedRAMP) with... ...strive for both market alignment and internal equity when determining compensation....SeniorTemporary workFlexible hoursShift work$136.16k - $170.2k
...and get around our communities. Lyft’s engineering team is growing rapidly, and we are looking... ...Software Engineers with a passion in Security to help us scale. Come be part of the Security... ...Unblock, support and communicate with internal partners to achieve results Experience:...SeniorHourly payWork at officeLocal area3 days per week- A multinational financial institution is seeking a Senior Ethical Hacker in Seattle, WA. The role involves conducting security assessments, managing vulnerabilities, and developing proof-of-concepts. Candidates should have at least 5 years of experience in ethical hacking...Senior
$110k - $130k
...Perform risk and security assessments, design secure infrastructure architectures,... ...has an immediate remote opening for a Senior Security Engineer(Penetration Testing/GRC Assessments)... ...comprehensive penetration testing for internal and external environments, including...SeniorTemporary workWork at officeImmediate startRemote workVisa sponsorshipAfternoon shift$182k - $202k
...of the world's largest community of security researchers to continuously discover,... ...inclusion, respect, and accountability. Senior Security Engineer, Detection and ResponseRemote... ...protected characteristic as outlined by international, federal, state, or local laws. This...SeniorApprenticeshipLocal areaRemote workFlexible hoursShift work- Axon is looking for a Senior Security Operations Engineer in Seattle, WA to enhance security infrastructure and ensure operational reliability. This role involves automating PKI solutions and collaborating with various teams for integrated security management. The ideal...SeniorWork at office
- Axon is seeking a Senior Security Operations Engineer to enhance our security infrastructure in Seattle, WA. The role emphasizes PKI solutions and Kubernetes management, vital for our mission of protecting life through technology. This position promotes a hybrid work schedule...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer, Internal Audit. Be the first to apply!
- staff security engineer Seattle, WA
- senior application security engineer Seattle, WA
- sr information security engineer Seattle, WA
- security engineering manager Seattle, WA
- cloud security engineer Seattle, WA
- endpoint security engineer Seattle, WA
- physical security engineer Seattle, WA
- product security engineer Seattle, WA
- principal security engineer Seattle, WA
- security engineer Seattle, WA

