AWS Application Security Manager

Amazon Dev Center U.S., Inc.
 Arlington, VA


Job summary

Since early 2006, Amazon Web Services (AWS) has provided companies of all sizes with an infrastructure web services platform in the cloud. With AWS you can requisition compute power, storage, and other services thereby gaining access to a suite of elastic IT infrastructure services as your business demands them. AWS customers can take advantage of’s global computing infrastructure which is the backbone of’s multi-billion dollar retail business. AWS provides scalable, reliable, and secure distributed computing infrastructure that has been honed for over a decade. For more information on Amazon Web Services, please visit:

AWS Security is working on cutting edge solutions in partnership with external parties that involve a wide variety of technologies including cloud services, identity and access management, machine learning, mobile devices, and custom hardware — all operating at massive scale.

AWS Security is looking for an Vendor Security Team Manager to help validate that our Vendor provided services, applications, and websites are designed and implemented to the highest security standards. The focus will be on Corporate IT tools and services to include SaaS resources. You will be responsible for analyzing the security of applications and services, vendor-provided solutions, discovering and addressing security issues, building security automation, and quickly reacting to new threat scenarios. You will be responsible for managing a team of technical program managers and security engineers conducting security reviews and threat modeling, assisting with cross-organizational security initiatives, guiding external penetration testing coordination, and creating metrics to demonstrate your team’s performance. You will lead development of elegant solutions to complex business problems and apply appropriate technologies while following security engineering best practices. You will mentor junior engineers and be a security thought leader for the organization. Similarly, our highly collaborative team is committed to each team member’s growth as our business grows. You will have the opportunity to learn from, and be mentored by, those who are building and securing our cutting-edge services. You will help set the direction for a team of security professionals that is responsible for the use of Vendors at AWS to include SaaS products and services. This role combines long term strategic planning to raise the bar on security across the enterprise with the excitement and challenge of quickly reacting to new threat scenarios. AWS Security is on the cutting edge of many security issues for a wide variety of platforms and technologies including cloud services, mobile devices, virtualization and custom hardware, all operating at a massive scale.

As a Technical Manager at Amazon, it is expected that you will speak authoritatively on behalf of your team and that your technical knowledge demonstrates both depth and breadth. You will be responsible for your team’s organizational structure and how that team works within the context of the larger AWS IT Security team. Leveraging the strengths of individual team members, delegating tasks appropriately and managing delivery of long term projects will all be critical tasks for this role. A Technical Manager has deep knowledge in their domain and is a sought after thought leader across the organization. They have both management and technical expertise and actively participate in the organization’s planning processes.

Managers in this role must define metrics to quickly and accurately present the team’s performance and variance against its goals. They must also participate in and/or coordinate segments of cross-AWS initiatives, communicating status and results effectively across the division. A Technical Manager III is expected to seek out stretch assignments for your current team and foster their professional career development.

*This role is open to the Austin, TX, Seattle, Washington, or Washington DC locations.


* Team management, growth, and organization

* Professional development of team members

* Project management

* Metrics and projections

* Driving security initiatives

* Recruiting

* Process Improvement

* Application security reviews

* Review of third-party services (e.g. SaaS-providers)

* Audit, assessment, and penetration testing techniques

* Projects and research work as needed

* Security training and outreach to internal development teams

* Security guidance documentation

* Security tool development

* Security metrics delivery and improvements

* Assistance with recruiting activities and administrative work

Our team also puts a high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren’t focused on how many hours you spend at work or online. Instead, we’re happy to offer a flexible schedule so you can have a more productive and well-balanced life—both in and outside of work.

Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded engineer and enable them to take on more complex tasks in the future.

Here at AWS, we embrace our differences. We are committed to furthering our culture of inclusion. We have ten employee-led affinity groups, reaching 40,000 employees in over 190 chapters globally. We have innovative benefit offerings, and we host annual and ongoing learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences. Amazon’s culture of inclusion is reinforced within our 16 Leadership Principles, which remind team members to seek diverse perspectives, learn and be curious, and earn trust.

Basic Qualifications

* BS in Computer Science, Management Information Systems, Engineering or related field, or equivalent work experience

* Minimum of 5 years of experience directly managing a team of at least five engineers

* Minimum 4 years of security engineering, system and network security, authentication and security protocols, cryptography, and application security

Preffered Qualifications

* Experience driving large, cross-organization initiatives

* Experience managing communication with geographically distributed teams

* Excellent written and verbal communication skills, especially experience with executive-level communications

* Skilled at explaining complex technical issues in terms understandable by the business

* Strong sense of ownership, urgency, and drive

* Ability to make concrete progress in the face of ambiguity and imperfect knowledge (avoid “analysis paralysis”)

* Experience with multiple programming languages (such as, Java, C++, Ruby, Python, Perl, etc.)

* Experience with vulnerability risk and impact assessment

* Sharp analytical abilities and proven design skills

* Experience providing training and mentorship

* Intermediate knowledge and understanding of security engineering, system and network security, authentication and security protocols, cryptography, or application security

* Experience implementing security solutions at the business division level

* An understanding of network and web related protocols (such as, TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols)

* An understanding of web services

* Experience with multiple programming languages (such as, Java, C++, Ruby, Python, Perl, etc.)

* Excellent written and verbal communication skills

* Demonstrable teamwork skills and resourcefulness

* Possess self-drive to keep moving things forward even in the face of ambiguity and imperfect knowledge (avoid “analysis paralysis”)

* Strong sense of ownership, urgency, and drive

* Sharp analytical abilities and proven design skills

*Meets/exceeds Amazon’s leadership principles requirements for this role

*Meets/exceeds Amazon’s functional/technical depth and complexity for this role

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit