[Apply Now] Principal Security Engineer, AWSSecurity

Amazon
London
9 months ago
Applications closed

Related Jobs

View all jobs

Security Resilience Manager

Waste Management Technician- Part time

Heat of IT & Systems

Head of IT & Systems

Developer

Techncial Delivery Lead

Principal Security Engineer, AWS Security Job ID:2780049 | Amazon Web Services Australia Pty Ltd This position canalso be based in Sydney, Australia. We are looking for anexperienced Principal Security Engineer to join the Security teamin Australia. You will be on a team responsible for conducting bothpre and post launch testing, offensive campaigns, emergent threattesting, creating/maintaining automated threat emulation solutions,and helping security and service teams add offensive insight totheir development, deployment, monitoring, and response processes.This team partners with the larger Security organization andService teams to continuously validate security throughout theservice/system lifecycle. You will be an expert across multipledomains such as cyber security; threat, vulnerability and riskassessments (TVRA), security tools (e.g. Splunk, Crowstrike, etc.),application of security frameworks (e.g. ISM, NIST, etc.) and/orimplementation and monitoring of cyber security controls (i.e.detection, protection, alerting, etc.) and will be sought out foradvice on a range of technical and business related issues. Yourrole will help ensure that our systems and processes are securedagainst the latest threats and you will lead security testing oflarge Amazon projects while setting standards and defining bestpractices for the Security team. You will proactively shareknowledge across the Amazon community and will be a critical memberof the organization in one or more of the core areas of security.Key job responsibilities: 1. Offering recommendations andfine-tuning findings to enhance threat mitigations, ensuring robustsecurity measures are in place. 2. Setting a high standard andgenerating high-quality testing plans and reports, striving forexcellence in security testing procedures. 3. Conducting offensivesecurity testing and engaging in ongoing vulnerability research toproactively identify potential risks. 4. Systematically identifyingvulnerabilities and meticulously tracking them to facilitate timelyremediation efforts. 5. Staying ahead of emerging threats bycontinuously testing systems and applications for vulnerabilitiesthat may arise. 6. Developing and maintaining automated solutionsfor emulating threats, enhancing efficiency and accuracy in threatdetection. 7. Providing security training and conducting outreachsessions with internal development teams to raise awareness andfoster a security-conscious culture. 8. Developing comprehensivesecurity guidance documentation, including policies, procedures,and best practices, to serve as a reference for the organization.9. Designing and building security tools tailored to theorganization's needs, enhancing the overall security posture. 10.Delivering meaningful security metrics to stakeholders andcontinuously improving the metrics for better insight into thesecurity landscape. Hold or be able to attain an AustralianGovernment Security Vetting Agency clearance (seehttps://www1.defence.gov.au/security/clearances). A day in thelife: Engineers in this role must show exemplary judgment in makingtechnical trade-offs between short versus long term security andbusiness goals. They must also demonstrate resilience and navigatedifficult situations with composure and tact. Conflicts should beaddressed by listening, finding the best way forward and persuadingone’s colleagues. Successful engineers in this role will regularlyanalyze their own performance with a critical eye. A broadunderstanding of the business and its interconnections is required.This position will also provide training, advice, and mentorship toother engineers. BASIC QUALIFICATIONS * Minimum 10+ years ofexperience in delivering cyber security solution to largeenterprises or to Government customers. * Proven ability to providetechnical and strategic oversight for a high-performing team ofsecurity professionals. * Demonstrated experience creatingeffective security strategies that balance prevention anddetection, drive risk reduction and mitigation. PREFERREDQUALIFICATIONS * Bachelor's degree in Computer Science orEngineering. * Masters’ degree or PhD in Cybersecurity or relateddomain. * Worked on large-scale cloud programs to deliver securityoutcomes. Amazon is committed to a diverse and inclusive workplace.Amazon is an equal opportunity employer, and does not discriminateon the basis of race, national origin, gender, gender identity,sexual orientation, disability, age, or other legally protectedattributes. Our inclusive culture empowers Amazonians to deliverthe best results for our customers. If you have a disability andneed a workplace accommodation or adjustment during the applicationand hiring process, including support for the interview oronboarding process, please visithttps://amazon.jobs/content/en/how-we-hire/accommodations for moreinformation. Amazon is an Equal Opportunity Employer – Minority /Women / Disability / Veteran / Gender Identity / Sexual Orientation/ Age. #J-18808-Ljbffr

Subscribe to Future Tech Insights for the latest jobs & insights, direct to your inbox.

By subscribing, you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

The Skills Gap in Cyber Security Jobs: What Universities Aren’t Teaching

Cyber security has become one of the most critical disciplines in the modern economy. From protecting financial systems and healthcare data to securing national infrastructure, cloud platforms and supply chains, cyber security professionals now sit at the frontline of digital trust. Demand for cyber security talent in the UK has surged. Job vacancies remain high, salaries continue to rise, and organisations across every sector report difficulty hiring skilled professionals. Yet despite this demand, many graduates struggle to break into cyber security roles and employers consistently report that candidates are not job-ready. The problem is not intelligence, ambition or academic effort. It is a persistent and widening skills gap between university education and real-world cyber security work. This article explores that gap in depth: what universities teach well, what they routinely miss, why the gap exists, what employers actually want, and how jobseekers can bridge the divide to build sustainable careers in cyber security.

Cyber Security Jobs for Career Switchers in Their 30s, 40s & 50s (UK Reality Check)

If you’re thinking about switching into cyber security in your 30s, 40s or 50s, you’re in good company. Across the UK, organisations of all sizes are hiring people from diverse backgrounds to protect systems, data & customers. But with hype around “hackers” & quick-win courses, it’s hard to separate reality from fiction. This guide gives you a UK reality check: which roles genuinely exist, what employers actually want, how training really works, what to expect on salary & progression & whether age matters. Whether you come from finance, project management, operations, law, HR or customer service, there is a credible route into cyber security if you approach it strategically.

How to Write a Cyber Security Job Ad That Attracts the Right People

Cyber security is now a board-level priority for organisations across the UK. From financial services and healthcare to critical infrastructure, SaaS platforms and the public sector, demand for skilled cyber security professionals continues to grow. Yet despite this demand, many employers struggle to attract the right candidates. Cyber security job adverts often generate large volumes of applications, but few are a genuine match. Meanwhile, experienced security engineers, analysts and architects quietly ignore adverts that feel vague, unrealistic or disconnected from real security work. In most cases, the problem is not a lack of talent — it is the quality of the job advert. Cyber security professionals are trained to assess risk, spot weaknesses and question assumptions. A poorly written job ad signals organisational immaturity and weak security culture. A well-written one signals seriousness, competence and trust. This guide explains how to write a cyber security job ad that attracts the right people, improves applicant quality and positions your organisation as a credible security employer.