Amazon logo
Amazon

Amazon is the largest online retailer in the world. The Fortune 500 company offers traditional and e-books, household items, apparel, electronics, movies, music

Security Engineer III

Location

United States

Posted

7 days ago

Salary

$179.2K - $226.7K / year

Seniority

Mid Level

Job Description

Security Engineer III

Amazon

Role Description Identify and resolve emerging security threats impacting Amazon's global enterprise, production environments, and customers. - Provide penetration testing. - Provide security engineering solutions and support during customer-facing incidents. - Contribute to development of Amazon.com Services Information Security organization’s policies, processes, and programs. - Identify and troubleshoot recurring issues and escalate appropriately for full resolution. 40 hours / week, 8:00am-5:00pm, Salary Range: $179,234/year to $226,700/year. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, visit: Amazon Benefits . Amazon.com is an Equal Opportunity-Affirmative Action Employer – Minority / Female / Disability / Veteran / Gender Identity / Sexual Orientation. Qualifications - Bachelor's degree or foreign equivalent degree in Computer Science, Engineering, Information Technology, Cybersecurity, Mathematics or a related field. - Five years of experience in the job offered or a related occupation. Requirements - Five years of experience in the following skill(s): - Experience with system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits. - Experience with security engineering practices, including: - Web application security. - Network security. - Authentication and authorization protocols. - Cryptography. - Automation. - Experience with dynamic and manual code auditing to identify security issues. - Programming in Java, C, C++, Perl, Ruby or Python. - Application of threat modeling or other risk identification techniques. - 100% telecommuting permitted, work may be performed from anywhere in the U.S. Preferred Qualifications Please see job description and the position requirements above. Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit Accommodations Information for more information.

Related Categories

Related Job Pages

More Security Engineer Jobs

NVIDIA logo

Information Security Engineer

NVIDIA

NVIDIA is widely considered one of the world's most desirable employers in technology. We have some of the world's most forward-thinking and passionate people working for us. If you're creative and autonomous, we want to hear from you!

Full TimeRemoteTeam 10,001+Since 1993H1B Sponsor

• Constantly improve automation, develop new tools and skills that make our secure practices easier for users to adopt and deploy • Partner with engineering and product management from earliest design through release. This entails tracking evolving discussions, surfacing security implications, and translating them into practical mentorship • Run security reviews across code, dependencies, containers, cloud, and CI/CD • Triage, prioritize, and drive remediation to closure • Build automation and developer-facing tooling that make secure-by-default the easy path • Ask sharp questions. Challenge assumptions. Surface risks that don't appear on standard checklists • Improve secure development practices, standards, and workflows • Communicate risk crisply to technical and non-technical audiences • Stay ahead of emerging threats relevant to modern software and cloud.

California + 4 moreAll locations: California | Colorado | District Of Columbia | New York | Virginia
$152K - $241.5K / year
Bespoke Labs logo

Cybersecurity Expert

Bespoke Labs

Bespoke Labs is a venture funded startup creating AI tools for data curation and post-training LLMs. (We are hiring!)

ContractRemoteTeam 1-10H1B No Sponsor

• Monitor and analyze evolving cyber threats as they intersect with AI systems and training pipelines • Track attacker TTPs, threat-group behavior, and AI-targeting trends across a 6–24 month horizon • Conduct adversarial analysis and scenario planning to stay ahead of emerging risks • Probe AI models for security boundaries through structured prompt testing and red-teaming exercises • Run independent security audits and penetration tests across systems and infrastructure • Identify, document, and prioritize vulnerabilities with clear remediation recommendations • Produce executive-ready risk assessments and intelligence reports that drive decision-making

United States

OT Security Engineer

Adapture Renewables

​Incorporated in 2011, Adapture Renewables develops, acquires, owns, and operates utility-scale solar energy assets and battery energy storage systems across the U.S., aiming to

Role Description Adapture Renewables, Inc. is on a mission to be a leader in this new era of sustainable energy. Our Technology team is looking for a talented OT Security Engineer to help support the efforts of our fast-growing company. This position will work in our Technology team and is responsible for designing, implementing, and maintaining cybersecurity controls across ARI’s SCADA and industrial control system (ICS) environments, including the interfaces between site OT networks and our enterprise IT infrastructure. The role owns NERC CIP Low impact compliance across the operating fleet, the vendor security relationships that gate access to our plants, and the security telemetry that feeds our centralized monitoring stack. This role reports to the Director of Technology & Security. The candidate may be based remotely in the U.S., with regular travel to operating PV and BESS sites and periodic travel to our Bay Area home office. Core Responsibilities - Design and implement OT network segmentation between site SCADA, control, and enterprise zones across the operating fleet. - Own secure remote access for vendors and ARI staff: jump hosts, MFA, session recording, and just-in-time access patterns. - Deploy and tune EDR on plant servers and engineering workstations within OT reliability constraints. - Maintain hardened baselines and configuration control for site servers, HMIs, RTUs/RTACs, and OT network equipment. - Run vulnerability assessment and patch / mitigation cycles for OT assets in coordination with site operations. - Maintain and execute the technical controls required under CIP-003 R2 Attachment 1 across all Low impact BES Cyber Systems. - Maintain BES Cyber System asset inventories and categorization evidence (CIP-002). - Maintain CIP-013 Low impact supply chain risk management evidence for vendors with electronic access. - Support CIP-008 incident reporting workflows and CIP-011 information protection requirements. - Participate in self-certifications, internal controls testing, and external audits; produce audit-quality artifacts. - Establish and enforce security requirements for SCADA, inverter, and BESS OEMs, ISPs, and field service vendors. - Drive contractual and technical supply chain controls in partnership with Procurement and Legal. - Integrate OT telemetry and security logs into ARI’s centralized monitoring stack. - Triage and lead response for OT security events; coordinate with site operations, the Compliance team, and the MSSP / enterprise SOC. - Develop and run tabletop exercises; maintain CIP-008 playbooks and capture post-incident lessons learned. - Conduct site visits to operating PV and BESS plants for inventories, validations, and control testing. - Deliver OT security awareness training for operators, technicians, and vendor partners. - Contribute to ARI’s broader cybersecurity program, aligned to CIS Controls v8, NIST CSF v2, and the in-progress IEC 62443 and ISO 27001 implementations. Qualifications - 3–5+ years in OT / ICS / SCADA security, industrial cybersecurity, or critical infrastructure security; utility, IPP, or owner-operator experience strongly preferred. - Bachelor’s degree in Electrical Engineering, Computer Engineering, Cybersecurity, or related discipline, or equivalent demonstrated experience. - Hands-on experience implementing and evidencing NERC CIP controls, with direct exposure to CIP-002, CIP-003, CIP-008, CIP-011, and CIP-013. - Working knowledge of OT networking: VLANs, L2/L3 switching and routing, industrial firewalls, DMZ design, jump architectures, and certificate-based authentication. - Familiarity with common ICS hardware and protocols: PLCs, RTUs, RTACs, HMIs; Modbus, DNP3, SEL. - Experience with SIEM / logging platforms and tuning detections for OT environments. - Preferred certifications: GICSP, ISA / IEC 62443 Cybersecurity Specialist, CompTIA Security+, or CISSP. - Strong documentation discipline; ability to produce evidence that survives audit scrutiny. - Clear written and verbal communication; able to translate security requirements into reliability outcomes for plant operations. - Solar and BESS operations experience, ERCOT market exposure, and prior NERC CIP audit participation are pluses. - Comfortable with field work, planned outage coordination, and occasional on-call response. - Valid driver’s license and ability to travel to operating sites as needed. Benefits - 401(k) plan with company matching contribution - Competitive health, vision, and dental benefits - Attractive personal time off and company holiday package - Work-from-home policy - Salary commensurate with experience Note Qualified candidates only. No search firms. Adapture Renewables, Inc. is committed to equal employment opportunity.

United States
Full TimeRemoteTeam 1,001-5,000H1B Sponsor

• The Project Manager administers assigned project(s) from ramp-up to completion; planning and executing the projects within the terms of the signed agreement ensuring the project is delivered on time and within budget • Implement project and process management methodology, standards and tools to drive and facilitate successful project delivery. • Lead project kick-off meetings to ensure proper initiation of a given project. Act as initial point of escalation for all issues that require further investigation. Complete accurate monthly forecasting report to aid in proper staffing and future financial analysis • Proactively mitigate risk and forecast the trajectory of projects to ensure that timely action is taken to keep projects on time and budget • Accurately estimate costs and revenue for the life cycle of Projects and/or Work Orders according to our company goals and standards

United States
$80K - $85K / year
Job Closed