✦ Luna Orbit — Cybersecurity

Security Engineer II, Stores Security Review Operations

at Amazon.com

📍 US, NY, New York Onsite Posted April 03, 2026
Type Full-Time
Experience mid
Exp. Years 3+ years
Education Not specified
Category Cybersecurity

Security Engineer II at Amazon Security Review Operations to conduct security reviews, perform penetration testing, and drive remediation with partner teams. Build tooling and contribute to security improvements across multiple business verticals.

  • Conducting high quality application security reviews and penetration tests independently, or as part of a team
  • Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
  • Contributing to team tooling, innovation, and improvements
  • Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings

Background in networking, application security, and cloud security with programming in multiple OO languages; experience with security testing and tooling; AWS familiarity.

The ideal candidate is a mid-level security engineer with 3+ years in threat modeling, secure coding, or pentesting, strong AWS knowledge, and hands-on experience with security tooling and automation to safeguard Amazon services.

Knowledge of networking protocols such as HTTPDNS and TCP/IPKnowledge of industry-based security vulnerabilities and remediation techniques3+ years of any combination of the following: threat modeling experiencesecure codingidentity management and authenticationsoftware developmentcryptographysystem administration and network security experience2+ years of programming in PythonRubyGoSwiftJava.NetC++ or similar object oriented language experience3+ years of experience in a penetration testing or information security role
Knowledge of cloud service providers and their offeringspreferably AWSand its various technologies and servicesExperience in developing security tooling and automationExperience in CTF competitionsCVE researchand/or Bug Bounty recognitionAdvanced degree in Computer Science or related field
Amazon Web ServicesPythonGoSwiftJavaMicrosoft .NETC++C#
Knowledge of HTTPDNSTCP/IP; threat modeling; secure coding; penetration testing; information security; PythonRubyGoSwiftJava.NETC++C#; security tooling; automation; AWS; cloud service providers
HTTPDNSTCP/IPThreat modelingSecure codingPenetration testingInformation securityPythonRubyGoSwiftJavaC++C#.NETSecurity toolingAutomationAWSAmazon Web Services
leadershipcommunicationcollaborationcustomer obsessiondecision making
Industry E-commerce
Job Function Perform security testing and threat-focused evaluations across Amazon services and drive remediation with engineering teams
Role Subtype Security Engineer II
Tech Domains Amazon Web Services, Python, Go, Java, JavaScript, C++, C#, Microsoft .NET, HTTP, DNS, Networking / TCP-IP, Security tooling
security engineersecurity engineer iiawsamazon web servicespenetration testingthreat modelingsecure codingsecurity toolingautomationcloud securityPythonGoSwiftJavaC++C#.NETHTTPDNSTCP/IPinformation securitypython

No AWS or cloud security experience, Less than 3 years in security/pen testing, No programming experience in common languages

Apply for this Position →

Get matched to jobs like this

Luna finds roles that fit your skills and career goals — no endless scrolling required.

Create a Free Profile