Security Engineer I, Secure Third Party Tools (S3T)

Are you motivated to protect customers at scale by building security into every third-party interaction? The Secure Third Party Tools (S3T) team within Amazon Security is shifting how we safeguard customer trust — moving from reactive assessments to proactive, automated protection. As a Security Engineer on this team, you will combine technical review expertise with a builder's mindset to evaluate third-party services, identify risks, and contribute to tooling that codifies security decisions into repeatable automation. You'll collaborate closely with service teams and senior security engineers, communicating risk clearly and driving resolution. This is a role for someone who is curious, adaptable, and eager to grow their security engineering craft while strengthening how Amazon manages vendor risk.

Key job responsibilities
- Perform technical security reviews of third-party services — including AI/ML integrations, cloud architectures, and services handling sensitive customer data — identifying gaps in security controls and recommending mitigations.
- Trace data flows through complex systems, threat model third-party use cases, and evaluate vendor penetration test reports to surface risks and drive proportionate remediation decisions.
- Contribute to AI-powered security tooling and automation that scales review decisions across the organization, scripting solutions and improving existing runbooks.
- Communicate identified risks and recommendations in written and verbal form to service teams and leadership, escalating where appropriate to drive resolution.
- Author and refine security decision rubrics and implementation patterns so that future engineers can build upon your findings.

A day in the life
You start by picking up a new third-party engagement, reviewing the architecture diagrams and data-flow documentation the service team has provided. You apply threat modeling to identify where sensitive data crosses trust boundaries, then draft your findings and discuss them with a senior engineer during a checkpoint. After lunch you might write a script to automate a repetitive validation step, or update the team's internal tooling with a new decision pattern you've identified. Your work feeds directly into the automation that makes the next review faster and more consistent.

About the team
The S3T team sits within Amazon Security and is responsible for evaluating and securing third-party services used across the company. The team is composed of security engineers at multiple levels who partner closely with builder teams, legal, and privacy stakeholders. Our mission is to scale security through software — encoding high-judgment decisions into automation so we can protect customers worldwide without growing linearly. We are building toward a future where every third-party integration is assessed proactively and continuously, and we are looking for engineers who want to help shape that vision.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available