security engineer
генерация резюме под вакансию
сопроводительное письмо
описание
The Content Security team protects pre-release content across Amazon Global Media and Entertainment throughout the content creation lifecycle. It secures production workflows, develops protection measures, and maintains cloud infrastructure and tooling, including defenses against emerging generative AI threats.
задачи
- Serve as the primary content security advisor to film and series production teams, providing tailored guidance on secure workflow design, editorial environment setup, Aspera file transfer configurations, cloud storage architecture, on-set networking, and remote collaboration tools;
- Assess internal and external content processing architectures, from large enterprises to boutique post-production houses, to securely deploy and maintain content networks and equipment;
- Manage security assessments of third-party services and tools supporting Amazon Studios, including production team request intake and end-to-end vendor security coordination;
- Research, evaluate, and pilot next-generation content security measures such as forensic watermarking, audio/video fingerprinting, and content tracking technologies;
- Contribute to the strategy for securing pre-release content against generative AI threats, including AI-driven extraction, reconstruction, deepfake misuse, and model training on unreleased assets; translate emerging risks into actionable controls and standards;
- Maintain and enhance AWS infrastructure and applications supporting Content Security operations;
- Build internal security tooling to automate access governance, audit reporting, and compliance monitoring workflows;
- Write and maintain lightweight Python and scripting automation for security tooling, audit workflows, and operational reporting;
- Develop and iterate security standard operating procedures tailored to each studio and production team;
- Provide regular written updates on program status, risk posture, and incident findings.
требования
- 3+ Years of non-internship experience with scripting, programming, and security code review in a common programming language;
- 3+ Years of experience in any combination of threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, and network security;
- Experience applying threat modeling or other risk identification techniques, or equivalent experience;
- Knowledge of industry-based security vulnerabilities and remediation techniques;
- Knowledge of using or integrating common cloud-hosted services;
- Nice to have: networking protocols such as HTTP(S), DNS, and TCP/IP; AWS products and services; security activities across one or more SDLC phases, including security design review, threat modeling, secure code review, and security testing; CCSP, CEH, CFR, Cloud+, CySA+, GCED, GICSP, or PenTest+ certification.
условия
- Training, knowledge-sharing, and career development resources are available;
- Flexible work hours and arrangements are part of the company culture.
навыки
Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.