Post a job

Job has expired

This job post is expired and is no longer taking new applicants.

Return home Find similar jobs

Senior Pentest Security Engineer, Devices & Services Pentest

AMAZon logo

Location
United States
Base Salary
143k-248k USD
AMAZon

Job Description

Come join our penetration testing team dedicated to the detection and exploitation of vulnerabilities affecting Amazon’s consumer services and devices. This includes conducting in-depth and low-level reviews of hardware, bootloaders, radios, secure enclaves, embedded systems as well as services including authentication mechanisms, AI, mobile, web applications, and web service APIs. Pentesters also invent new ways to automate and improve their work with techniques such as symbolic execution, fuzzing, machine learning, and static analysis.

The Amazon Devices and Services Trust & Security (DSTS) organization was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers’ trust, data, and the systems on which they rely. We protect customers by performing security reviews, offensive testing, vulnerability assessments, incident response and remediations. We also drive down costs by building and automating security foundations and integrating them into design and release processes. DSTS builds the foundational capabilities that raise an org-wide security bar across the growing diversity of D&S businesses - securing 100+ device types, 12,000+ applications, and 100+ product lines that are developed and operated by more than 16,000+ builders.

The DSTS penetration testing organization is growing and seeking an experienced web service API and device penetration tester to help shape the future of Amazon’s service security. You will work with builder teams and product owners to triage penetration testing requests and identify high-impact security vulnerabilities across Amazon’s devices and services ecosystem. The ideal candidate will be expected to comprehend large complex web service architectures and to dive deep into a service's source code and also perform foundational hardware security penetration tests. This role will provide you with challenging technical opportunities and will also be a great deal of fun if hacking Amazon sounds exciting to you!

In this role, you will be part of a dedicated team of talented penetration testers identifying vulnerabilities in the devices and services ecosystem. You will strive to understand systems, software, and services deeply and develop creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping millions of customers that rely on Amazon’s consumer products safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams. You're well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization. If you're passionate about finding security bugs, writing tools to reduce manual testing, and enjoy seeing your work impact Amazon consumer devices and services, then this position is for you. Candidates from mid to senior level are encouraged to apply.


Key job responsibilities
* Lead penetration tests against devices, services, and software released by Amazon’s Devices & Services organization and develop proof of concept exploits.
* Lead vulnerability research using variety of custom tooling and technologies while scaling security testing (e.g. symbolic execution, static analyzers, fuzzers, scanners, machine learning, etc).
* Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.
* Review and influence technical solutions to mitigate security vulnerabilities by providing actionable long-term risk mitigation guidance to drive security improvements.
* Leading impactful security improvements in large product lines through close collaboration with our partner builder teams.
* Develop detailed technical documentation describing identified vulnerabilities, associated impact and remediation to guide communication with internal engineering stakeholders and leadership.
* Mentor junior penetration testers and cultivate a culture of collaboration and research sharing.

A day in the life
The internal penetration testing team is part of the Devices and Services Trust & Security organization, which is responsible for the entire SDLC, vulnerability management, incident response, and overall security across Amazon Consumer Devices & Services (Kindle, Ring, FireOS, Kuiper, Alexa, eero, and more). The internal penetration testing team is responsible for reviewing these products, with focus on penetration testing, fuzzing, and vulnerability research.

While the majority of our Security team are based in the US, by applying to this position your application will be considered for all locations we hire for in the world, however candidates should expect to accommodate US time for necessary meetings.

About the team
What We Do
Kuiper Trust Services owns the creation and operation of services to protect customer data and Kuiper devices. Candidates for this role should have an interest in any of the following: AWS Services, PKI (public key infrastructure), HSMs (Hardware Security Modules), Firmware Signing, Secure Boot, Encryption, Cryptography, Key Management, and Secure Device Provisioning.

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications


- 5+ years of experience identifying, exploiting, and recommending solutions to remediate web application and service API vulnerabilities (e.g. mass assignment, broken object/function level authorization, JWT/OAuth, injection, business logic flaws, excessive data exposure, etc.).
- Foundational knowledge of hardware security fundamentals (e.g. Secure boot, JTAG/UART/SPI/I2C, firmware extraction and analysis, TEE, side-channel attacks, privilege escalation).
- Experience designing and reviewing secure system architectures through the use of Threat Modeling incorporating sophisticated and modern attacks.
- Knowledge of cloud service providers and their offerings, preferably AWS, and its various technologies and services.
- Bachelor’s degree in Computer Science or related field, or equivalent industry experience.

Preferred Qualifications

- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition.
- Experience with applying and assessing Machine Learning technologies.
- Published security research (e.g. conference presentations, whitepapers, blog posts).

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Advice from our career coach

As a candidate for the position of web service API and device penetration tester at Amazon, it is essential to have a strong understanding of security vulnerabilities, automated testing techniques, and web service architectures. To stand out as an applicant, consider the following tips:

  • Highlight your experience in identifying and exploiting web application and service API vulnerabilities, such as mass assignment, injection, and business logic flaws.
  • Showcase your foundational knowledge of hardware security fundamentals, including secure boot, firmware analysis, and side-channel attacks.
  • Demonstrate your ability to design secure system architectures through Threat Modeling and experience with cloud service providers, especially AWS.
  • Share any experience with CTF competitions, CVE research, Bug Bounty recognition, Machine Learning technologies, and published security research.
  • Emphasize your communication skills and ability to work collaboratively with cross-functional teams to drive security improvements.

Apply for this job

Expired?

Please let AMAZon know you found this job with RemoteJobs.org. This helps us grow!

RemoteJobs.org mascot