Auf einen Blick
- Aufgaben: Join our team to find and exploit vulnerabilities in Amazon's devices and services.
- Arbeitgeber: Be part of Amazon's Devices and Services Trust & Security organization, dedicated to customer safety.
- Mitarbeitervorteile: Enjoy a collaborative environment with opportunities for mentorship and skill development.
- Warum dieser Job: Exciting challenges await as you help secure millions of customers' trust and data.
- Gewünschte Qualifikationen: 3+ years in web app security; strong coding and vulnerability assessment skills required.
- Andere Informationen: Ideal for those passionate about hacking and making a real impact on security.
Das voraussichtliche Gehalt liegt zwischen 48000 - 84000 € pro Jahr.
Pentest Security Engineer II, Devices & Services Pentesting
DESCRIPTION
Come join our penetration testing team dedicated to the detection and exploitation of vulnerabilities across Amazon’s portfolio ranging from consumer services and devices to the Kuiper satellites. This includes conducting in-depth reviews of complex service workflows including authentication mechanisms, AI, mobile, web applications, and web service APIs. Pentesters also invent new ways to automate and improve their work with techniques such as AI/LLMs, fuzzing, detection at scale, and static analysis.
Our team operates under the Amazon Devices and Services Trust & Security (DSTS) organization which was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers‘ trust, data, and the systems on which they rely. We protect customers by performing security reviews, offensive testing, vulnerability assessments, and provide guidance for remediations. We also drive down costs by building and automating security foundations and integrating them into design and release processes. DSTS builds the foundational capabilities that raise an org-wide security bar across the growing diversity of D&S businesses – securing 100+ device types, 12,000+ applications, and 100+ product lines that are developed and operated by more than 16,000+ builders.
The DSTS penetration testing organization is growing and seeking an experienced web penetration tester to help shape the future of Amazon’s service security. You will work with builder teams and product owners to perform penetration testing and identify high-impact security vulnerabilities across the web services ecosystem supporting Amazon’s devices. The ideal candidate will be expected to comprehend large complex web service architectures and to dive deep into a service’s source code, and to have some exposure to device penetration tests. This role will provide you with challenging technical opportunities and will also be a great deal of fun if hacking Amazon sounds exciting to you!
In this role, you will be part of a dedicated team of talented penetration testers identifying vulnerabilities in the devices and services ecosystem. You will strive to understand systems, software, and services deeply and develop creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping millions of customers that rely on Amazon’s consumer products safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams. You’re well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization. If you’re passionate about finding security bugs, writing tools to enhance manual testing capabilities, automating repetitive tasks, and enjoy seeing your work impact Amazon consumer devices and services, then this position is for you. Candidates from mid to senior level are encouraged to apply.
Key job responsibilities
- Lead and contribute to penetration tests against services and software released by Amazon’s Devices & Services organization. This includes working closely with builder teams to scope pentests, develop test plans, find vulnerabilities, develop proof of concept exploits, report findings, and validate patches.
- Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.
- Review and influence technical solutions to mitigate security vulnerabilities by providing actionable long-term risk mitigation guidance to drive security improvements.
- Lead impactful security improvements in large product lines through close collaboration with our partner builder teams.
- Develop detailed technical documentation describing identified vulnerabilities, associated impact, and recommended remediation to guide communication with internal engineering stakeholders and leadership.
- Mentor junior penetration testers and cultivate a culture of collaboration and research sharing.
BASIC QUALIFICATIONS
- 3+ years of experience identifying, exploiting, and recommending solutions to remediate web application and service API vulnerabilities (e.g. mass assignment, broken object/function level authorization, JWT/OAuth, injection, business logic flaws, excessive data exposure, etc.).
- Experience tracing sources and sinks during code review to identify vulnerabilities, and providing contextual remediation guidance to address vulnerability root cause.
- Experience designing and reviewing secure system architectures through the use of Threat Modeling incorporating sophisticated and modern attacks.
- Knowledge of cloud service providers and their offerings, preferably AWS, and its various technologies and services.
- Bachelor’s degree in Computer Science or related field, or equivalent industry experience.
PREFERRED QUALIFICATIONS
- Foundational knowledge of hardware security fundamentals.
- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition.
- Experience with applying and assessing Machine Learning technologies.
- Published security research (e.g. conference presentations, whitepapers, blog posts).
Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( to know more about how we collect, use and transfer the personal data of our candidates.#J-18808-Ljbffr
Pentest Security Engineer II, Devices & Services Pentesting Arbeitgeber: ENGINEERINGUK
Kontaktperson:
ENGINEERINGUK HR Team
StudySmarter Bewerbungstipps 🤫
So bekommst du den Job: Pentest Security Engineer II, Devices & Services Pentesting
✨Tip Number 1
Familiarize yourself with Amazon's Devices & Services portfolio. Understanding the specific services and devices you'll be working with will give you an edge during interviews and help you tailor your approach to pentesting.
✨Tip Number 2
Brush up on your knowledge of common web application vulnerabilities, especially those mentioned in the job description like JWT/OAuth issues and injection flaws. Being able to discuss these in detail will demonstrate your expertise.
✨Tip Number 3
Engage with the pentesting community through forums or CTF competitions. This not only sharpens your skills but also shows your passion for security, which is a key trait they are looking for.
✨Tip Number 4
Prepare to discuss your experience with automation tools and techniques. Since the role emphasizes improving efficiency through automation, showcasing relevant projects or tools you've developed can set you apart.
Diese Fähigkeiten machen dich zur top Bewerber*in für die Stelle: Pentest Security Engineer II, Devices & Services Pentesting
Tipps für deine Bewerbung 🫡
Understand the Role: Before applying, make sure you fully understand the responsibilities and requirements of the Pentest Security Engineer II position. Familiarize yourself with penetration testing methodologies and the specific technologies mentioned in the job description.
Tailor Your Resume: Customize your resume to highlight relevant experience in web application security, vulnerability assessment, and penetration testing. Use specific examples that demonstrate your skills in identifying and remediating vulnerabilities, especially those related to web services and APIs.
Craft a Compelling Cover Letter: Write a cover letter that showcases your passion for security and your understanding of Amazon's mission. Mention any relevant projects or experiences that align with the role, and express your enthusiasm for contributing to the safety of Amazon's consumer products.
Highlight Technical Skills: In your application, emphasize your technical skills, particularly in areas like static analysis, threat modeling, and cloud services (preferably AWS). Mention any experience with automation tools or machine learning technologies that could enhance penetration testing efforts.
Wie du dich auf ein Vorstellungsgespräch bei ENGINEERINGUK vorbereitest
✨Understand the Role and Responsibilities
Make sure you have a clear understanding of the job description and the specific responsibilities of a Pentest Security Engineer II. Familiarize yourself with penetration testing methodologies, especially in relation to web applications and service APIs.
✨Showcase Your Technical Skills
Be prepared to discuss your experience with identifying and exploiting vulnerabilities. Highlight specific examples from your past work, particularly those involving complex web service architectures and source code analysis.
✨Demonstrate Problem-Solving Abilities
During the interview, be ready to explain how you approach vulnerability assessments and remediation. Discuss any innovative techniques you've used, such as automation or AI, to enhance your testing capabilities.
✨Communicate Effectively
Since this role involves collaboration with builder teams and product owners, practice articulating your thoughts clearly. Be prepared to explain technical concepts in a way that is accessible to non-technical stakeholders.