Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit this link for more information. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. USA, AZ, Tempe - 77,400.00 - 135,400.00 USD annually. USA, TX, Irving - 77,400.00 - 135,400.00 USD annually. USA, WA, Bellevue - 82,700.00 - 135,400.00 USD annually.
Security Engineer II, Stores Penetration Testing
Location
United States
Posted
4 days ago
Salary
Not specified
Job Description
Role Description
Amazon’s Information Security Penetration Testing Team is seeking a Security Engineer to help keep Amazon secure for its customers. In this role, you will attack Amazon’s services, applications, and websites to discover security issues and report them to our internal technology teams. This position will provide you with challenging opportunities, both technologically and as a leader.
A Security Engineer at Amazon is expected to be strong in multiple domains. Engineers in this role work closely with teams throughout Information Security, as well as provide technical leadership and advice to teams and leaders throughout Amazon.
You will be in direct contact with teams in a variety of business verticals, giving you first-hand knowledge about how Amazon is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Amazon to find new ways to break services, processes, and technologies throughout the company.
Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. You will demonstrate resilience and navigate ambiguous situations with composure and tact. You will be expected to provide thought leadership for the organization as you discover, invent, and innovate throughout the course of your duties. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its customers secure.
Key job responsibilities
- Conducting high quality application penetration tests independently, or as part of a team
- Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
- Contributing to team tooling, innovation, and improvements
- Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings
Qualifications
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Knowledge of industry-based security vulnerabilities and remediation techniques
- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- 2+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object-oriented language experience
- 3+ years of experience in a penetration testing or information security role
Requirements
- Knowledge of cloud service providers and their offerings, preferably AWS, and its various technologies and services
- Experience in developing security tooling and automation
- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
- Advanced degree in Computer Science or related field
Benefits
- Comprehensive health insurance (medical, dental, vision, prescription)
- Basic Life & AD&D insurance and option for Supplemental life plans
- EAP, Mental Health Support, Medical Advice Line
- Flexible Spending Accounts
- Adoption and Surrogacy Reimbursement coverage
- 401(k) matching
- Paid time off
- Parental leave
Job Requirements
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Knowledge of industry-based security vulnerabilities and remediation techniques
- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- 2+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object-oriented language experience
- 3+ years of experience in a penetration testing or information security role
- Knowledge of cloud service providers and their offerings, preferably AWS, and its various technologies and services
- Experience in developing security tooling and automation
- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
- Advanced degree in Computer Science or related field
Benefits
- Comprehensive health insurance (medical, dental, vision, prescription)
- Basic Life & AD&D insurance and option for Supplemental life plans
- EAP, Mental Health Support, Medical Advice Line
- Flexible Spending Accounts
- Adoption and Surrogacy Reimbursement coverage
- 401(k) matching
- Paid time off
- Parental leave
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Director - Cyber Engineering Cloud Security
CencoraCencora is a leading pharmaceutical solutions organization centered on improving the lives of people and animals everywhere. With 46,000+ global team members, we have the opportunity to make a positive impact on healthcare in communities everywhere. Our team members are empowered to activate their careers through a collective of tools and resources designed to support individual career interests and aspirations. We value our listening culture that actions real outcomes and our team members appreciate and recognize one another for contributions that are making a meaningful global impact. No matter what your role is here, the work we do together has meaning. When you join our team, you become a crucial part of a greater purpose. We’re committed to supporting you personally and professionally, so we can achieve more together at the center of health. Protect yourself from job scams: Recruitment scams are on the rise. To protect yourself, we urge you to be vigilant and follow these guidelines > https://careers.cencora.com/us/en/job-scams
This role leads the global strategy, architecture, engineering, and governance for enterprise cloud security across multi-cloud and hybrid environments, securing public cloud, SaaS platforms, and containerized workloads. The director is responsible for defining the cloud security strategy, establishing reference architectures, leading governance across AWS, Azure, GCP, and managing the cloud security policy framework.
Security Intern assisting with risk management and security solutions
Principal Technical Consultant – Identity Focused Security Architect
Thinkahead Consultant Psychologist Pty LtdWe get to the heart of the matter.....real people......real solutions
Principal Technical Consultant leading identity solution implementations at AHEAD
The teacher is responsible for delivering specific course content in an online environment by providing instruction, support, and guidance, managing the learning process, and focusing on individual student needs. Essential functions include providing engaging synchronous and asynchronous learning experiences, differentiating instruction, maintaining the grade book, and actively communicating with students and parents/learning coaches.