Pentest Security Engineer II, Devices & Services Pentesting
US, Virtual
Our team operates under the Amazon Devices and Services Trust & Security (DSTS) organization which was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers’ trust, data, and the systems on which they rely. We protect customers by performing security reviews, offensive testing, vulnerability assessments, and provide guidance for remediations. We also drive down costs by building and automating security foundations and integrating them into design and release processes. DSTS builds the foundational capabilities that raise an org-wide security bar across the growing diversity of D&S businesses - securing 100+ device types, 12,000+ applications, and 100+ product lines that are developed and operated by more than 16,000+ builders.
The DSTS penetration testing organization is growing and seeking an experienced web penetration tester to help shape the future of Amazon’s service security. You will work with builder teams and product owners to perform penetration testing and identify high-impact security vulnerabilities across the web services ecosystem supporting Amazon’s devices. The ideal candidate will be expected to comprehend large complex web service architectures and to dive deep into a service's source code, and to have some exposure to device penetration tests. This role will provide you with challenging technical opportunities and will also be a great deal of fun if hacking Amazon sounds exciting to you!
In this role, you will be part of a dedicated team of talented penetration testers identifying vulnerabilities in the devices and services ecosystem. You will strive to understand systems, software, and services deeply and develop creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping millions of customers that rely on Amazon’s consumer products safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams. You're well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization. If you're passionate about finding security bugs, writing tools to enhance manual testing capabilities, automating repetitive tasks, and enjoy …
This job isn't fresh anymore!
Search Fresh JobsJob Profile
RestrictionsFlexible schedule
Benefits/PerksCareer growth Diverse and inclusive workplace Diverse experiences Equal opportunity employer Equity Flexible schedule Flexible work hours Inclusive Team Culture Inclusive workplace Knowledge sharing Learning experiences Medical Mentorship Other benefits Sign-on payments Total compensation package Training & Career Growth Work-life balance
Tasks- Analyze source code
- Collaboration
- Communicate effectively
- Communication
- Conduct penetration tests
- Develop test plans
- Documentation
- Identify vulnerabilities
- Leadership
- Penetration Testing
- Perform penetration testing
- Risk Mitigation
- Threat modeling
- Training
AI Analysis APIs Automation AWS Collaboration Communication Computer Customer service Design Devices Documentation Engineering Fuzzing Hardware security Healthcare Leadership Machine Learning Manual testing Mentorship Mobile applications Operations Organization Penetration Testing Presentations Retail Risk mitigation Security Security Reviews Software Source-Code Analysis Static Analysis Technical Documentation Technical Solutions Testing Threat modeling Training Vulnerability assessment Web applications Web service APIs
EducationBusiness Computer Science Engineering Equivalent Operations Related Field
Certifications