Senior Pentest Security Engineer, Devices and Services Pentest at Amazon.com – US, AZ, Virtual Location – Arizona

Join our penetration testing team dedicated to detecting and exploiting vulnerabilities affecting Amazon’s consumer services and devices. This includes conducting in-depth and low-level assessments of hardware, bootloaders, radios, secure enclaves, embedded systems and services including authentication mechanisms, AI, mobile, web applications and web service APIs. Pen testers are also coming up with new ways to automate and improve their work with techniques such as symbolic execution, fuzzing, machine learning, and static analysis.

The Amazon Devices and Services Trust & Security (DSTS) organization was founded in 2014 with the mission to protect Amazon Devices & Services (D&S) customers’ trust, data, and the systems they rely on. We protect customers by conducting security assessments, offensive testing, vulnerability assessments, incident response and remediation. We also reduce costs by building and automating security foundations and integrating them into design and release processes. DSTS is building the foundational capabilities that raise the security bar across the organization in the growing diversity of D&S companies – securing more than 100 device types, 12,000+ applications, and 100+ product lines developed and managed by more than 16,000+ builders.

The DSTS Penetration Testing organization is growing and is looking for an experienced Web Services API and Device Penetration Tester to shape the future of Amazon’s service security. You’ll work with build teams and product owners to review penetration testing requests and identify high-impact security vulnerabilities across Amazon’s ecosystem of devices and services. The ideal candidate will be expected to understand large complex web service architectures, dive deep into a service’s source code, and also perform fundamental hardware security penetration testing. This role offers you challenging technical opportunities and will also be a lot of fun if hacking Amazon sounds exciting to you!

In this role, you will be part of a dedicated team of talented penetration testers who identify vulnerabilities in the ecosystem of devices and services. You strive to deeply understand systems, software and services and develop creative ways to break assumptions to find vulnerabilities. You care about keeping millions of customers who rely on Amazon’s consumer products safe and you are passionate about mitigating vulnerabilities by providing actionable guidance to product teams. You are known for your excellent prioritization skills and your ability to communicate at all levels of an organization. If you’re passionate about finding security bugs, writing tools to reduce manual testing, and enjoy seeing how your work impacts Amazon consumer devices and services, then this position is for you. Mid to senior level candidates are encouraged to apply.

Key Job Responsibilities
* Conduct penetration testing of devices, services, and software released by Amazon’s Devices & Services organization and develop proof-of-concept exploits.
* Lead vulnerability research using various custom tools and technologies while scaling security testing (e.g. symbolic execution, static analyzers, fuzzers, scanners, machine learning, etc.).
* Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.
* Assess and influence technical solutions to mitigate security vulnerabilities by providing actionable long-term risk mitigation guidance to drive security improvements.
* Lead impactful security improvements across major product lines through close collaboration with our partner builder teams.
* Develop detailed technical documentation describing identified vulnerabilities, associated impact and remediation to guide communications with internal technical stakeholders and leadership.
* Mentor junior penetration testers and cultivate a culture of collaboration and research sharing.

A day in the life
The internal penetration testing team is part of the Devices and Services Trust & Security organization, which is responsible for the entire SDLC, vulnerability management, incident response, and overall security of Amazon Consumer Devices & Services (Kindle, Ring, FireOS, Kuiper, Alexa, Creepy and more). The internal penetration testing team is responsible for assessing these products, with a focus on penetration testing, fuzzing, and vulnerability research.

Although the majority of our security team is based in the US, by applying for this position your application will be considered for all locations we hire from around the world. However, candidates should expect to make time in the US for necessary meetings.

About the team
What we do
Kuiper Trust Services owns the creation and operation of services to protect customer data and Kuiper devices. Candidates for this role must have an interest in any of the following: AWS Services, PKI (public key infrastructure), HSMs (Hardware Security Modules), Firmware Signing, Secure Boot, Encryption, Cryptography, Key Management, and Secure Device Provisioning.

Various experiences
Amazon Security values ​​diverse experiences. Even if you do not meet all the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just getting started, doesn’t follow a traditional path or includes alternative experiences, don’t let this stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high standard of security for all Amazon products and services. We offer talented security professionals the opportunity to accelerate their careers with the opportunity to gain experience in a wide range of areas, including cloud, devices, retail, entertainment, healthcare, operations and physical stores.

Inclusive team culture
At Amazon Security, it is our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to keep learning and embrace our uniqueness. Tackling the toughest security challenges requires us to seek out and celebrate a diversity of ideas, perspectives and voices.

Education and career growth
We continually raise our performance bar as we strive to become the best employer in the world. That’s why you’ll find endless opportunities for sharing knowledge, training, and other career-advancing resources so you can develop into a better-rounded professional.

Work/life balance
We attach great importance to harmony between work and private life. Achieving success at work should never come at the expense of sacrifices at home. That’s why flexible working hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there is nothing we cannot achieve.

Basic qualifications

– 5+ years of experience identifying, exploiting and recommending solutions to address vulnerabilities in web applications and service APIs (e.g. mass allocation, broken object/function level authorization, JWT/OAuth, injection, business logic flaws, excessive data exposure, etc.) .
– Fundamental knowledge of the basics of hardware security (e.g. Secure Boot, JTAG/UART/SPI/I2C, firmware extraction and analysis, TEE, side-channel attacks, privilege escalation).
– Experience designing and assessing secure system architectures using Threat Modeling that incorporates advanced and modern attacks.
– Knowledge of cloud service providers and their offerings, preferably AWS, and its various technologies and services.
– A bachelor’s degree in computer science or a related field, or equivalent industry experience.

Preferred qualifications

– Experience with CTF competitions, CVE research and/or Bug Bounty recognition.
– Experience with applying and assessing Machine Learning technologies.
– Published security research (e.g. conference presentations, white papers, blog posts).

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.

Our compensation reflects labor costs in various U.S. geographic markets. The base salary for this position ranges from $143,300/year in our lowest geographic market to $247,600/year in our highest geographic market. Salary is based on a number of factors, including market location, and may vary depending on job-related knowledge, skills and experience. Amazon is a total compensation company. Depending on the position offered, equity, sign-on payments and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial and/or other benefits. For more information, visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain open until filled. Applicants must apply via our internal or external career site.

You May Also Like

More From Author