Current jobs related to Security Engineer I, Offensive Security Penetration Testing - New York, New York - Amazon Services LLC


  • New York, New York, United States WithSecure Full time

    About the RoleWe are seeking a highly skilled and experienced Senior Cybersecurity Consultant to join our team at WithSecure. As a key member of our team, you will be responsible for leading penetration tests and security assessments, as well as representing the company in key client relationships.Key ResponsibilitiesLead penetration tests and security...


  • New York, New York, United States Sisense Full time

    At Sisense, we are at the forefront of the unified data platform, empowering professional data teams to navigate complex data challenges effectively. We are on the lookout for a dedicated individual who is passionate about enhancing user experiences for both technical and non-technical audiences, and who can drive transformative outcomes for our...


  • New York, New York, United States SMBC Full time

    Job Title: Security Testing EngineerSMBC Group is a leading global financial institution with a rich history and diverse range of financial services. As a Security Testing Engineer, you will play a critical role in ensuring the security and resilience of our systems and applications.Key Responsibilities:Analyze IT infrastructure, systems, and applications...


  • New York, New York, United States Airitos Full time

    Position OverviewLocation: Hybrid Onsite 2-3x / Week in New York, NYContract Type: Approximately 1 Year with Potential for ExtensionRole Summary:The Application Security division serves as a reliable evaluator and risk consultant for the software development teams. Composed of security professionals skilled in software protection and penetration testing,...


  • New York, New York, United States Airitos Full time

    Position OverviewLocation: Hybrid Onsite 2-3x / Week in New York, NYJob Type: ~ 1 Year Contract w/Potential for ExtensionRole Summary:The Application Security division serves as a reliable evaluator and risk consultant for software development teams. This team consists of security professionals with specialized knowledge in software security and penetration...


  • New York, New York, United States Airitos Full time

    Position OverviewLocation: Hybrid Onsite 2-3x / Week in New York, NYJob Type: ~ 1 Year Contract w/Potential for ExtensionRole Summary:The Application Security division serves as a reliable evaluator and risk consultant for software development teams. This group consists of security professionals skilled in software protection and penetration evaluation. We...


  • New York, New York, United States Motion Recruitment Full time

    Lead Our Cyber Security TeamWe are seeking an experienced Penetration Tester to take on a leadership role within our advisory firm. As a Director of Red Team, you will oversee and mentor a team of junior employees, expanding the team and being the voice of the pen test practice.Key Responsibilities80% Hands-on penetration testing20% Write-up and report...


  • New York, New York, United States 00002 Citibank, N.A. Full time

    About CitiCiti is a leading global bank with a presence in over 160 countries and jurisdictions. We provide a wide range of financial products and services to consumers, corporations, governments, and institutions.The RoleWe are seeking a highly skilled Cloud Security Operations Specialist to join our team. As a key member of our Cloud Security Operations...


  • New York, New York, United States Luxoft Full time

    About the RoleLuxoft is seeking a highly skilled Cyber Security Lead Engineer to join our Cyber Technology service team. As a key member of our team, you will play a vital role in creating Application Security Scanning & Penetration Testing capabilities, determining required IT business solutions, and assisting in implementing them.We offer a collaborative...


  • New York, New York, United States Heidrick & Struggles Full time

    About Us:Heidrick & Struggles (Nasdaq: HSII) stands as a leading provider of global leadership advisory and on-demand talent solutions, addressing the senior-level talent and consulting requirements of the world's foremost organizations. As trusted advisors in leadership, we collaborate with our clients to cultivate future-ready leaders and organizations,...


  • New York, New York, United States Heidrick & Struggles Full time

    About Us:Heidrick & Struggles (Nasdaq: HSII) stands as a leading provider of global leadership advisory and on-demand talent solutions, catering to the senior-level talent and consulting requirements of the world's foremost organizations. As trusted advisors in leadership, we collaborate with our clients to cultivate future-ready leaders and organizations,...


  • New York, New York, United States Heidrick & Struggles Full time

    About Us:Heidrick & Struggles (Nasdaq: HSII) stands as a leading provider of global leadership advisory and on-demand talent solutions, addressing the senior-level talent and consulting requirements of the world's foremost organizations. As trusted advisors in leadership, we collaborate with our clients to cultivate future-ready leaders and organizations,...


  • New York, New York, United States Innova Solutions Full time

    Job Title: Mobile Application Security EngineerInnova Solutions is seeking a highly skilled Mobile Application Security Engineer to join our team. As a key member of our security team, you will be responsible for executing and driving security posture validation, application testing, penetration testing, and the management of vulnerabilities on systems...


  • New York, New York, United States Diligent Tec, Inc Full time

    Position: Senior Information Security EngineerCompany: Diligent Tec, IncEmployment Type: Contract to HireJob OverviewDiligent Tec, Inc is in search of a highly skilled Senior Information Security Engineer with a wealth of experience exceeding 10 years. The successful candidate will possess a robust background in Threat and Vulnerability Management (TVM) and...


  • New York, New York, United States Diligent Tec, Inc Full time

    Position: Senior Information Security EngineerCompany: Diligent Tec, IncEmployment Type: Contract to HireJob OverviewDiligent Tec, Inc is in search of a highly skilled Senior Information Security Engineer with a minimum of 10 years of professional experience. The successful candidate will possess a robust background in Threat and Vulnerability Management...


  • New York, New York, United States Diligent Tec, Inc Full time

    Position: Senior Information Security EngineerCompany: Diligent Tec, IncEmployment Type: Contract to HireJob OverviewWe are in search of a seasoned Senior Information Security Engineer with a minimum of 10 years of specialized experience. The successful candidate will possess a robust foundation in Threat and Vulnerability Management (TVM) as well as Data...


  • New York, New York, United States Diligent Tec, Inc Full time

    Position: Senior Cyber Security EngineerCompany: Diligent Tec, IncEmployment Type: Contract to HireJob OverviewWe are in search of a seasoned Senior Cyber Security Engineer with a minimum of 10 years of specialized experience. The successful candidate will possess a robust foundation in Threat and Vulnerability Management (TVM) as well as Data Loss...


  • New York, New York, United States Clark Davis Associates Full time

    Position Overview: The Director of Security Engineering at Clark Davis Associates will spearhead the formulation and execution of innovative security engineering methodologies and solutions to protect our worldwide operations. This position necessitates a profound comprehension of security technologies, risk assessment, and leadership capabilities to...


  • New York, New York, United States Clark Davis Associates Full time

    Position Overview: The Director of Security Engineering at Clark Davis Associates will spearhead the formulation and execution of sophisticated security engineering strategies and solutions to protect our international operations. This position demands a profound comprehension of security technologies, risk management, and leadership capabilities to...

  • Security Officer

    2 weeks ago


    New York, New York, United States Inter-Con Security Full time

    Job SummaryWe are seeking a highly skilled and dedicated Security Officer to join our team at Inter-Con Security. As a Security Officer, you will be responsible for providing a safe and secure environment for our clients and their employees.Key ResponsibilitiesMonitor and respond to security breaches and incidentsMonitor life safety equipment and report any...

Security Engineer I, Offensive Security Penetration Testing

3 months ago


New York, New York, United States Amazon Services LLC Full time
Amazon's Information Security Penetration Testing Team is seeking a Security Engineer to help keep Amazon secure for its customers.

In this role, you will attack Amazon's services, applications, and websites to discover security issues and report them to our internal technology teams.

This position will provide you with challenging opportunities, both technologically and as a leader, but will also be a great deal of fun if hacking Amazon alongside a team of highly skilled individuals sounds exciting to you.

A Security Engineer at Amazon is expected to be strong in multiple domains.

Engineers in this role work closely with teams throughout Information Security, as well as provide technical leadership and advice to teams and leaders throughout Amazon.

You will be in direct contact with teams in a variety of business verticals, giving you first hand knowledge about how Amazon is built and how it operates at a deep, technical level.

Additionally, you will leverage the knowledge you gain about Amazon to find new ways to break services, processes, and technologies throughout the company.


Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals.

You will demonstrate resilience and navigate ambiguous situations with composure and tact.

You will be expected to provide thought leadership for the organization as you discover, invent, and innovate throughout the course of your duties.

Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its customers secure.

Key job responsibilities

  • Conducting high quality application penetration tests independently, or as part of a team
  • Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
  • Contributing to team tooling, innovation, and improvements
  • Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings
About the team
About Amazon Security

Diverse Experiences
Amazon Security values diverse experiences.

Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply.

If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences.

Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services.

We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We're continuously raising our performance bar as we strive to become Earth's Best Employer.

That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony.

Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture.

When we feel supported in the workplace and at home, there's nothing we can't achieve.

We are open to hiring candidates to work out of one of the following locations:

Virtual Location - NY

BASIC QUALIFICATIONS

  • Bachelor's degree in Computer Science or related field, or equivalent industry experience with threat modeling, design review, or other threat analysis techniques
  • 1+ years of experience in a penetration testing or information security role
  • 1+ years of professional experience with security engineering practices, including: web application security, network security, authentication and authorization protocols, cryptography, automation, and other software security disciplines
  • 1+ years of experience with dynamic and manual code auditing to identify security issues
  • 1+ years of experience with interpreted or compiled languages (e.g. Python, Ruby, C/C++, Java, .NET)
PREFERRED QUALIFICATIONS

  • Experience with mobile application penetration testing
  • Knowledge of cloud service providers and their offerings, preferably AWS, and its various technologies and services
  • Experience in various security domains (e.g. system and network security, authentication and security protocols, cryptography, application security, incident response)
  • Experience in developing security tooling and automation
  • Advanced degree in Computer Science or related field and experience in CTF competitions, CVE research, and/or Bug Bounty recognition