Security Engineer II, Offensive Security Penetration Testing

2 days ago


Washington DC United States Amazon Full time
Security Engineer II, Offensive Security Penetration Testing

Job ID: 2817030 | Amazon.com Services LLC

Amazon’s Information Security Penetration Testing Team is seeking a Security Engineer to help keep Amazon secure for its customers. In this role, you will attack Amazon’s services, applications, and websites to discover security issues and report them to our internal technology teams. This position will provide you with challenging opportunities, both technologically and as a leader, but will also be a great deal of fun if hacking Amazon alongside a team of highly skilled individuals sounds exciting to you.

A Security Engineer at Amazon is expected to be strong in multiple domains. Engineers in this role work closely with teams throughout the Amazon Security organization, as well as provide technical leadership and advice to teams and leaders throughout Amazon. You will be in direct contact with teams in a variety of business verticals, giving you first hand knowledge about how Amazon is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Amazon to find new ways to break services and technologies throughout the company.

Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. You will demonstrate resilience and navigate ambiguous situations with composure and tact. You will be expected to provide thought leadership for the organization as you discover, invent, and innovate throughout the course of your duties. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its customers secure.

Key job responsibilities
  1. Conducting high quality application penetration tests independently, or as part of a team
  2. Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
  3. Contributing to team tooling, innovation, and process improvements
  4. Communicating and collaborating with partner security teams, service owners, and senior leadership to influence and prioritize the resolution of discovered security findings
BASIC QUALIFICATIONS
  1. 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  2. Bachelor's degree in computer science or equivalent
  3. 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  4. 3+ years of experience in a penetration testing or similar offensive security role
PREFERRED QUALIFICATIONS
  1. Experience with AWS products and services
  2. 1+ years experience with GenAI application penetration testing (prompt testing), network penetration testing, and/or mobile penetration testing

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

#J-18808-Ljbffr

  • Minneapolis, MN, United States GoTo Full time

    GoTo Businesses of all sizes trust GoTo to power business growth and support customers. Explore our business phone system, contact center, and IT support products. View all jobs at GoTo Where you’ll work: Anywhere within Hungary Offensive Security at GoTo The Offensive Security team conducts various security assessments in a variety of domains;...


  • Washington, United States Amazon Full time

    Senior Security Engineer , AWS Offensive SecurityJob ID: 2831178 | Amazon Development Center U.S., Inc.Do you enjoy finding unique security issues? Do you enjoy protecting customers at scale? Do you like challenging assumptions? On the AWS Offensive Security team, you will help ensure our devices, applications, services, and systems are designed and...


  • Charleston, SC, United States Soteria Full time

    Senior Offensive Security Consultant (Pentester) Established in 2014 and based in Charleston, South Carolina, Soteria's expertise in the cybersecurity domain is predicated upon the accumulated practical experience across all team members. Soteria's security professionals have held leading positions in private industries, state governments, and federal...


  • , SC, United States Soteria Full time

    Senior Offensive Security Consultant (Cloud) Established in 2014 and based in Charleston, South Carolina, Soteria's expertise in the cybersecurity domain is predicated upon the accumulated practical experience across all team members. Soteria's security professionals have held leading positions in private industries, state governments, and federal...


  • Washington, United States SiriusXM Full time

    Responsibilities: Who We Are: SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners -- in the car, at home, and anywhere on the go with connected devices....


  • Washington, United States SiriusXM Full time

    Responsibilities: Who We Are: SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners -- in the car, at home, and anywhere on the go with connected devices....


  • Washington, DC, United States Cannon Security Products Full time

    About the jobThe Integrity, Investigations, Intelligence and Events (i3E) teams at Meta are dedicated to protecting the users of our family of applications (e.g. Facebook, Instagram, WhatsApp, Oculus) from a multitude of threats including criminal organizations, human trafficking and exploitation, and scams/fraud. We are seeking security engineers to...


  • Washington, DC, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, DC, United States GLO Comms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Plano, TX, United States PepsiCo Full time

    Job DescriptionOverviewPepsiCo’s Global offensive Security Program is responsible for driving offensive Security testing and continuous monitoring to identify and manage security risks. Our mission is to make security risks visible and actionable to the business and ensure that vulnerabilities are addressed promptly and effectively. This role will be...


  • Washington, United States Diverse Lynx Full time

    Job Title: Penetration Testing EngineeringRemoteContract RoleJob Description/ ResponsibilitiesExperience must include: 1. Security testing of custom solutions, integrations with ERP solutions and other commercial of the shelf solutions, application middleware (API, application servers, etc.), etc. that are on-premise and/or in the cloud in web, fat client or...


  • Las Vegas, NV, United States Eviden Full time

    Job title: Security Engineer Level IILocations: Las Vegas NVType: Fulltime with Eviden (An ATOS Business)Position Summary The primary objective of the Security Engineer II is to provide support to the Security Analysts on the team, create documentation, deploy new security tools, and maintain existing security tools. The ideal candidate has 3 or more years...


  • Palo Alto, CA, United States NoWorkerLeftBehind LLC Full time

    ️ Experienced in Offensive Security - as a Malware Engineer, Red Teamer, or Ethical Hacker. Deep interest in Generative AI Agents - must have used generative AI and ideally AI Agents or Copilots before and understand related concepts. Experience or certifications related to pen-testing and malware are a big plus. We welcome spanerse candidates of all...


  • Washington, DC, United States Editech Staffing Full time

    We are seeking a Lead Mobile Security Engineer to join a growing team! In this role, you'll lead security testing projects, conduct in-depth code reviews, and ensure mobile applications and developer workflows are secure.Benefits IncludeHealth, Vision and Dental InsuranceGenerous Paid Time Off401K MatchingCompletion of I-9, verifying US work authorization...


  • Washington, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • washington, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, United States Cannon Security Products Full time

    About the job The Integrity, Investigations, Intelligence and Events (i3E) teams at Meta are dedicated to protecting the users of our family of applications (e.g. Facebook, Instagram, WhatsApp, Oculus) from a multitude of threats including criminal organizations, human trafficking and exploitation, and scams/fraud. We are seeking security engineers to...


  • Washington, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...


  • Washington, United States Glocomms Full time

    We are are partnered with a leading real estate data analytics company to bring on a Senior Security Engineer to join their offensive security team. This role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance their security posture. This engineer will conduct thorough adversary emulation...