Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Engineer II, Offensive Security Penetration Testing image - Rise Careers
Job details

Security Engineer II, Offensive Security Penetration Testing - job 1 of 7

Description

Amazon’s Information Security Penetration Testing Team is seeking a Security Engineer to help keep Amazon secure for its customers. In this role, you will attack Amazon’s services, applications, and websites to discover security issues and report them to our internal technology teams. This position will provide you with challenging opportunities, both technologically and as a leader, but will also be a great deal of fun if hacking Amazon alongside a team of highly skilled individuals sounds exciting to you.

A Security Engineer at Amazon is expected to be strong in multiple domains. Engineers in this role work closely with teams throughout Information Security, as well as provide technical leadership and advice to teams and leaders throughout Amazon. You will be in direct contact with teams in a variety of business verticals, giving you first hand knowledge about how Amazon is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Amazon to find new ways to break services, processes, and technologies throughout the company.

Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. You will demonstrate resilience and navigate ambiguous situations with composure and tact. You will be expected to provide thought leadership for the organization as you discover, invent, and innovate throughout the course of your duties. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its customers secure.

Key job responsibilities
* Conducting high quality application penetration tests independently, or as part of a team
* Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
* Contributing to team tooling, innovation, and improvements
* Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings

About the team
About Amazon Security
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- Bachelor's degree in computer science or equivalent
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP

Preferred Qualifications

- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Experience with AWS products and services
- Experience with programming languages such as Python, Java, C++

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Average salary estimate

$174400 / YEARLY (est.)
min
max
$136000K
$212800K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Engineer II, Offensive Security Penetration Testing, Amazon

If you’re looking for an exciting opportunity as a Security Engineer II in Offensive Security Penetration Testing at Amazon, you’re in for a thrilling ride! In this pivotal role, you will engage directly in protecting Amazon’s expansive ecosystem by finding and fixing security vulnerabilities across our diverse services, applications, and websites. You’ll be working alongside a dynamic team of security professionals, and every day will present new challenges that keep your skills sharp and your mind engaged. Your mission? Conduct comprehensive penetration tests that unveil security gaps while crafting detailed reports that will help guide our internal teams towards robust solutions. Collaboration is key here; you’ll be in constant communication with various partners and teams, helping to influence and prioritize security initiatives effectively. You’ll have the autonomy to think creatively and critically about Amazon's architecture, making informed judgments that balance immediate security needs with long-term business objectives. Customer obsession is at the heart of everything we do at Amazon, and as you box in potential threats, you will also be ensuring a seamless and secure experience for millions of customers worldwide. If this challenge sounds exciting and you're passionate about security and technology, then we can’t wait for you to join us and innovate within Amazon's vibrant, fast-paced environment!

Frequently Asked Questions (FAQs) for Security Engineer II, Offensive Security Penetration Testing Role at Amazon
What are the primary responsibilities of a Security Engineer II at Amazon?

A Security Engineer II in Offensive Security Penetration Testing at Amazon is tasked with conducting in-depth application penetration tests, both individually and as part of a team. You'll create weather plans, document your findings, and communicate with various teams about remediation strategies for identified security issues. Additionally, contributing to the development of innovative tools and protocols to enhance security processes is a key part of the role.

Join Rise to see the full answer
What qualifications are required for a Security Engineer II position at Amazon?

To apply for the Security Engineer II position at Amazon, candidates should have at least 3 years of programming experience in languages such as Python, Java, or C++. A Bachelor's degree in Computer Science or a related field is essential, along with a strong knowledge of networking protocols like HTTP, DNS, and TCP/IP. Preferred qualifications include experience with AWS services and expertise in threat modeling, secure coding, and network security.

Join Rise to see the full answer
How does Amazon support the professional growth of Security Engineers?

Amazon places a strong emphasis on professional development for Security Engineers II. The company provides access to various training resources, knowledge-sharing sessions, and career advancement programs, ensuring that you constantly learn and grow in your role. The inclusive and curious culture encourages continuous learning and exploration of new ideas, making it a great place to enhance your skills.

Join Rise to see the full answer
What is the work environment like for a Security Engineer II at Amazon?

The work environment for a Security Engineer II at Amazon is dynamic and collaborative. You'll be part of a team that thrives on curiosity and innovation, working together to tackle some of the toughest security challenges in the industry. The team's culture emphasizes diversity and inclusion, allowing for a range of perspectives that enrich problem-solving and creativity.

Join Rise to see the full answer
What is the salary range for a Security Engineer II position at Amazon?

The salary range for a Security Engineer II at Amazon varies depending on location and experience, with a base pay between $136,000 and $212,800 per year across different U.S. markets. Compensation can also include equity and other forms of financial rewards as a part of a comprehensive compensation package.

Join Rise to see the full answer
Common Interview Questions for Security Engineer II, Offensive Security Penetration Testing
Can you explain your experience with penetration testing for web applications?

In response, highlight specific projects where you conducted penetration tests, detailing the methodologies you used, tools you employed, and any significant findings or outcomes that enhanced security. Make sure to illustrate your thought process and how it aligns with Amazon's priorities in security.

Join Rise to see the full answer
What programming languages are you proficient in and how have you used them in security tasks?

Discuss your experience with languages like Python or Java, providing examples of how you've leveraged these languages to develop security tools, automate testing, or analyze vulnerabilities, showcasing your technical capabilities and innovation.

Join Rise to see the full answer
How do you ensure that your security findings are effectively communicated to technical and non-technical teams?

Share your approach to documenting findings and creating reports that are clear and actionable. Discuss how you simplify complex technical language for non-technical stakeholders and ensure all teams understand the implications and required actions.

Join Rise to see the full answer
Have you ever faced a security challenge that required you to think creatively? Please describe it.

This is an opportunity to narrate an experience where traditional methods failed, and innovative thinking led you to an effective solution. Highlight the steps you took and the eventual impact on security measures.

Join Rise to see the full answer
What is your understanding of customer obsession in the context of security?

Emphasize how a focus on customer experience drives your security practices. Explain how ensuring customer trust and safety directly influences your testing strategies and remediation recommendations.

Join Rise to see the full answer
Describe a time when you worked with a diverse team. What challenges did you face, and how did it help you grow?

Reflect on an experience working in a diverse team, discussing any initial challenges and how differing perspectives led to stronger results. Highlight the importance of collaboration in enhancing security outcomes.

Join Rise to see the full answer
What tools or technologies do you prefer for performing security assessments?

Mention specific tools you have used in the past like Metasploit, Burp Suite, or OWASP ZAP, explaining their value in your testing processes and your familiarity with these technologies.

Join Rise to see the full answer
How do you stay updated with the latest security vulnerabilities and trends?

Discuss the resources you utilize, such as security blogs, forums, courses, or industry conferences. Highlight your commitment to continuous learning and adaptation in the ever-evolving security landscape.

Join Rise to see the full answer
Can you share your experience with AWS security features?

Explain your familiarity with AWS security tools such as IAM, AWS Shield, or Amazon GuardDuty, and describe how you've integrated these tools into your penetration testing practices to enhance security.

Join Rise to see the full answer
What is your approach to creating remediation plans for identified vulnerabilities?

Detail your systematic approach to identifying, analyzing, and prioritizing vulnerabilities, and how you work alongside relevant teams to develop feasible and effective remediation strategies.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 11 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Mission Driven
Social Impact Driven
Passion for Exploration
Reward & Recognition
Dandy Hybrid No location specified
Posted 9 days ago
Photo of the Rise User
Axon Hybrid Scottsdale, Arizona, United States
Posted 2 hours ago
Posted 3 days ago
Posted 6 days ago

Amazon is guided by four principles: customer obsession rather than competitor focus, passion for invention, commitment to operational excellence, and long-term thinking.

2079 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
BENEFITS & PERKS
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 13, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!