Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Penetration Testing Engineer, AWS GenAI Security  image - Rise Careers
Job details

Penetration Testing Engineer, AWS GenAI Security

Description

Do you enjoy finding unique security issues? Do you enjoy protecting customers at scale? Do you enjoy mentoring and leading engineers to solve problems? On the AWS Penetration Testing team, as a Security Engineer / Penetration Testing Engineer you will be responsible for the delivery of continuous assessments. You will be asked to solve complex technology problems, build tools to automate your way out of manual efforts, and influence the way Amazon services respond to and mitigate threats.

Our team is responsible for the manual assessment of all products, services and software released by AWS. We specialize in digging deep to find security issues that static analysis tools can’t, and write the tooling to help with these goals whenever possible. The AWS surface area is large and diverse, and we use results found in manual analysis to help improve our enterprise-wide automation to proactively spot and fix potential security issues to protect customers.

We are looking for a Security Engineer/Penetration Testing Engineer to help ensure our services, applications, and websites are designed and implemented to the highest security standards. You will be responsible for application, web services infrastructure and GenAI systems penetration testing. You will be responsible for automating repetitive tasks using various scripting languages. You will be responsible for mentoring and leading other engineers to deliver complex penetration tests and vulnerability assessments. You will be expected to drive automation, tooling, efficiency and advance the teams penetration testing capabilities. You will be responsible for influencing Amazon services through the creation of threat mitigation plans. You will work directly with internal teams to solve challenging software and security problems.

**This role is open to alternative locations including: Seattle, WA - Herndon, VA – Arlington, VA – Atlanta, GA - Austin, TX**


Key job responsibilities
* Perform penetration testing complex proprietary software and hardware for AWS services
* Manually audit the source code of web services and software authored in house by Amazon
* Write proof of concept code to demonstrate the severity of a potential security issue
* Provide clear communication on issues to developers that suggest and help to test the fix
* Partner with AWS developers to drive improvement in application security as a result of security review engagements
* Provide actionable long-term risk mitigation guidance to internal and external stakeholder
* Conduct independent vulnerability research pertaining to AWS relevant technologies

A day in the life
Our team is responsible for providing comprehensive security engineering support to the AWS GenAI business. We are a team comprising of application security and penetration testing engineers who work in close collaboration with service teams building AWS GenAI services.

About the team
About Amazon Security

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

- A Bachelor’s degree in Computer Science, Cybersecurity, Information Security, degree in similar technical field, or equivalent professional experience can be used in lieu of a degree.
- Minimum of 3 years of experience in security testing (Penetration testing, Vulnerability testing, Red teaming, bug hunting, CTF experience, or related field).
- Minimum of 3 years of experience with manually auditing source code (One or more of: Java, Ruby, Python, JavaScript, Rust, C, others) to find security issues.
- Minimum of 3 years of experience scripting in Python or other equivalent interpreted languages.
- Minimum of 3 years of professional experience with 2 or more areas of security engineering practices such as in web application security, network security, authentication and authorization protocols, cryptography, automation and other software security disciplines.

Preferred Qualifications

- Experience with micro-service, API-based agent, or service-oriented software architectures.
- Operations experience with CI/CD or managing distributed systems
- Experience with bug hunting, bug bounties, capture the flag, software development
- Experience with evaluating GenAI products and services.
- Experience with AWS technologies and services (e.g. S3, Lambda, EC2, KMS, IAM, etc.).

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Average salary estimate

$174400 / YEARLY (est.)
min
max
$136000K
$212800K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Penetration Testing Engineer, AWS GenAI Security , Amazon

Are you passionate about cybersecurity and love the thrill of unearthing hidden vulnerabilities? Join the AWS Penetration Testing team as a Penetration Testing Engineer focused on GenAI Security! In this exciting role, you'll dive deep into complex technology challenges, actively assessing AWS’s vast array of products and services to ensure they stand up against potential security threats. You'll lead and mentor fellow engineers, sharing your expertise as you perform in-depth penetration testing, conduct source code audits, and provide constructive feedback to enhance security measures. We value automation and innovation, so you’ll create scripts to streamline repetitive tasks, all while partnering with talented AWS developers to bolster application security. Your contributions not only protect millions of customers but also influence how services respond to and mitigate risks. This is more than just a job; it's an opportunity to make a significant impact in the world of security! Let's work together to keep AWS and its GenAI services secure and reliable. So, are you ready to embark on this journey with us? Apply now and be part of a collaborative team that values your insights and encourages your growth!

Frequently Asked Questions (FAQs) for Penetration Testing Engineer, AWS GenAI Security Role at Amazon
What responsibilities does a Penetration Testing Engineer at AWS GenAI Security have?

As a Penetration Testing Engineer at AWS GenAI Security, you will take on a variety of responsibilities. You'll perform penetration testing on proprietary software and services, audit source code, and write proof of concept code to showcase security vulnerabilities. Your role will also involve mentoring other engineers, driving automation, and influencing Amazon services by creating effective threat mitigation plans.

Join Rise to see the full answer
What qualifications are required for a Penetration Testing Engineer role at AWS?

To qualify as a Penetration Testing Engineer at AWS, you should have at least a Bachelor’s degree in Computer Science or a related field, or equivalent practical experience. Candidates must possess a minimum of 3 years in security testing, source code auditing, and scripting in languages such as Python, Java, or JavaScript, alongside experience in web application security and cryptography.

Join Rise to see the full answer
What skills are preferred for a Penetration Testing Engineer at AWS GenAI Security?

Preferred skills for a Penetration Testing Engineer at AWS GenAI Security include experience with microservice architectures, familiarity with CI/CD operations, and knowledge of AWS technologies like EC2 and S3. Having hands-on experience with bug hunting and participation in Capture The Flag challenges can also enhance your candidacy.

Join Rise to see the full answer
How does AWS ensure a diverse and inclusive workplace for the Penetration Testing Engineer position?

AWS is committed to creating a diverse and inclusive workplace. For the Penetration Testing Engineer position, they encourage candidates from various backgrounds to apply, valuing unique experiences and perspectives. This commitment extends to ongoing DEI events and learning opportunities aimed at enhancing team collaboration and creativity.

Join Rise to see the full answer
What can a candidate expect from the work culture at AWS as a Penetration Testing Engineer?

Candidates can expect a collaborative, inclusive, and growth-oriented work culture at AWS. As a Penetration Testing Engineer, you will have access to continuous learning opportunities, a focus on work-life balance, and a supportive environment where your insights and expertise are valued, fostering your career advancement.

Join Rise to see the full answer
Common Interview Questions for Penetration Testing Engineer, AWS GenAI Security
What is your experience with penetration testing tools and methodologies?

When answering this question, provide specific examples of tools you’ve used, such as Metasploit or Burp Suite. Describe the methodologies you adhere to, like OWASP standards, and offer insights into how you apply these techniques in real-world scenarios to identify and address vulnerabilities.

Join Rise to see the full answer
How do you approach source code auditing?

In your response, detail your systematic approach to source code auditing, mentioning specific languages you're proficient in. Highlight any tools and techniques you use, such as static code analysis, and share a specific instance where your auditing uncovered significant vulnerabilities.

Join Rise to see the full answer
Can you describe a challenging security issue you've resolved?

Share a detailed account of a challenging security problem you encountered and the steps you took to resolve it. Discuss the impact of this issue on the organization, your problem-solving process, and the final outcome, ensuring to display your analytical thinking and technical skills.

Join Rise to see the full answer
How do you stay current with the latest security threats and vulnerabilities?

Discuss your methods for staying updated, such as reading cybersecurity blogs, participating in forums, attending conferences, and following relevant influencers on social media. Emphasize your proactive approach to continuous learning in the ever-evolving field of cybersecurity.

Join Rise to see the full answer
What scripting languages are you proficient in and how do you use them in security testing?

Be specific about your proficiency in scripting languages like Python or Ruby, and explain how you use them to automate tasks, create tools for vulnerability testing, or analyze large data sets. Provide examples of scripts you've written and the impact they had on your security testing outcomes.

Join Rise to see the full answer
What steps would you take to perform a risk assessment?

Outline a structured process for conducting a risk assessment, including identifying assets, assessing vulnerabilities, evaluating potential impacts, and determining mitigation strategies. Emphasize the importance of thorough documentation and collaboration with stakeholders to formulate effective security strategies.

Join Rise to see the full answer
How do you test the security of web applications?

Explain your approach to web application testing, including both manual and automated techniques. Discuss specific vulnerabilities you target, such as SQL injection or cross-site scripting, and the tools you employ to simulate attacks and ensure application security.

Join Rise to see the full answer
Can you give an example of how you've influenced security improvements in a team?

Share a specific instance where you advocated for security best practices within your team. Describe the issue, your proposed solutions, and how you collaborated with team members to implement changes that led to significant security enhancements.

Join Rise to see the full answer
What do you think is the most significant emerging threat in cybersecurity today?

Articulate your thoughts on current emerging threats, such as ransomware or cloud security vulnerabilities. Discuss how these threats impact organizations and what proactive measures can be taken to mitigate these risks effectively.

Join Rise to see the full answer
How would you explain complex security concepts to non-technical stakeholders?

Highlight your communication skills and ability to simplify complex concepts. Provide an example of a time you had to present security findings to a non-technical audience, focusing on clarity, analogies, and actionable insights to ensure understanding.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 6 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Posted 2 days ago
Talent Worx Remote No location specified
Posted 4 days ago
Photo of the Rise User
Continental Remote Strada Avram Imbroane, Timișoara, Romania
Posted 11 days ago
Photo of the Rise User
Posted 11 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Customer-Centric
Social Impact Driven
Rapid Growth
Maternity Leave
Paternity Leave
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Paid Holidays
Paid Time-Off
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 2 days ago

Amazon is guided by four principles: customer obsession rather than competitor focus, passion for invention, commitment to operational excellence, and long-term thinking.

2144 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
BENEFITS & PERKS
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
March 26, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Mason just viewed HR/Recruiting Assistant at Illumination
Photo of the Rise User
Someone from OH, Strongsville just viewed Used Car Buyer - Concord Toyota at Sonic Automotive
Photo of the Rise User
Someone from OH, Cincinnati just viewed Mid-level Creative (f/m/d) at Landor
P
Someone from OH, Kent just viewed Graphic Designer at ProjectGrowth
Photo of the Rise User
Someone from OH, Waverly just viewed Client Services Manager at Pepperstone
Photo of the Rise User
Someone from OH, Plain City just viewed Aesthetic Telehealth Nurse Practitioner (remote) at Moxie
Photo of the Rise User
Someone from OH, Columbus just viewed EdTech Product/Program Manager at Planner5D
S
Someone from OH, Lorain just viewed Test Engineer- Ninja at SharkNinja
Photo of the Rise User
40 people applied to SOC Analyst I at Epsilon
Photo of the Rise User
Someone from OH, Youngstown just viewed Channel Development Representative at Arrow Electronics
Photo of the Rise User
Someone from OH, Cincinnati just viewed Buyer at Novolex
k
Someone from OH, Columbus just viewed Patient Experience Coordinator at knownwell
Photo of the Rise User
19 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
Someone from OH, Columbus just viewed Store Manager - New Store Opening at Curaleaf
Photo of the Rise User
Someone from OH, Akron just viewed Finance Intern - Summer 2025 at Spectrum
Photo of the Rise User
Someone from OH, Norwalk just viewed Hybrid Account Manager-Commercial Lines at AssuredPartners
Photo of the Rise User
Someone from OH, Loveland just viewed Animator at Apex Systems Bellevue, WA at Apex Systems
Photo of the Rise User
Someone from OH, Canton just viewed Lead Jr. Toddler Teacher at All Around Children
Photo of the Rise User
Someone from OH, Mentor just viewed Site Merchandising Manager at Lovepop
Photo of the Rise User
Someone from OH, Batavia just viewed Restaurant Busser at Outback Steakhouse
Photo of the Rise User
Someone from OH, New Albany just viewed Customer Success Manager at Quisitive
Photo of the Rise User
Someone from OH, Columbus just viewed UGC Creator - USA, Female 40-50 - Contract to hire at Upwork