Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Pentest Security Engineer, Devices & Services Pentesting image - Rise Careers
Job details

Pentest Security Engineer, Devices & Services Pentesting

Description

Come join our penetration testing team dedicated to the detection and exploitation of vulnerabilities from Amazon’s consumer services and devices to the Kuiper satellites. This includes conducting in-depth reviews of complex service workflows including authentication mechanisms, AI, mobile, web applications, and web service APIs. Pentesters also invent new ways to automate and improve their work with techniques including AI/LLMs, fuzzing, detection at scale, and static analysis.

Our team operates under the Amazon Devices and Services Trust & Security (DSTS) organization which was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers’ trust, data, and the systems on which they rely. We protect customers by performing security reviews, offensive testing, vulnerability assessments, and provide guidance for remediations. We drive down costs by building and automating security foundations and integrating them into design and release processes. DSTS builds the foundational capabilities that raise an org-wide security bar across the growing diversity of D&S businesses - securing 100+ device types, 12,000+ services, and 100+ product lines that are developed and operated by more than 16,000+ builders.

The DSTS penetration testing organization is growing and seeking an experienced web penetration tester to help shape the future of Amazon’s service security. You will work with builder teams and product owners to perform penetration testing and identify high-impact security vulnerabilities across the web services ecosystem supporting Amazon’s devices. The ideal candidate will be expected to comprehend large complex web service architectures, dive deep into a service's source code, and to get some exposure to device penetration tests. This role will provide you with challenging technical opportunities and will also be a great deal of fun if hacking Amazon sounds exciting to you!

In this role, you will be part of a dedicated team of talented penetration testers identifying vulnerabilities in the devices and services ecosystem. You will strive to understand systems, software, and services deeply and develop creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping millions of customers that rely on Amazon’s consumer products safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams. You're well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization. If you're passionate about finding security bugs, writing tools to enhance manual testing capabilities, automating repetitive tasks, and enjoy seeing your work impact Amazon consumer devices and services, then this position is for you. Candidates from mid to senior level are encouraged to apply.

Key job responsibilities
- Contribute to penetration tests against services and software released by Amazon’s Devices & Services organization. This includes working closely with builder teams to find vulnerabilities, develop proof of concept exploits, report findings, and validate patches.
- Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.
- Review and influence technical solutions to mitigate security vulnerabilities by providing actionable long-term risk mitigation guidance to drive security improvements.
- Provides impactful security contributions to large product lines through close collaboration with our partner builder teams.
- Develop detailed technical documentation describing identified vulnerabilities, associated impact, and recommended remediation to guide communication with internal engineering stakeholders and leadership.
- Continuous growth and development of technical skillsets while contributing to standing projects for program improvement in DSPT.

About the team
While the majority of our Security team are based in the US, by applying to this position your application will be considered for all locations we hire for in the world, however candidates should expect to accommodate US time for necessary meetings.
Our team puts a high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren’t focused on how many hours you spend at work or online. Instead, we’re happy to offer a flexible schedule so you can have a more productive and well-balanced life—both in and outside of work.
Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about career growth and strive to assign projects based on what will help each team member develop into a better-rounded engineer and enable them to take on more complex tasks in the future.

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

- Bachelor’s degree in Computer Science or related field and 1+ year of equivalent industry experience or 3+ years of equivalent industry experience.
- Core understanding of web application and service API vulnerabilities (e.g. mass assignment, broken object/function level authorization, JWT/OAuth, injection, business logic flaws, excessive data exposure, etc.).
- Experience tracing sources and sinks during code review to identify vulnerabilities, and providing contextual remediation guidance to address vulnerability root cause.
- Experience designing and reviewing secure system architectures through the use of Threat Modeling incorporating sophisticated and modern attacks.
- Knowledge of cloud service providers and their offerings, preferably AWS, and its various technologies and services.

Preferred Qualifications

- Foundational knowledge of hardware security fundamentals.
- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition.
- Experience with Microservice architectures, AI/ML technologies, scripting and tooling, or pentesting as part of an SDLC operation of a large-scale enterprise environment.
- Published security research (e.g. conference presentations, whitepapers, blog posts).

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $125,500/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Average salary estimate

$169150 / YEARLY (est.)
min
max
$125500K
$212800K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Pentest Security Engineer, Devices & Services Pentesting, Amazon

Join Amazon as a Pentest Security Engineer within the Devices & Services Pentesting team, where you'll unleash your pentesting prowess to safeguard cutting-edge technologies from vulnerabilities! Your role will involve diving deep into an intriguing array of systems—ranging from consumer services to Kuiper satellites—conducting in-depth penetration tests and reviews of complex service workflows. You’ll be exploring authentication mechanisms, mobile applications, AI, and web service APIs. Creativity is key as you invent innovative automation techniques using AI/LLMs, fuzzing, and static analysis to streamline processes. As a valued member of the Amazon Devices and Services Trust & Security team, you’ll help identify high-impact security vulnerabilities while collaborating closely with builder teams and product owners. Here, you won't just report your findings; you'll develop proof of concept exploits and share essential remediation strategies that drive security improvements across a vast network of over 12,000 services and more than 100 device types. Your insights will help secure the foundation on which Amazon operates, thereby protecting millions of customers who trust our devices and services. If the idea of contributing to such a mission and working within a culture that prioritizes mentorship, career growth, and work-life balance resonates with you, come explore the exciting challenges awaiting you as a Pentest Security Engineer at Amazon!

Frequently Asked Questions (FAQs) for Pentest Security Engineer, Devices & Services Pentesting Role at Amazon
What are the main responsibilities of a Pentest Security Engineer at Amazon?

As a Pentest Security Engineer at Amazon, your primary responsibilities include conducting penetration tests for various services and products, analyzing source code for vulnerabilities using both manual and automated tools, and working closely with builder teams to influence security improvements. Your contributions play a pivotal role in safeguarding millions of users by identifying security flaws, developing exploit proofs, reporting findings, and guiding teams on effective remediation strategies.

Join Rise to see the full answer
What qualifications are required for a Pentest Security Engineer position at Amazon?

To qualify for the Pentest Security Engineer role at Amazon, candidates should possess a Bachelor’s degree in Computer Science or a related field along with at least 1 year of relevant experience, or possess 3 years of equivalent industry experience. A core understanding of web application and service API vulnerabilities, as well as proficiency in analyzing source code, is essential for success in this role.

Join Rise to see the full answer
How does the Amazon Pentest Security Engineer role support career growth?

At Amazon, the Pentest Security Engineer position fosters career growth through a culture of mentorship, knowledge-sharing, and continuous learning opportunities. The dynamic environment supports engineers in honing their technical skills while contributing to impactful projects, making it an ideal space for developing into a well-rounded professional capable of taking on increasingly complex tasks.

Join Rise to see the full answer
What tools and techniques will a Pentest Security Engineer use at Amazon?

Pentest Security Engineers at Amazon utilize a wide range of tools and techniques including automated static analysis, threat modeling, and various pentesting methodologies. Familiarity with AI/ML technologies, scripting for automation, and knowledge of cloud services, particularly AWS, also plays a significant role in executing effective penetration tests across Amazon's vast ecosystem.

Join Rise to see the full answer
What is the team culture like for Pentest Security Engineers at Amazon?

The culture for Pentest Security Engineers at Amazon is built on inclusivity, collaboration, and knowledge sharing. The team values work-life balance, encourages diverse perspectives, and supports new hires through mentoring and training programs, creating a welcoming environment where engineers can thrive personally and professionally.

Join Rise to see the full answer
Common Interview Questions for Pentest Security Engineer, Devices & Services Pentesting
What experience do you have with conducting penetration tests for web applications?

In your response, detail your hands-on experience with various testing methodologies, the types of web applications you’ve tested, and any specific vulnerabilities you have successfully exploited. Highlight how you document your findings and collaborate with development teams to facilitate remediation.

Join Rise to see the full answer
Can you explain a complex vulnerability you identified and how you approached it?

Choose a specific vulnerability you've encountered, explain its implications and the steps you took to replicate and document it. Discuss how you provided remediation guidance to the respective development team and the outcome of those efforts.

Join Rise to see the full answer
How do you prioritize vulnerabilities and decide which ones to address first?

Discuss your methodology for assessing risk and impact, such as considering factors like the potential damage an exploit might cause, the number of users affected, and the exploitability of the vulnerability. Explain how you align your prioritization process with business objectives.

Join Rise to see the full answer
What tools do you find most effective in your penetration testing work?

Share the tools you regularly use for penetration testing, such as Burp Suite, OWASP ZAP, or custom scripts you’ve developed. Discuss how you integrate these tools into your testing framework and their specific benefits in identifying vulnerabilities.

Join Rise to see the full answer
Describe your experience with threat modeling in the context of secure software development.

Talk about your familiarity with threat modeling techniques—like STRIDE or PASTA—and how you have applied them to assess potential security risks during the software development lifecycle. Emphasize how this proactive approach helps to prevent security issues down the line.

Join Rise to see the full answer
How do you stay updated on the latest security vulnerabilities and trends?

Mention the resources you rely on to stay informed, which may include vulnerability databases, online forums, security newsletters, or participation in Capture The Flag competitions. Explain how continuous learning contributes to your effectiveness as a pentester.

Join Rise to see the full answer
Can you provide an example of a successful collaboration with a development team to improve security?

Detail a specific instance where you worked closely with a development team, explaining the vulnerability identified, the collaborative process for remediation, and the outcome of the efforts. Highlight your communication strategies and any tools that facilitated the collaboration.

Join Rise to see the full answer
What are your thoughts on automation in penetration testing?

Express your views on the benefits and limitations of automation in pentesting. Discuss how you effectively incorporate automation while ensuring thoroughness in manual testing, and highlight any automation solutions you have developed or utilized.

Join Rise to see the full answer
What is your approach to documenting and reporting vulnerabilities?

Describe your structured approach to vulnerability documentation, emphasizing clarity and detail in your reports. Discuss the importance of actionable insights and recommendations in your communications with technical and non-technical stakeholders.

Join Rise to see the full answer
What motivates you about working in security and pentesting?

Convey your passion for cybersecurity and the thrill of finding vulnerabilities. Discuss how this role fits your career aspirations, your commitment to safeguarding users, and the sense of accomplishment you experience when tackling complex security challenges.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Mattel Hybrid 333 Continental Blvd, El Segundo, CALIFORNIA
Posted 22 hours ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Posted 3 hours ago
Posted 2 days ago
Photo of the Rise User
Posted 4 days ago
Photo of the Rise User
NBCUniversal Remote 904 Sylvan Ave, Englewood Cliffs, NEW JERSEY
Posted 2 days ago

Amazon is guided by four principles: customer obsession rather than competitor focus, passion for invention, commitment to operational excellence, and long-term thinking.

1758 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
BENEFITS & PERKS
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 6, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!