AWS Security is a global team tasked with keeping the cloud safe. To help deliver for customers on this promise, the AWS Bug Bounty team is seeking a security engineer with strong security analytic skills to join our team!
The primary responsibility of this role is to leverage your experience and internal knowledge of AWS systems to effectively triage a diverse set of incoming reports which can pertain to any of AWS's 200+ services. Technical dive deep and curiosity are a way of life on this team in order to establish the true severity of a report and what defense in depth mechanisms need to happen beyond just an immediate patch.
Automation is the key to scaling and innovation at AWS and in this role you will write automation to reduce the load on humans; everything from developing ticketing, reporting and trend identification automation.
AWS Bug Bounty has a diverse set of customers: service owners and engineers, security leadership as well as our external crowd of researchers. Strong communication skills are required when providing excellent customer service for our customers, especially when growing our external crowd. As an engineer on the team, you will be expected to help deliver insights to leadership and assist service teams in prioritizing and remediating difficult security problems.
The development of the AWS researcher community is paramount to ensuring the success of our program and of our customers. As such we seek to earn researcher trust by being as transparent as possible with our responses to their reporting and our reward structures. As part of this team you will be expected to develop external messaging for both researchers and our own customer base. Above all else, a strong sense of Customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its Customers secure with the highest priority.
This role will provide you with challenging opportunities, both technologically and as a leader to grow AWS’s Bug Bounty Program into the best on planet Earth.
Key job responsibilities
- Researching, reproducing, and responding to security issues reported through the bug bounty program
- Technical Escalation
- Managing relationships with external security researchers working with AWS's bug bounty program
- Perform deep analysis of new vulnerability classes
- Driving improvements to team tooling, automation, and processes
- Influencing program direction
- Identify and drive resolution of vulnerability trends
- Attend industry conferences and assist in hosting on site hack-a-thons and other researcher engagement activities
A day in the life
Our mornings typically start by looking at the queue of submitted reports that have already undergone initial triage by our third party partners. We single out reports that need urgent attention and then do a deep dive: reproducing, root causing and where appropriate extending the findings in the report to demonstrate maximum impact. Once done we coordinate with the internal stakeholders to drive the report until remediation.
We maintain a close partnership with other security teams across Amazon to surface reports and trend data that are relevant to their mission.
About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- Knowledge of networking protocols such as HTTP, DNS and TCP/IP
- Bachelor's degree in computer science or equivalent work experience.
- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Experience with AWS products and services
- Experience with programming languages such as Python, Java, C++
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.
Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.
If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
Are you ready to take your security expertise to new heights? As a Security Engineer on the AWS Bug Bounty team, you’ll be at the forefront of securing AWS's vast array of services. Here at Amazon, our commitment to keeping the cloud safe is unwavering, and we need a passionate individual like you to help us fulfill this promise. In this role, you'll leverage your security analytic skills to triage incoming bug reports across over 200 services. Your innate curiosity will drive your deep dives into vulnerabilities, helping to establish their true severity and the necessary defenses needed to safeguard our systems. You'll work closely with both internal stakeholders and external researchers, creating robust communications that foster trust and collaboration. We're looking for someone who isn’t just a technician but a storyteller—a communicator who can translate complex security issues into actionable insights. Automation is key in this fast-paced environment, and your programming prowess will streamline processes, enhance our tooling, and help us scale efficiently. Be prepared to attend industry conferences and engage with the security community, all while maintaining our commitment to customer obsession. Join us on this exciting journey to elevate AWS Bug Bounty into the best program on the planet and enjoy a culture that values your unique experiences. At Amazon, we believe in work-life harmony, continuous learning, and creating an inclusive environment where everyone can thrive. Become a part of our mission to keep our customers secure, and apply today!
Join Cadence as a Sr Staff Systems Engineer and take charge of optimizing and securing our Microsoft Active Directory infrastructure.
DMI seeks an experienced Network Operations Manager to oversee critical network systems for a Federal agency, ensuring efficient operations and innovative solutions.
IGS is on the lookout for a DevOps Engineer to enhance their federal IT services through innovative cloud and analytics solutions.
Amgen is looking for a Manager to lead AI literacy and go-to-market efforts to transform patient care through innovative technology.
10x Banking is on the lookout for a proactive Security Operations Engineer to elevate their security operations and support the transformation of the banking sector.
Join Pepsi Bottling Ventures as a Client Technology Specialist to lead the desktop and mobile environment support and innovation.
Join Adtalem Global Education as a Business Systems Analyst, where you’ll bridge technology and business processes in higher education.
Join Emory Healthcare as a Clinical Informatics Specialist II and drive the optimization of clinical technologies to enhance patient care.
Amazon is guided by four principles: customer obsession rather than competitor focus, passion for invention, commitment to operational excellence, and long-term thinking.
2353 jobsSubscribe to Rise newsletter