Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Engineer II, Offensive Security Penetration Testing image - Rise Careers
Job details

Security Engineer II, Offensive Security Penetration Testing - job 1 of 4

Description

Amazon’s Information Security Penetration Testing Team is seeking a Security Engineer to help keep Amazon secure for its customers. In this role, you will attack Amazon’s services, applications, and websites to discover security issues and report them to our internal technology teams. This position will provide you with challenging opportunities, both technologically and as a leader, but will also be a great deal of fun if hacking Amazon alongside a team of highly skilled individuals sounds exciting to you.

A Security Engineer at Amazon is expected to be strong in multiple domains. Engineers in this role work closely with teams throughout Information Security, as well as provide technical leadership and advice to teams and leaders throughout Amazon. You will be in direct contact with teams in a variety of business verticals, giving you first hand knowledge about how Amazon is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Amazon to find new ways to break services, processes, and technologies throughout the company.

Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. You will demonstrate resilience and navigate ambiguous situations with composure and tact. You will be expected to provide thought leadership for the organization as you discover, invent, and innovate throughout the course of your duties. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its customers secure.

Key job responsibilities
* Conducting high quality application penetration tests independently, or as part of a team
* Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
* Contributing to team tooling, innovation, and improvements
* Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings

About the team
About Amazon Security

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- Bachelor's degree in computer science or equivalent
- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- 3+ years of experience in a penetration testing or similar offensive security role

Preferred Qualifications

- 4+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Experience with AWS products and services

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Average salary estimate

$174400 / YEARLY (est.)
min
max
$136000K
$212800K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Engineer II, Offensive Security Penetration Testing, Amazon

Are you ready to take on a challenge that combines your passion for security with the excitement of working at Amazon? As a Security Engineer II specializing in Offensive Security Penetration Testing, you'll be at the forefront of keeping our services, applications, and websites secure. Your job will entail conducting innovative penetration tests to unearth security vulnerabilities and collaborating closely with various teams to report your findings effectively. You'll be a key player in Amazon's Information Security Penetration Testing Team, which thrives on curiosity, creativity, and a deep commitment to security. This isn't just another job—it's an opportunity to work alongside highly skilled professionals while having fun 'hacking' in a supportive environment. Your role will require you to display exemplary judgment and a strong sense of customer obsession, ensuring that security measures align with both short-term and long-term company goals. You'll also contribute to enhancements in team processes and tooling while making key communications with stakeholders throughout Amazon. If you're someone who values a diverse and inclusive culture, enjoys challenges, and is eager to innovate in the security domain, then we invite you to explore this opportunity with us at Amazon in California!

Frequently Asked Questions (FAQs) for Security Engineer II, Offensive Security Penetration Testing Role at Amazon
What are the key responsibilities of a Security Engineer II at Amazon?

As a Security Engineer II at Amazon, your primary responsibilities will include conducting high-quality application penetration tests, creating detailed engagement plans, documenting your findings, and driving the resolution of security issues by collaborating with various teams. You'll not only be involved in identifying potential vulnerabilities but will also contribute significantly to the team's tooling and process improvements.

Join Rise to see the full answer
What qualifications do I need to apply for Security Engineer II at Amazon?

To apply for the Security Engineer II position at Amazon, you should have a Bachelor's degree in computer science or a related field, along with at least 3 years of experience in programming languages such as Python, Java, or C++. Additionally, having 3 years of experience in penetration testing or a similar offensive security role is crucial for success in this role.

Join Rise to see the full answer
How does the Security Engineer II role contribute to customer security at Amazon?

The Security Engineer II at Amazon plays a vital role in maintaining customer security by identifying and mitigating vulnerabilities in Amazon's products and services. The insights gained through penetration testing allow the team to implement stronger security protocols, thus providing a safe and trusted environment for customers.

Join Rise to see the full answer
What is the team culture like for Security Engineers at Amazon?

The team culture for Security Engineers at Amazon is collaborative, innovative, and inclusive. You will be part of a community that values diverse perspectives and experiences, encouraging continuous learning and sharing of knowledge. Events focused on Diversity, Equity, and Inclusion (DEI) are commonplace, promoting a workplace where everyone can thrive and contribute to solving security challenges.

Join Rise to see the full answer
What career growth opportunities exist for Security Engineer II at Amazon?

Amazon’s Security Engineer II position offers extensive career growth opportunities. Employees have access to training and mentorship programs to develop their skills across various domains such as cloud security, threat modeling, and compliance. There’s a culture of promoting from within, so high-performing engineers may have the chance to advance into senior or specialized roles as they gain experience.

Join Rise to see the full answer
Common Interview Questions for Security Engineer II, Offensive Security Penetration Testing
Can you describe a challenging penetration test you conducted in your previous role?

When answering this question, focus on the specifics of the project, the methodology you used, the challenges faced, and how you overcame them. Highlight the importance of collaboration with other teams and detail the impact of your findings on improving security.

Join Rise to see the full answer
How do you stay up-to-date with the latest security vulnerabilities and trends?

Interviewers want to know that you're proactive in enhancing your skills. Share resources such as blogs, forums, or courses you follow, as well as any industry conferences or events you attend. Discuss how you apply this knowledge to your work.

Join Rise to see the full answer
What programming languages are you proficient in, and how have you used them in security?

Be ready to discuss your proficiency in languages relevant to security, such as Python or Ruby. Provide examples of projects or scenarios where you've utilized these skills to develop security tools or scripts. Demonstrating practical applications will show your hands-on experience.

Join Rise to see the full answer
Can you explain your approach to threat modeling?

Discuss your systematic approach to identifying, evaluating, and mitigating potential threats. Include techniques or frameworks you've used, and be sure to highlight any particular scenarios where your threat modeling led to significant improvements in security posture.

Join Rise to see the full answer
What is your experience with AWS security practices?

Since this role prefers candidates with AWS experience, discuss your knowledge of AWS security tools, compliance, and best practices. Mention any specific experience with settings, controls, or services that enhance the security of AWS deployments.

Join Rise to see the full answer
How do you prioritize security findings during a penetration test?

Emphasize your analytical skills by explaining how you assess the severity of each finding based on potential impact and likelihood. Discuss collaboration with stakeholders to decide on actionable remediation steps and balancing urgency with practicality.

Join Rise to see the full answer
What tools are you familiar with for penetration testing?

Talk about a variety of tools you have worked with, such as Metasploit, Burp Suite, or Nmap. Explain how you've used these tools in previous roles and the insights they provided into vulnerabilities or security improvements.

Join Rise to see the full answer
Describe a time you had to communicate complex security findings to non-technical stakeholders.

This question focuses on your communication skills. Provide an example of how you simplified technical language and effectively communicated the risks and recommendations, ensuring the audience understood the implications for their business or services.

Join Rise to see the full answer
How do you handle ambiguous situations during a security assessment?

Share your strategies for managing ambiguity, such as relying on your knowledge base, consulting with colleagues, or iterative testing. Give an example where your calm and composed demeanor led to a successful outcome despite uncertainty.

Join Rise to see the full answer
Why do you want to work as a Security Engineer II at Amazon?

Here, align your response with Amazon's values. Discuss how the company's emphasis on customer trust, security at scale, and innovation resonate with you. Highlight your desire to contribute to a culture that values learning and collaboration.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Amazon Hybrid Nashville, TN
Posted 9 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
Posted 2 days ago

Amazon is guided by four principles: customer obsession rather than competitor focus, passion for invention, commitment to operational excellence, and long-term thinking.

1758 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
BENEFITS & PERKS
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 10, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!