Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Engineer II, Offensive Security Penetration Testing image - Rise Careers
Job details

Security Engineer II, Offensive Security Penetration Testing - job 1 of 5

Description

Amazon’s Information Security Penetration Testing Team is seeking a Security Engineer to help keep Amazon secure for its customers. In this role, you will attack Amazon’s services, applications, and websites to discover security issues and report them to our internal technology teams. This position will provide you with challenging opportunities, both technologically and as a leader, but will also be a great deal of fun if hacking Amazon alongside a team of highly skilled individuals sounds exciting to you.

A Security Engineer at Amazon is expected to be strong in multiple domains. Engineers in this role work closely with teams throughout the Amazon Security organization, as well as provide technical leadership and advice to teams and leaders throughout Amazon. You will be in direct contact with teams in a variety of business verticals, giving you first hand knowledge about how Amazon is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Amazon to find new ways to break services and technologies throughout the company.

Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. You will demonstrate resilience and navigate ambiguous situations with composure and tact. You will be expected to provide thought leadership for the organization as you discover, invent, and innovate throughout the course of your duties. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its customers secure.

Key job responsibilities
- Conducting high quality application penetration tests independently, or as part of a team
- Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
- Contributing to team tooling, innovation, and process improvements
- Communicating and collaborating with partner security teams, service owners, and senior leadership to influence and prioritize the resolution of discovered security findings

About the team
About Amazon Security

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- Bachelor's degree in computer science or equivalent
- 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- 3+ years of experience in a penetration testing or similar offensive security role

Preferred Qualifications

- Experience with AWS products and services
- 1+ years experience with GenAI application penetration testing (prompt testing), network penetration testing, and/or mobile penetration testing

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Average salary estimate

$174400 / YEARLY (est.)
min
max
$136000K
$212800K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Engineer II, Offensive Security Penetration Testing, Amazon

Are you ready to take your skills to the next level at Amazon? We're on the lookout for a Security Engineer II, specializing in Offensive Security Penetration Testing. In this dynamic role, you'll be part of Amazon’s Information Security Penetration Testing Team, where your mission will be to attack Amazon’s services, applications, and websites to uncover security vulnerabilities and report them to our talented internal technology teams. Trust us, this isn’t just another job; it’s an adventure! You’ll be empowered with both technical challenges and leadership opportunities, joining forces with a crew of highly skilled individuals who share your passion for security and innovation. As a Security Engineer at Amazon, you'll play a pivotal role, working closely with various teams across the entire organization. You'll not only gain deep, technical insights into how we operate but also leverage that knowledge to discover new ways to enhance our security measures. Communication will be key, as you’ll collaborate with different security teams and stakeholders to prioritize and resolve security findings. We want someone with exemplary judgment who can balance short-term fixes with long-term security objectives. A strong sense of customer obsession is critical, as your ultimate goal is to ensure that Amazon and its customers stay secure and protected. If you're ready to hack, innovate, and lead within one of the most recognized brands in the world, Amazon is the place for you!

Frequently Asked Questions (FAQs) for Security Engineer II, Offensive Security Penetration Testing Role at Amazon
What are the key responsibilities of a Security Engineer II at Amazon?

As a Security Engineer II at Amazon, your key responsibilities will include conducting high-quality application penetration tests either independently or as part of a collaborative team. You'll create detailed engagement plans, thoroughly document your findings, and provide actionable remediation recommendations. Additionally, contributing to team tooling, innovation, and process improvements will be central to your role. You'll also be expected to communicate effectively with partner security teams, service owners, and senior leadership to influence the resolution of security findings.

Join Rise to see the full answer
What qualifications are required for the Security Engineer II position at Amazon?

To qualify for the Security Engineer II position at Amazon, you should have a Bachelor's degree in computer science or a related field and at least 3 years of experience in programming using languages such as Python, Ruby, or Java. Additionally, 3 years in a penetration testing or similar offensive security role, along with experience in threat modeling, secure coding practices, and network security, are required. A strong understanding of AWS products and services is also preferable.

Join Rise to see the full answer
How does the Security Engineer II at Amazon contribute to career growth?

Being a Security Engineer II at Amazon offers ample opportunities for career growth. The role encourages knowledge-sharing, interaction with diverse teams, and participation in ongoing training and development programs. Amazon values continuous learning, and the exposure you'll receive across various business verticals will help you build a comprehensive skill set, making it an ideal environment for advancing your career in security.

Join Rise to see the full answer
What is the work culture like for a Security Engineer II at Amazon?

At Amazon, the work culture for a Security Engineer II is collaborative, inclusive, and focused on shared learning experiences. The team values diverse perspectives and celebrates innovative ideas that help tackle tough security challenges. With flexible work arrangements and a strong emphasis on work-life balance, employees are supported in both their personal and professional lives, fostering a positive workplace environment.

Join Rise to see the full answer
What skills are essential for the Security Engineer II role at Amazon?

Essential skills for the Security Engineer II role at Amazon include strong programming abilities in languages like Python, Ruby, or Java, along with significant experience in penetration testing and offensive security practices. Critical thinking, problem-solving, and communication skills are equally important for effectively conducting tests, documenting your findings, and collaborating with different teams across the organization.

Join Rise to see the full answer
Common Interview Questions for Security Engineer II, Offensive Security Penetration Testing
Can you explain your experience with application penetration testing?

When answering this question, detail specific projects where you've conducted application penetration tests, mentioning the tools and techniques you used. Emphasize your methodical approach to discovering vulnerabilities and how you documented and reported your findings to stakeholders.

Join Rise to see the full answer
How do you prioritize security issues during your testing?

Explain your process for prioritizing security issues by discussing factors like the potential impact on the system, ease of exploitation, and business context. Mention any frameworks or methodologies you use to evaluate and categorize vulnerabilities effectively.

Join Rise to see the full answer
What are some common vulnerabilities you look for in web applications?

Discuss common vulnerabilities such as SQL injection, cross-site scripting (XSS), and insecure authentication. Provide examples of how you've discovered these vulnerabilities in past roles and the steps you recommended for remediation.

Join Rise to see the full answer
Describe a particularly challenging penetration test you've conducted.

Share a specific example of a challenging penetration test, outlining the context, the obstacles you faced, and how you overcame them. Highlight the skills you utilized and what you learned from the experience.

Join Rise to see the full answer
What tools do you prefer for penetration testing and why?

Mention specific tools like Burp Suite, Metasploit, or OWASP ZAP that you regularly use, explaining why you favor them in your testing process. Discuss how these tools align with your methodology and enhance the effectiveness of your tests.

Join Rise to see the full answer
How do you stay current with the latest security trends and techniques?

Discuss your strategies for staying updated on security trends, such as following security blogs, attending conferences, and participating in penetration testing communities. Highlight specific resources you find particularly beneficial.

Join Rise to see the full answer
Can you describe your experience working with AWS security services?

Talk about any direct experience you have with AWS security services, including IAM, AWS Shield, or AWS WAF. If applicable, share how you’ve integrated these services into your security testing process to protect cloud resources effectively.

Join Rise to see the full answer
How do you handle discovering a major vulnerability during a test that could affect customers?

Explain your ethical responsibility when discovering significant vulnerabilities. Discuss the importance of timely communication with the appropriate teams, following documented protocols, and prioritizing remediation efforts to ensure customer safety.

Join Rise to see the full answer
What are your thoughts on the balance between security and user experience?

Articulate your view on the necessity of balance between security measures and user experience. Discuss examples of how you've implemented secure practices without severely impacting user workflow or application functionality.

Join Rise to see the full answer
Have you ever had a disagreement with a team member regarding a security finding? How did you resolve it?

Share a situation where you encountered a disagreement, focusing on how you communicated with your team member to discuss perspectives professionally. Highlight the importance of fostering open dialogue and seeking common ground for achieving security goals.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
McDonald's Corporation Hybrid 110 N Carpenter St, Chicago, IL 60607, USA
Posted 2 days ago
Photo of the Rise User
SpaceX Hybrid Cape Canaveral, FL
Posted 5 days ago
Mission Driven
Social Impact Driven
Passion for Exploration
Reward & Recognition
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Posted 11 days ago
Photo of the Rise User
Posted 9 days ago

Amazon is guided by four principles: customer obsession rather than competitor focus, passion for invention, commitment to operational excellence, and long-term thinking.

1789 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
BENEFITS & PERKS
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 13, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!