Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Sr. Penetration Testing Engineer, AWS Penetration Testing image - Rise Careers
Job details

Sr. Penetration Testing Engineer, AWS Penetration Testing

Description

Do you enjoy finding unique security issues? Do you enjoy protecting customers at scale? On the AWS Penetration Testing team, you will be responsible for the delivery of continuous assessments. You will be asked to solve complex technology problems, build tools to automate your way out of manual efforts, and influence the way Amazon services respond to and mitigate threats.

Our team is responsible for the manual assessment of all products, services and software released by AWS. We specialize in digging deep to find security issues that static analysis tools can’t, and write the tooling to help with these goals whenever possible. The AWS surface area is large and diverse, and we use results found in manual analysis to help improve our enterprise-wide automation to proactively spot and fix potential security issues to protect customers.

We are looking for a Security Engineer to help ensure our services, applications, and websites are designed and implemented to the highest security standards. You will be responsible for application, and hardware penetration testing. You will be responsible for automating repetitive tasks using various scripting languages. You will be responsible for influencing Amazon services through the creation of threat mitigation plans. You will work directly with internal teams to solve challenging software problems.

Key job responsibilities
* Perform penetration testing complex proprietary software and hardware for AWS services
* Manually audit the source code of web services and software authored in house by Amazon
* Write proof of concept code to demonstrate the severity of a potential security issue
* Provide clear communication on issues to developers that suggest and help to test the fix
* Partner with AWS developers to drive improvement in application security as a result of security review engagements
* Provide actionable long term risk mitigation guidance

About the team
About Amazon Security
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

- A Bachelor’s degree in Computer Science, Cybersecurity, similar degree, or equivalent professional experience can be used in lieu of a degree.
- Minimum of 5 years of experience in security testing (Penetration testing, Vulnerability testing, Red teaming, bug hunting or CTF experience)
- Minimum of 5 years of experience with manually auditing source code (One or more of: Java, Ruby, Python, JavaScript, Rust, C, others) to find security issues.
- Minimum of 5 years of experience scripting in Python or other equivalent interpreted languages.
- Minimum of 5 years of professional experience with security engineering practices such as in web application security, network security, authentication and authorization protocols, cryptography, automation and other software security disciplines.

Preferred Qualifications

- Experience with AWS technologies and services (e.g. S3, Lambda, EC2, KMS, IAM, etc.)
- Experience with bug hunting, bug bounties, capture the flag, software development
- Experience with multiple programming languages

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Average salary estimate

$195450 / YEARLY (est.)
min
max
$143300K
$247600K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Sr. Penetration Testing Engineer, AWS Penetration Testing, Amazon

If you’re looking for an exciting opportunity as a Sr. Penetration Testing Engineer with AWS Penetration Testing in Washington, USA, you’re in for a treat! This role merges the thrill of discovering unique security issues with the responsibility of protecting customers at a grand scale. On the AWS Penetration Testing team, you will not only conduct manual penetration tests but also tackle complex technology dilemmas while building innovative automation tools to streamline your tasks. You’ll be at the heart of ensuring Amazon's diverse range of products and services are secure against potential threats. Your responsibilities will include performing manual audits of AWS software, writing proof-of-concept code for vulnerabilities, and partnering with development teams to enhance application security. This position empowers you to influence the design and implementation of Amazon services through your expertise—your insights will guide long-term risk mitigation strategies. With a supportive team culture that values diverse experiences, you’ll find numerous opportunities for professional growth and training while enjoying a work-life balance that lets you shine both at work and beyond. So, if you’re keen on leveraging your skills in scripting, security testing, and manual audits to elevate Amazon’s security standards, this position is ideal for you!

Frequently Asked Questions (FAQs) for Sr. Penetration Testing Engineer, AWS Penetration Testing Role at Amazon
What are the primary responsibilities of a Sr. Penetration Testing Engineer at AWS?

As a Sr. Penetration Testing Engineer at AWS, your primary responsibilities include performing manual penetration testing on complex software and hardware systems, conducting thorough manual audits of source code, and writing proof-of-concept code to demonstrate vulnerabilities. You will also collaborate with developers to enhance security measures and create actionable risk mitigation strategies.

Join Rise to see the full answer
What qualifications are necessary for the Sr. Penetration Testing Engineer role at AWS?

To qualify for the Sr. Penetration Testing Engineer position at AWS, candidates should hold a Bachelor's degree in Computer Science, Cybersecurity, or a related field, along with at least five years of experience in security testing, manual source code auditing, and scripting. Familiarity with AWS services is preferred, along with a strong background in security engineering practices.

Join Rise to see the full answer
What scripting skills are important for the Sr. Penetration Testing Engineer position at AWS?

For the Sr. Penetration Testing Engineer role at AWS, proficiency in scripting languages such as Python is essential. You will use these skills to automate repetitive tasks and improve security testing processes. Familiarity with other programming languages like Java, Ruby, or JavaScript can enhance your effectiveness in this role.

Join Rise to see the full answer
How does AWS support the career growth of its Sr. Penetration Testing Engineers?

AWS emphasizes ongoing learning and development for its Sr. Penetration Testing Engineers. The company provides numerous training resources, mentorship opportunities, and access to cutting-edge technology, allowing you to continuously improve your skill set and advance your career in security.

Join Rise to see the full answer
What is the work-life balance like for Sr. Penetration Testing Engineers at AWS?

At AWS, work-life balance is a core value. As a Sr. Penetration Testing Engineer, you can expect flexible work hours and arrangements, ensuring that you can achieve professional goals without sacrificing personal commitments. This supportive culture fosters a productive and enjoyable working environment.

Join Rise to see the full answer
Common Interview Questions for Sr. Penetration Testing Engineer, AWS Penetration Testing
Can you describe your experience with penetration testing tools?

In preparing for the interview, focus on your practical experience with various penetration testing tools such as Burp Suite, Metasploit, and OWASP ZAP. Clearly outline specific scenarios where you effectively utilized these tools to identify and remediate vulnerabilities in applications or systems.

Join Rise to see the full answer
How do you approach a manual code audit?

When asked about manual code audits, explain that you begin by understanding the architecture of the codebase, followed by reviewing it for common vulnerabilities like SQL injection and cross-site scripting. Highlight your systematic approach and ability to collaborate with developers to enhance code security.

Join Rise to see the full answer
What scripting languages are you proficient in, and how have you used them in your work?

Discuss your proficiency in scripting languages, particularly Python, and provide examples of how you’ve used these skills to automate security testing processes or develop tools that streamline your testing efforts. Mention any projects where your scripting made a significant impact.

Join Rise to see the full answer
How do you stay current with the latest security vulnerabilities and threats?

You can impress interviewers by sharing your commitment to continuous learning. Mention resources such as security blogs, forums, and attending industry conferences, showcasing your proactive approach to staying informed about emerging threats and best practices in security.

Join Rise to see the full answer
Describe a challenging security issue you identified and how you mitigated it.

Give a concrete example of a specific vulnerability you encountered and the steps you took to identify, document, and mitigate it. Emphasize your role in communicating the issue effectively to stakeholders and the long-term solutions you proposed.

Join Rise to see the full answer
What considerations do you take when performing application penetration tests?

Explain the importance of understanding the application's threat model, functionality, and user input points. Discuss how this knowledge informs your testing strategy, enabling you to prioritize testing efforts effectively.

Join Rise to see the full answer
Have you ever collaborated with a development team to improve security? Share your experience.

Highlight an instance where you partnered with developers to address security concerns. Detail the collaborative process, improvements made, and the positive outcome, reinforcing the importance of communication in your security practices.

Join Rise to see the full answer
What would you do if you discovered a critical vulnerability during a penetration test?

Explain your step-by-step process for addressing a critical vulnerability, from documenting it and alerting the responsible parties to recommending immediate remediation measures. Highlight the importance of ensuring that user data remains secure while resolving the issue.

Join Rise to see the full answer
How would you explain a technical issue to a non-technical audience?

Discuss your approach to simplifying technical jargon into understandable concepts. Provide an example where you successfully communicated a complex issue to non-technical stakeholders, ensuring they recognized the significance of the vulnerability and the required actions.

Join Rise to see the full answer
Why are you interested in the Sr. Penetration Testing Engineer role at AWS?

Articulate your enthusiasm for working at AWS, emphasizing its commitment to security and innovation. Share your passion for contributing to an organization that prioritizes customer trust and continuously seeks to enhance its security posture.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 14 days ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
UWorld, LLC Remote No location specified
Posted 15 hours ago
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Posted 4 days ago
Photo of the Rise User
Posted 12 days ago

Amazon is guided by four principles: customer obsession rather than competitor focus, passion for invention, commitment to operational excellence, and long-term thinking.

2118 jobs
MATCH
Calculating your matching score...
CULTURE VALUES
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
BENEFITS & PERKS
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 19, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Stow just viewed IT Asset administrator at Ergomed
Photo of the Rise User
Someone from OH, Loveland just viewed Senior Buyer (wholesale) (m/f/d) at ABOUT YOU SE & Co. KG
Photo of the Rise User
Someone from OH, Cincinnati just viewed Summer 2025 Internship: Talent at Hylant
C
Someone from OH, Cincinnati just viewed Senior Instructional Designer at CXG
Photo of the Rise User
Someone from OH, Youngstown just viewed Compliance Specialist, Anti-Corruption Program at ServiceNow
Photo of the Rise User
Someone from OH, Cleveland just viewed Finance Intern - Summer 2025 at Spectrum
Photo of the Rise User
Someone from OH, Cleveland just viewed QC Engineer at QODE
Photo of the Rise User
34 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
Someone from OH, Cleveland just viewed Getinge is hiring: UI/UX Developer in Streetsboro at Getinge
Photo of the Rise User
Someone from OH, Westerville just viewed Data analyst | Mid at Nord Security
Photo of the Rise User
7 people applied to SOC Analyst at Prosegur
Photo of the Rise User
Someone from OH, North Canton just viewed Researcher-NBC Sports at NBCUniversal
Photo of the Rise User
Someone from OH, North Canton just viewed Researcher-NBC Sports at NBCUniversal
Photo of the Rise User
Someone from OH, Lakewood just viewed Culture and Programs Analyst at City of Philadelphia
Photo of the Rise User
Someone from OH, Olmsted Falls just viewed Customer Service - Representative at Waterway Carwash
M
Someone from OH, Strongsville just viewed Technical Writer (Contract) at Mintlify
Photo of the Rise User
Someone from OH, Cincinnati just viewed Inside Sales Co-Op at VEGA Americas
S
Someone from OH, Cleveland just viewed Senior JavaScript Developer at SuperDial
Photo of the Rise User
Someone from OH, Columbus just viewed Environmental Science Intern at Kimley-Horn