drjobs Pentest Security Engineer II Devices Services Pentesting

Pentest Security Engineer II Devices Services Pentesting

Employer Active

1 Vacancy
The job posting is outdated and position may be filled
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

USA

Yearly Salary drjobs

$ 136000 - 212800

Vacancy

1 Vacancy

Job Description

The Amazon Devices and Services Trust & Security (DSTS) penetration testing organization is growing and seeking an experienced hardware security researcher to help shape the future of Amazons device security. You will work with hardware teams and product owners to perform advanced hardware analysis and identify highimpact security vulnerabilities across Amazons device ecosystem. The ideal candidate will be expected to master debugging interfaces (JTAG SWD UART) and perform sophisticated hardware attacks including voltage/clock glitching sidechannel analysis (power/EM) and hardwarefocused fuzzing techniques. In addition to the hardware we expect device pentesters to be skilled in assessing the software including operating systems (Linux/Android OS or FreeRTOS) doing security reviews of C/C code ability to audit bootloaders trusted environments and radio/networking protocols like bluetooth wifi zigbee and LoRaWAN. This role will provide you with challenging technical opportunities to break hardware security mechanisms and will be a great deal of fun if extracting secrets from silicon sounds exciting to you!

The Amazon DSTS organization was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers trust data and the systems on which they rely. We protect customers by performing security reviews offensive testing vulnerability assessments and provide guidance for remediations. DSTS builds the foundational capabilities that raise an orgwide security bar across the growing diversity of D&S businesses securing 100 device types 12000 applications and 100 product lines that are developed and operated by more than 16000 builders.

In this role you will be part of a dedicated team of talented penetration testers identifying vulnerabilities in the devices and services ecosystem. You will strive to understand systems software and services deeply and develop creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping millions of customers that rely on Amazons consumer products safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams. Youre wellknown for your excellent prioritization skills as well as your ability to communicate at all levels of an organization. If youre passionate about finding security bugs writing tools to enhance manual testing capabilities automating repetitive tasks and enjoy seeing your work impact Amazon consumer devices and services then this position is for you. Candidates from mid to senior level are encouraged to apply.

Key job responsibilities
Lead and contribute to penetration tests against hardware and software released by Amazons Devices & Services organization. This includes working closely with builder teams to scope pentests develop test plans find vulnerabilities develop proof of concept exploits report findings and validate patches.
Review and influence technical solutions to mitigate security vulnerabilities by providing actionable longterm risk mitigation guidance to drive security improvements.
Lead impactful security improvements in large product lines through close collaboration with our partner builder teams.
Develop detailed technical documentation describing identified vulnerabilities associated impact and recommended remediation to guide communication with internal engineering stakeholders and leadership.
Mentor junior penetration testers and cultivate a culture of collaboration and research sharing.

About the team
While the majority of our Security team are based in the US by applying to this position your application will be considered for all locations we hire for in the world however candidates should expect to accommodate US time for necessary meetings.
Our team puts a high value on worklife balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here which is why we arent focused on how many hours you spend at work or online. Instead were happy to offer a flexible schedule so you can have a more productive and wellbalanced lifeboth in and outside of work.
Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures and were building an environment that celebrates knowledge sharing and mentorship. We care about career growth and strive to assign projects based on what will help each team member develop into a betterrounded engineer and enable them to take on more complex tasks in the future.

3 years of experience in a penetration testing or similar offensive security role.
3 years of professional experience with security engineering practices including: web application security network security authentication and authorization protocols cryptography automation and other software security disciplines.
2 years of experience with interpreted or compiled languages (e.g. C/C Java Python Ruby .NET).
Experience designing and reviewing secure system architectures through the use of Threat Modeling incorporating sophisticated and modern attacks.
Bachelors degree in Computer Science or related field or equivalent industry experience.

Experience with testing low level firmware and hardware.
Experience with applying and assessing Machine Learning technologies.
Knowledge of cloud service providers and their offerings preferably AWS and its various technologies and services.
Experience in various security domains (e.g. system and network security authentication and security protocols cryptography application security incident response).
Experience in developing security tooling and automation applying cutting edge technologies such as symbolic code analysis and fuzzing.
Published security research (e.g. conference presentations whitepapers blog posts).

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race national origin gender gender identity sexual orientation protected veteran status disability age or other legally protected status.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees supervisors and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees supervisors and staff to ensure exceptional customer service; and follow all federal state and local laws and Company policies. Criminal history may have a direct adverse and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above as well as the abilities to adhere to company policies exercise sound judgment effectively manage stress and work safely and respectfully with others exhibit trustworthiness and professionalism and safeguard business operations and the Companys reputation. Pursuant to the Los Angeles County Fair Chance Ordinance we will consider for employment qualified applicants with arrest and conviction records.

Pursuant to the San Francisco Fair Chance Ordinance we will consider for employment qualified applicants with arrest and conviction records.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process including support for the interview or onboarding process please visit for more information. If the country/region youre applying in isnt listed please contact your Recruiting Partner.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136000/year in our lowest geographic market up to $212800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on jobrelated knowledge skills and experience. Amazon is a total compensation company. Dependent on the position offered equity signon payments and other forms of compensation may be provided as part of a total compensation package in addition to a full range of medical financial and/or other benefits. For more information please visit
This position will remain posted until filled. Applicants should apply via our internal or external career site.

Employment Type

Remote

Company Industry

Key Skills

  • Abinitio
  • CMS
  • Baking
  • Insurance Sales
  • Air Compressors
  • Broadcast

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.