Come join our penetration testing team dedicated to the detection and exploitation of vulnerabilities across Amazons portfolio ranging from consumer services and devices to the Kuiper satellites. This includes conducting in-depth reviews of complex service workflows including authentication mechanisms AI mobile web applications and web service APIs. Pentesters also invent new ways to automate and improve their work with techniques such as AI/LLMs fuzzing detection at scale and static analysis.
Our team operates under the Amazon Specialized Businesses Security (SBS) organization which was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers trust data and the systems on which they rely. We protect customers by performing security reviews offensive testing vulnerability assessments and provide guidance for remediations. We also drive down costs by building and automating security foundations and integrating them into design and release processes. SBS builds the foundational capabilities that raise an org-wide security bar across the growing diversity of D&S businesses - securing 100 device types 12000 applications and 100 product lines that are developed and operated by more than 16000 builders.
The SBS penetration testing organization is growing and seeking an experienced web penetration tester to help shape the future of Amazons service security. You will work with builder teams and product owners to perform penetration testing and identify high-impact security vulnerabilities across the web services ecosystem supporting Amazons devices. The ideal candidate will be expected to comprehend large complex web service architectures and to dive deep into a services source code and to have some exposure to device penetration tests. This role will provide you with challenging technical opportunities and will also be a great deal of fun if hacking Amazon sounds exciting to you!
In this role you will be part of a dedicated team of talented penetration testers identifying vulnerabilities in the devices and services ecosystem. You will strive to understand systems software and services deeply and develop creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping millions of customers that rely on Amazons consumer products safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams. Youre well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization. If youre passionate about finding security bugs writing tools to enhance manual testing capabilities automating repetitive tasks and enjoy seeing your work impact Amazon consumer devices and services then this position is for you. Candidates from mid to senior level are encouraged to apply.
Key job responsibilities
- Contribute to penetration tests against services and software released by Amazons Devices & Services organization. This includes working closely with builder teams to find vulnerabilities develop proof of concept exploits report findings and validate patches.
- Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.
- Review and influence technical solutions to mitigate security vulnerabilities by providing actionable long-term risk mitigation guidance to drive security improvements.
- Provides impactful security contributions to large product lines through close collaboration with our partner builder teams.
- Develop detailed technical documentation describing identified vulnerabilities associated impact and recommended remediation to guide communication with internal engineering stakeholders and leadership.
- Continuous growth and development of technical skillsets while contributing to standing projects for program improvement in DSPT.
About the team
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description we encourage candidates to apply. If your career is just starting hasnt followed a traditional path or includes alternative experiences dont let it stop you from applying.
Why Amazon Security
At Amazon security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazons products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build
experience in a wide variety of areas including cloud devices retail entertainment healthcare operations and physical stores.
Inclusive Team Culture
In Amazon Security its in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas perspectives and voices.
Training & Career Growth
Were continuously raising our performance bar as we strive to become Earths Best Employer. Thats why youll find endless knowledge-sharing training and other career-advancing resources here to help you develop into a better-rounded professional.
Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home theres nothing we cant achieve.
- Knowledge of internet fundamentals and cloud computing concepts
- Bachelors degree in Computer Science or related field and 1 year of equivalent industry experience or 3 years of equivalent industry experience.
- Core understanding of web application and service API vulnerabilities (e.g. mass assignment broken object/function level authorization JWT/OAuth injection business logic flaws excessive data exposure etc.).
- Experience tracing sources and sinks during code review to identify vulnerabilities and providing contextual remediation guidance to address vulnerability root cause.
- Experience designing and reviewing secure system architectures through the use of Threat Modeling incorporating sophisticated and modern attacks.
- Foundational knowledge of hardware security fundamentals.
- Experience in CTF competitions CVE research and/or Bug Bounty recognition.
- Experience with Microservice architectures AI/ML technologies scripting and tooling or pentesting as part of an SDLC operation of a large-scale enterprise environment.
- Published security research (e.g. conference presentations whitepapers blog posts).
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status disability or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process including support for the interview or onboarding process please visit
for more information. If the country/region youre applying in isnt listed please contact your Recruiting Partner.
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience qualifications and location. Amazon also offers comprehensive benefits including health insurance (medical dental vision prescription Basic Life & AD&D insurance and option for Supplemental life plans EAP Mental Health Support Medical Advice Line Flexible Spending Accounts Adoption and Surrogacy Reimbursement coverage) 401(k) matching paid time off and parental leave. Learn more about our benefits at TX Austin - 136000.00 - 184000.00 USD annually
USA WA Virtual Location - Washington - 136000.00 - 184000.00 USD annually