Pentest Security Engineer, Devices & Services PentestingJob ID: 2874681 | Amazon Development Center Germany GmbH
Come join our penetration testing team dedicated to the detection and exploitation of vulnerabilities from Amazon's consumer services and devices to the Kuiper satellites.
This includes conducting in-depth reviews of complex service workflows including authentication mechanisms, AI, mobile, web applications, and web service APIs.
Pentesters also invent new ways to automate and improve their work with techniques including AI/LLMs, fuzzing, detection at scale, and static analysis.
Our team operates under the Amazon Devices and Services Trust & Security (DSTS) organization which was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers' trust, data, and the systems on which they rely.
We protect customers by performing security reviews, offensive testing, vulnerability assessments, and provide guidance for remediations.
We drive down costs by building and automating security foundations and integrating them into design and release processes.
The DSTS penetration testing organization is growing and seeking an experienced web penetration tester to help shape the future of Amazon's service security.
You will work with builder teams and product owners to perform penetration testing and identify high-impact security vulnerabilities across the web services ecosystem supporting Amazon's devices.
The ideal candidate will be expected to comprehend large complex web service architectures, dive deep into a service's source code, and to get some exposure to device penetration tests.
In this role, you will be part of a dedicated team of talented penetration testers identifying vulnerabilities in the devices and services ecosystem.
You will strive to understand systems, software, and services deeply and develop creative ways to break assumptions in order to find vulnerabilities.
You care deeply about keeping millions of customers that rely on Amazon's consumer products safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams.
Key job responsibilitiesContribute to penetration tests against services and software released by Amazon's Devices & Services organization.
This includes working closely with builder teams to find vulnerabilities, develop proof of concept exploits, report findings, and validate patches.Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.Review and influence technical solutions to mitigate security vulnerabilities by providing actionable long-term risk mitigation guidance to drive security improvements.Provides impactful security contributions to large product lines through close collaboration with our partner builder teams.Develop detailed technical documentation describing identified vulnerabilities, associated impact, and recommended remediation to guide communication with internal engineering stakeholders and leadership.Continuous growth and development of technical skillsets while contributing to standing projects for program improvement in DSPT.BASIC QUALIFICATIONSBachelor's degree in Computer Science or related field and 1+ year of equivalent industry experience or 3+ years of equivalent industry experience.Core understanding of web application and service API vulnerabilities (e.g.
mass assignment, broken object/function level authorization, JWT/OAuth, injection, business logic flaws, excessive data exposure, etc.
).Experience tracing sources and sinks during code review to identify vulnerabilities, and providing contextual remediation guidance to address vulnerability root cause.Experience designing and reviewing secure system architectures through the use of Threat Modeling incorporating sophisticated and modern attacks.Knowledge of cloud service providers and their offerings, preferably AWS, and its various technologies and services.PREFERRED QUALIFICATIONSFoundational knowledge of hardware security fundamentals.Experience in CTF competitions, CVE research, and/or Bug Bounty recognition.Experience with Microservice architectures, AI/ML technologies, scripting and tooling, or pentesting as part of an SDLC operation of a large-scale enterprise environment.Published security research (e.g.
conference presentations, whitepapers, blog posts).Amazon is an equal opportunities employer.
We believe passionately that employing a diverse workforce is central to our success.
We make recruiting decisions based on your experience and skills.
We value your passion to discover, invent, simplify and build.
Posted: January 27, 2025
Amazon is committed to a diverse and inclusive workplace.
Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.
#J-18808-Ljbffr