Sr. Penetration Testing Engineer, AWS Penetration Testing Job at Amazon.com Services LLC, Washington State

d1ZjMm5SQUllSmV3UFZxTWZFU0VZU3REa1E9PQ==
  • Amazon.com Services LLC
  • Washington State

Job Description

DESCRIPTION

AWS Security is looking for a Red Team Security, Penetration Test Engineer to help ensure that our systems and processes are secured against the latest threats. You will be on a team responsible for conducting offensive campaigns, emergent threat testing, creating/maintaining automated threat emulation solutions, and helping security and service teams add offensive insight to their development, deployment, monitoring, and response processes. Offensive security at scale is a unique challenge - AWS possesses both scale of systems and scale of staff and processes. This position will provide you with a challenging opportunity.

A Penetration Test Security Engineer at Amazon is expected to be strong in multiple domains. Efficient time management skills are required along with the ability to deliver results in the face of uncertainty. A Penetration Test Security Engineer will proactively share knowledge across the Amazon community and will be a key company resource in one or more of the core areas of security. They will lead security reviews of large Amazon projects while setting standards and defining best practices for the AWS IT Security team.

Engineers in this role must show exemplary judgment in making technical trade-offs between short versus long term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. Conflicts should be addressed by listening, finding the best way forward and persuading one’s colleagues. Successful engineers in this role will regularly analyze their own performance with a critical eye. A broad understanding of the AWS business and its interconnections is required. This position will also provide training and mentorship to other engineers throughout AWS and will be expected to provide thought leadership for the organization as you invent and innovate in the course of your duties.

Key job responsibilities
1. Vulnerability Identification and Tracking
2. Offensive security testing & vulnerability research
3. Emergent threat testing
4. Creating/maintaining automated threat emulation solutions
5. Recommendation of findings and threat mitigations
6. Produce high quality red team reports
7. Projects and research work as needed
8. Security training and outreach to internal development teams
9. Security guidance documentation
10. Security tool development
11. Security metrics delivery and improvements
12. Assistance with recruiting activities

About the team
Work/Life Balance
Our team puts a high value on work-life balance. It isn’t about how many hours you spend at home or at work; it’s about the flow you establish that brings energy to both parts of your life. We believe striking the right balance between your personal and professional life is critical to life-long happiness and fulfillment. We offer flexibility in working hours and encourage you to find your own balance between your work and personal lives.

Mentorship & Career Growth
Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded professional and enable them to take on more complex tasks in the future.

BASIC QUALIFICATIONS

- A Bachelor’s degree in Computer Science, Cybersecurity, similar degree, or equivalent professional experience can be used in lieu of a degree.
- Minimum of 5 years of experience in security testing (Penetration testing, Vulnerability testing, Red teaming, bug hunting or CTF experience)
- Minimum of 5 years of experience with manually auditing source code (One or more of: Java, Ruby, Python, JavaScript, Rust, C, others) to find security issues.
- Minimum of 5 years of experience scripting in Python or other equivalent interpreted languages.
- Minimum of 5 years of professional experience with security engineering practices such as in web application security, network security, authentication and authorization protocols, cryptography, automation and other software security disciplines.

Job Tags

Full time, Temporary work, Work from home,

Similar Jobs

Ryder System

Truck Driver CDL A Home Daily Job at Ryder System

 ...Immediately Hiring a Dedicated SOLO Class A CDL Driver in Owensboro, KY and we want the right...  ...Deliver SOLOTo:IN Route: Local Home Daily Tractor Type: Day Cab TrailerType...  ...Required Company Paid Scale Bypass Trucks are 36 months or newer, include 24/7... 

Allied Stone Inc

Trabajo en Crown Fabricacion Job at Allied Stone Inc

Job Description Job Description Allied Stone est contratando para varios puestos en la planta de fabricacin en Crown Rd en Farmer's Branch, TX

S Universe

Junior NetSuite Project Manager Job at S Universe

 ...The NetSuite Project Manager is responsible for planning, executing, and finalizing NetSuite implementation projects within scope, budget, and timeline. This role involves coordinating with internal teams, clients, and stakeholders to ensure successful project delivery... 

GardaWorld Security Services U.S.

Security Officer - Access Entry Job at GardaWorld Security Services U.S.

 ...Job Description: GardaWorld Security Services is Now Hiring a Surveillance Security Officer! Ready to suit up as a Surveillance Security Guard? What matters most about a role like this is your sharp eye, capturing every detail as you scan a series of screens.... 

Van Buren County

Male Drug Tester Job at Van Buren County

 ...Administrator, the Specialty Courts Male Substance Use Screener (Drug Tester) provides urine collection services to participants...  ...inclusive. Other duties may be required and assigned. # Drive to testing locations around Van Buren County and administer observed urine...