×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Pentest Security Engineer, Specialized Pentest Team, Devices & Services

Job in Washington, Daviess County, Indiana, 47169, USA
Listing for: Amazon
Full Time position
Listed on 2026-02-14
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below

Description

Come join our penetration testing team dedicated to the detection and exploitation of vulnerabilities across Amazon’s portfolio ranging from consumer services and devices to the Kuiper satellites. This includes conducting in-depth reviews of complex service workflows including authentication mechanisms, AI, mobile, web applications, and web service APIs.

Pentesters also invent new ways to automate and improve their work with techniques such as AI/LLMs, fuzzing, detection at scale, and static analysis.

Key Job Responsibilities
  • Contribute to penetration tests against services and software released by Amazon’s Devices & Services organization, working closely with builder teams to find vulnerabilities, develop proof‑of‑concept exploits, report findings, and validate patches.
  • Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.
  • Review and influence technical solutions to mitigate security vulnerabilities by providing actionable long‑term risk mitigation guidance.
  • Provide impactful security contributions to large product lines through close collaboration with partner builder teams.
  • Develop detailed technical documentation describing identified vulnerabilities, associated impact, and recommended remediation to guide communication with internal engineering stakeholders and leadership.
  • Continuously grow and develop technical skillsets while contributing to standing projects for program improvement in DSPT.
About the Team

The SBS penetration testing organization operates under the Amazon Specialized Businesses Security (SBS) organization, formed in 2014 to protect Amazon Devices & Services customers’ trust, data, and systems. We perform security reviews, offensive testing, vulnerability assessments, and provide guidance for remediations while building and automating security foundations that raise an org‑wide security bar across the growing diversity of D&S businesses.

We are seeking an experienced web penetration tester to help shape the future of Amazon’s service security. You will work with builder teams and product owners to perform penetration testing and identify high‑impact security vulnerabilities across the web services ecosystem supporting Amazon’s devices.

In this role you will be part of a dedicated team identifying vulnerabilities in the devices and services ecosystem, striving to understand systems, software, and services deeply and developing creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping millions of customers safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams.

You are known for your excellent prioritization skills and ability to communicate at all levels of an organization.

Candidates from mid to senior level are encouraged to apply.

Basic Qualifications
  • Knowledge of internet fundamentals and cloud computing concepts
  • Bachelor’s degree in Computer Science or related field and 1+ year of equivalent industry experience, or 3+ years of equivalent industry experience
  • Core understanding of web application and service API vulnerabilities (e.g., mass assignment, broken object/function‑level authorization, JWT/OAuth, injection, business logic flaws, excessive data exposure, etc.)
  • Experience tracing sources and sinks during code review to identify vulnerabilities, and providing contextual remediation guidance to address vulnerability root cause
  • Experience designing and reviewing secure system architectures through the use of threat modeling incorporating sophisticated and modern attacks
Preferred Qualifications
  • Foundational knowledge of hardware security fundamentals
  • Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
  • Experience with microservice architectures, AI/ML technologies, scripting and tooling, or pentesting as part of an SDLC operation of a large‑scale enterprise environment
  • Published security research (e.g., conference presentations, whitepapers, blog posts)

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary