Security Engineer II - Red Team

Seattle, Washington, USA

Full Time
Amazon.com logo
Amazon.com
Apply now Apply later

Posted 1 month ago

Amazon’s Offensive Security Team is seeking a Red Teamer to help keep Amazon's infrastructure secure for its customers by attacking Amazon’s services, infrastructure, processes, and controls, and by partnering with defensive & service teams to remediate weaknesses and sharpen our detective, preventative, and response capabilities. This role presents an ultimate test of ones security knowledge and ability, along with the support of a team of highly skilled individuals. This position will provide you with challenging opportunities, both technologically and as a leader, but will also be a great deal of fun if hacking Amazon sounds exciting to you.

A Security Engineer at Amazon is expected to be strong in multiple domains. Engineers in this role work closely with teams throughout Information Security, as well as provide technical leadership and advice to teams and leaders throughout Amazon. You will be in direct contact with teams in a variety of business verticals, giving you first hand knowledge about how Amazon is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Amazon to find new ways to break services, processes, and technologies throughout the company.

Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. They must also demonstrate resilience and navigate ambiguous situations with composure and tact. Individuals in this role will be expected to provide thought leadership for the organization as you discover, invent, and innovate throughout the course of their duties. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its customers secure.

Responsibilities include:
· Conducting red team engagements throughout Amazon independently, or as part of a team.
· Creating detailed engagement plans, execute operations, and emulate adversary Tactics, Techniques, and Procedures (TTPs).
· Thoroughly documenting timelines, attack paths, findings/gaps, and recommendations.
· Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings.

Basic Qualifications


· 4+ years work experience in a red teaming or penetration testing role
· Knowledge and understanding in various security domains (e.g. security engineering, system and network security, authentication and security protocols, cryptography, application security, incident response)
· Experience with interpreted or compiled languages (e.g. Python, Ruby, C/C++, Java, .NET)
· Experience with common offensive security tools (e.g. Metasploit, Burp Suite)
· Experience with adversary Tactics, Techniques, and Procedures (TTPs)
· Strong sense of ownership, urgency, and passion
· Sharp analytical abilities and attention to detail
· Effective written and verbal communication skills

Preferred Qualifications

· BS in Computer Science or related field
· Experience with cloud service providers and their offerings, preferably AWS, and its various technologies and services
· Experience in developing security tooling and automating red team infrastructure
· Experience in conducting social engineering assessments
· Experience in web application/service assessments
· Experience in enterprise network infrastructure assessments
· Experience in reverse engineering and associated tooling (e.g. IDA)
· Experience in fuzzing, memory corruption, and exploit development
· Experience in hardware hacking
· Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
· Experience providing training and mentorship
· Demonstrable teamwork skills and resourcefulness
· Ability to make concrete progress in the face of ambiguity and imperfect knowledge

Amazon is an Equal Opportunity-Affirmative Action Employer – Minority / Female / Disability / Veteran / Gender Identity / Sexual Orientation




Job tags: AWS Burp Suite C Cryptography CTF Incident response Java Metasploit Network security Offensive Security Penetration testing Python Red team Ruby TTPs