Security Engineer

Munich, Bavaria, DEU

Applications have closed

Amazon.com

Free shipping on millions of items. Get the best of Shopping and Entertainment with Prime. Enjoy low prices and great deals on the largest selection of everyday essentials and other products, including fashion, home, beauty, electronics, Alexa...

View company page

Amazon Lab126 is an inventive research and development company that designs and engineers high-profile consumer electronics. Lab126 began in 2004 as a subsidiary of Amazon.com, Inc., originally creating the best-selling Kindle family of products. Since then, we have produced groundbreaking devices like Fire tablets, Fire TV and Amazon Echo. What will you help us create? Are you interested in being part of a top-notch security team covering all Amazon consumer devices (including hardware and low-level functionality) as well as key Amazon services supporting our consumer devices (such as Computer Vision, AppStore, Device Registration, Kindle, etc.)? Do you enjoy breaking diverse systems spanning low level embedded software, operating systems, applications, peripherals or web client, web sites, and cloud services? Do you like finding and exploiting vulnerabilities in products? Do you find yourself automating and scaling detection of vulnerabilities every single day? Do you want to be part of a vulnerability research team dedicated to detection and mitigation of vulnerabilities prior to launch in order to keep Amazon consumer devices and services safe? Your work directly impacts the way our customers, teams, and business across the globe get things done. If you want to keep customers safe, then we have a job for you! You can learn more about security at Lab 126 here: https://www.youtube.com/watch?v=k0UTTxzeGog.

Job responsibilities
In this role, you will be part of a dedicated team of talented security engineers performing vulnerability research, penetration testing and red team exercises to identify vulnerabilities. You will strive to understand systems, software, and services deeply and develop creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping Amazon customers safe and therefore are passionate about mitigating vulnerabilities/risks by providing actionable guidance to product teams and drive long term security improvements. You're well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization. If you're passionate about finding security bugs, writing tools to reduce manual testing, and enjoy seeing your work's impact across Amazon consumer products and services, then this position is for you. Candidates from entry to senior level will all be considered.
Perform penetration testing and red team exercises across all products, services, and software released by Amazon Lab126 and develop proof of concept exploits.

Perform vulnerability detection using variety of automated static, dynamic analysis as well as custom tooling (e.g. static analyzers, fuzzers, scanners, analyzers, etc.) to scale vulnerability detection and enable easier analysis of externally reported issues.

Review technical solutions to provide guidance to help mitigate security vulnerabilities as well as provide actionable long-term risk mitigation guidance to drive security improvements

Create tools for the discovery of vulnerabilities as well as scale security testing.

Develop detailed technical documentation describing identified vulnerabilities, associated impact as well as recommendations for guidance for communication with internal engineering stakeholders as well as leadership.

Basic Qualifications


Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, Cyber Security or a related field
1+ years relevant work experience

Preferred Qualifications

Master’s degree in Computer Science, Computer Engineering, Electrical Engineering or equivalent
2+ year of development experience in C, C++, assembly (x86, x86-64, ARM) and/or Java
Experience with at least one scripting language (e.g. python, ruby, bash, JavaScript, Go)
Experience in embedded/IoT device security or web services security specifically, with experience of performing software security audits, vulnerability discovery and analysis.
Experience with common software security vulnerabilities and methods of exploitation, such as memory corruption, privilege escalation, web application exploitation, file format vulnerabilities, protocol-based weaknesses, etc.
Experience with static and dynamic tools for vulnerability detection and exploit mitigation techniques
Product security incident response in mobile, IoT or cloud services verticals
Experience with extracting firmware, reverse engineering a variety of hardware and software, including firmware, operating systems, and applications, binary analysis and proof of concept exploit development
Knowledge of common wireless connectivity protocols with focus on protocol and implementation security vulnerabilities (e.g. Bluetooth, WiFi, 802.15.4)
Knowledge of hardware security mechanisms, including secure boot, trusted execution environments


Tags: Audits Bash C Cloud Computer Science Exploit Exploits Incident response Java JavaScript Pentesting Product security Python Red team Reverse engineering Ruby Scripting Vulnerabilities

Region: Europe
Country: Germany
Job stats:  21  2  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.