Security Engineer II, AWS Offensive Security
Do you enjoy finding unique security issues? Do you enjoy protecting customers at scale? Do you like challenging assumptions? On the AWS Offensive Security team, you will help ensure our devices, applications, services, and systems are designed and implemented to the highest standards and resilient to the modern threats. You will be asked to solve complex technology problems, build tools to automate your way out of manual efforts, and influence the way Amazon services respond to and mitigate threats.AWS Offensive Security is on the cutting edge of many security issues for a wide variety of platforms and technologies including cloud services, Internet of things (IoT), ML/GenAI, identity and access management, mobile devices, virtualization and custom hardware, all operating at massive scale. Similarly, our highly collaborative team is committed to each team member’s growth as our business grows.We are looking for a Security Engineer to help secure our foundational platforms with an emphasis on hardware. You will be responsible for conducting security reviews including hands-on security evaluations (penetration testing), analyzing threat models, and developing tooling that will help detect security issues at scale.You should be comfortable with tackling novel technical situations, and conducting hands-on testing of new, unique surfaces, to ensure proper security mitigations are in place. You will provide crystal-clear technical direction and risk mitigation guidance for diverse engineering and business leaders at all levels. By applying your hard-earned years of practical security engineering expertise in projects related to securing hardware, you will literally shape the future of cloud computing. Along the way, we guarantee that you will learn a ton, have fun, and make a positive impact on millions of people.Key job responsibilities• Security reviews for hardware including servers and devices• Penetration testing & vulnerability research• Threat modeling• Security training and outreach to internal development teams• Security guidance documentation• Assistance with recruiting activitiesAbout the teamAbout Amazon SecurityDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- BS in Computer Science or related field, or equivalent work experience- Minimum of 3 years of experience in Security Engineering or Development of Security capabilities, supporting engineering projects from concept to delivery, and 1 years in one or more of the following technical categories:- Virtualization security (Xen, KVM, QEMU)- Hardware security (PCB, JTAG, UART, SPI, ROM, microcode, custom ASIC/FPGA)- x86 and/or ARM chipset and firmware security (TPM, UEFI, TrustZone, Secure Boot, PCIe)- Security testing including code review of compute platforms (Server, PC or Mobile) ...