Pentest Security Engineer II, Devices

4 days ago


Dublin, Ireland Amazon Full time

Pentest Security Engineer II, Devices & Services Pentesting

Job ID: 2858054 | Amazon Development Center Germany GmbH - C92

Come join our penetration testing team dedicated to the detection and exploitation of vulnerabilities across Amazon’s portfolio ranging from consumer services and devices to the Kuiper satellites. This includes conducting in-depth reviews of complex service workflows including authentication mechanisms, AI, mobile, web applications, and web service APIs. Pentesters also invent new ways to automate and improve their work with techniques such as AI/LLMs, fuzzing, detection at scale, and static analysis.

Our team operates under the Amazon Devices and Services Trust & Security (DSTS) organization which was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers’ trust, data, and the systems on which they rely. We protect customers by performing security reviews, offensive testing, vulnerability assessments, and provide guidance for remediations. We also drive down costs by building and automating security foundations and integrating them into design and release processes. DSTS builds the foundational capabilities that raise an org-wide security bar across the growing diversity of D&S businesses - securing 100+ device types, 12,000+ applications, and 100+ product lines that are developed and operated by more than 16,000+ builders.

The DSTS penetration testing organization is growing and seeking an experienced web penetration tester to help shape the future of Amazon’s service security. You will work with builder teams and product owners to perform penetration testing and identify high-impact security vulnerabilities across the web services ecosystem supporting Amazon’s devices. The ideal candidate will be expected to comprehend large complex web service architectures and to dive deep into a service's source code, and to have some exposure to device penetration tests. This role will provide you with challenging technical opportunities and will also be a great deal of fun if hacking Amazon sounds exciting to you

In this role, you will be part of a dedicated team of talented penetration testers identifying vulnerabilities in the devices and services ecosystem. You will strive to understand systems, software, and services deeply and develop creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping millions of customers that rely on Amazon’s consumer products safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams. You're well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization. If you're passionate about finding security bugs, writing tools to enhance manual testing capabilities, automating repetitive tasks, and enjoy seeing your work impact Amazon consumer devices and services, then this position is for you. Candidates from mid to senior level are encouraged to apply.

Key job responsibilities

1. Lead and contribute to penetration tests against services and software released by Amazon’s Devices & Services organization. This includes working closely with builder teams to scope pentests, develop test plans, find vulnerabilities, develop proof of concept exploits, report findings, and validate patches.
2. Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.
3. Review and influence technical solutions to mitigate security vulnerabilities by providing actionable long-term risk mitigation guidance to drive security improvements.
4. Lead impactful security improvements in large product lines through close collaboration with our partner builder teams.
5. Develop detailed technical documentation describing identified vulnerabilities, associated impact, and recommended remediation to guide communication with internal engineering stakeholders and leadership.
6. Mentor junior penetration testers and cultivate a culture of collaboration and research sharing.

About the team

While the majority of our Security team are based in the US, by applying to this position your application will be considered for all locations we hire for in the world, however candidates should expect to accommodate US time for necessary meetings. Our team puts a high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren’t focused on how many hours you spend at work or online. Instead, we’re happy to offer a flexible schedule so you can have a more productive and well-balanced life—both in and outside of work. Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about career growth and strive to assign projects based on what will help each team member develop into a better-rounded engineer and enable them to take on more complex tasks in the future.

BASIC QUALIFICATIONS

1. 3+ years of experience identifying, exploiting, and recommending solutions to remediate web application and service API vulnerabilities (e.g. mass assignment, broken object/function level authorization, JWT/OAuth, injection, business logic flaws, excessive data exposure, etc.).
2. Experience tracing sources and sinks during code review to identify vulnerabilities, and providing contextual remediation guidance to address vulnerability root cause.
3. Experience designing and reviewing secure system architectures through the use of Threat Modeling incorporating sophisticated and modern attacks.
4. Knowledge of cloud service providers and their offerings, preferably AWS, and its various technologies and services.
5. Bachelor’s degree in Computer Science or related field, or equivalent industry experience.

PREFERRED QUALIFICATIONS

1. Foundational knowledge of hardware security fundamentals.
2. Experience in CTF competitions, CVE research, and/or Bug Bounty recognition.
3. Experience with applying and assessing Machine Learning technologies.
4. Published security research (e.g. conference presentations, whitepapers, blog posts).

Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice (https://www.amazon.jobs/en/privacy_page ) to know more about how we collect, use and transfer the personal data of our candidates.

Posted: January 25, 2025 (Updated about 3 hours ago)

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

#J-18808-Ljbffr



  • Dublin, Ireland Amazon Full time

    Quality Assurance Engineer II, Alexa Devices “Alexa, find me a job where I can create and innovate.” Quality Assurance Engineers at Amazon test cutting-edge applications and products at the user level and code level, both manually and with automated tools. They understand software internals, debug problems using log files, and write automated tests with...


  • Dublin, Ireland Mercury Engineering Full time

    Beware of Fraudulent Mercury Job Postings. Fraudsters may be posting fake job listings claiming to be from Mercury. Legitimate Mercury job offers will never ask for personal information or upfront payments. Always verify job postings through official Mercury channels. Graduate IT Security Analyst, Dublin, Ireland Mercury is the European leader in...


  • Dublin, Ireland Amazon Full time

    Software Dev Engineer II, Amazon One Enterprise As part of the AWS Solutions organization, we have a vision to provide business applications, leveraging Amazon’s unique experience and expertise, that are used by millions of companies worldwide to manage day-to-day operations. We will accomplish this by accelerating our customers’ businesses through...


  • Dublin, Ireland Amazon Full time

    The Amazon Middle East and North Africa team is looking for a Software Development Engineer who is passionate about building great products for our customers. The SDE-II will be based in Amman, Jordan and must have software engineering experience involving solving complex problems. They SDE-II will: 1. Design, implement, test, deploy and maintain innovative...


  • Dublin, Ireland Amazon Full time

    The Amazon Middle East and North Africa team is looking for a Software Development Engineer who is passionate about building great products for our customers. The SDE-II will be based in Amman, Jordan and must have software engineering experience involving solving complex problems. They SDE-II will: 1. Design, implement, test, deploy and maintain innovative...


  • Dublin, Ireland Chubb Fire and Security Ltd Full time

    Security Service Engineer Apply to locations: Chubb Dublin, Unit 3/4, Deansgrange Business Park, Deansgrange, Dublin, A94 D954 Time type: Full time Posted on: 30+ Days Ago Job requisition id: JR40000185 It's fun to work in a company where people truly BELIEVE in what they're doing! Think you know Chubb? We might just surprise you! Chubb is so much more...


  • Dublin, Ireland Amazon Full time

    Do you want to shape the future of how Alexa enabled devices connect with Alexa Cloud? Do you want to be part of a team that builds services used by millions of customers? If you said yes to any or all of those, come join the Alexa Connected Devices! We are looking for a passionate engineer to work on the development of Tier-1 Connectivity services for Alexa...


  • Dublin, Ireland SOLAS IT RECRUITMENT Full time

    Senior Network Security Engineer We are seeking a skilled Network Security Engineer to manage and secure our network infrastructure. The ideal candidate will have extensive experience with Cisco Networks and a deep understanding of network security principles and practices. Responsibilities: - Manage the security of Cisco routers, switches, networking...


  • Dublin, Ireland Amazon Full time

    Software Development Engineer II, MENA Marketing Tech Amazon Middle East and North Africa team is looking for a Software Development Engineer who is passionate about building great products for our Customers & Sellers. The SDE-II will be based in Amman, JOR and must have software engineering experience involving designing, architecting, and solving complex...


  • Dublin, Ireland SOLAS IT RECRUITMENT Full time

    Senior C# or VB.Net Developer – Hybrid We are looking for an experienced Senior C# or VB.Net Developer to join our client's team in Dublin. You will work on developing and maintaining software solutions, focusing on web-based and mobile platforms. This role requires a strong background in software development and familiarity with key technologies that...


  • Dublin, Ireland Amazon Full time

    Software Development Engineer II, MENA CX Amazon Middle East and North Africa team is looking for a Software Development Engineer who is passionate about building great products for our customers & Sellers. The SDE-II will be based in Amman, JOR and must have software engineering experience involving designing, architecting, and solving complex...


  • Dublin, Ireland Amazon Full time

    Quality Assurance Engineer II, Alexa Communications Elevate the Voice of Alexa Communications - Are you passionate about ensuring flawless user experiences in cutting-edge voice technology? The Contacts team within Alexa Communications is seeking a detail-oriented Quality Assurance Engineer to join our innovative squad. We're at the forefront of...


  • Dublin, Ireland Hyper Recruitment Solutions LTD Full time

    We are currently looking for a Senior Device Design Engineer to join a leading Pharmaceutical company based in the Dublin area. As the Senior Device Design Engineer, you will be responsible for driving the design and development of innovative combination products, contributing to a diverse range of exciting projects.KEY DUTIES AND RESPONSIBILITIES:Your...


  • Dublin, Ireland Rainmaker Business Technologies Full time

    Location: 88 Sandymount Road, Sandymount Village, Dublin 4 Job type: Fulltime, Permanent, On-premises Additional benefits: Income Protection, Death In Service Benefit Job Description: IT Security Engineer Minimum Experience: 3-5 years Qualifications: BSc. In Software Engineering or a similar technical discipline Rainmaker Business Technologies provides...


  • Dublin, Ireland Amazon Full time

    Software Developer Engineer, Device Software Services The Amazon Devices team designs and engineers high-profile consumer electronics, including the best-selling Kindle family of products. We have also produced groundbreaking devices like Fire tablets, Fire TV, Amazon Dash, and Amazon Echo. What will you help us create? A Software Developer Engineer (SDE)...

  • Quality Engineer II

    4 days ago


    Dublin, Ireland AdsWizz Full time

    Who We Are: SiriusXM and its brands (Pandora, SXM Media, AdsWizz, Simplecast, and SiriusXM Connected Vehicle Services) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners in the car, at home, and anywhere on the go with connected devices. Our...

  • Front End Engineer

    4 days ago


    Dublin, Ireland Amazon Full time

    Do you want to build frameworks for the next generation of UI apps running on Amazon Devices? Do you believe in the “Write Once Run Anywhere” coding paradigm? How about your code providing a positive impact to our smart home customers by ensuring unique Amazon technologies are easily available to app developers? Do you want to work in a horizontal team...


  • Dublin, Ireland Amazon Full time

    System Development Engineer II- AWS, Sales Tech , Amazon - SalesTech Amazon Seller Services India offers innovative solutions to help sellers grow their online businesses. With a fast-paced, entrepreneurial work environment, you'll be at the heart of Amazon's drive to deliver cutting-edge cloud technologies. We are seeking a Sys Dev Engineer II to help...


  • Dublin, Ireland AdsWizz Full time

    Who We Are: SiriusXM and its brands (Pandora, SXM Media, AdsWizz, Simplecast, and SiriusXM Connected Vehicle Services) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners in the car, at home, and anywhere on the go with connected devices. Our...


  • Dublin, Ireland Amazon Full time

    Software Development Engineer II, Amazon Amazon’s Intelligent Cloud Hosting (ICON) team is looking for a Software Development Engineer (SDE) to join our team! Our team is responsible for hosting Amazon’s websites, which includes all of Amazon’s global marketplaces and partner portals as well as consumer experiences like Kindle, Alexa, Amazon Video,...