Security Engineer, Security Verification
Salva questo lavoro e mantieni la tua ricerca organizzata
Crea un account gratuito per salvare lavori, creare avvisi e tornare a questa inserzione dalla tua dashboard.
We are looking for a Security Engineer to join Point-in-Time Security Testing, AWS's expert security assurance function for the launches and architectures where security automation alone is not enough. You will own complex security testing engagements end to end, and you will leave behind mechanisms that make each engagement worth more than itself.
Amazon Web Services (AWS) is the leading cloud service provider, providing virtualized infrastructure, storage, networking, messaging, and many other services to customers all over the world, including government customers. AWS runs a globally distributed environment operating at massive scale, and businesses from start-ups to large enterprises and governments run their most sensitive workloads on it. Point-in-Time Security Testing takes on the engagements where the architecture, threat model, or potential impact is complex enough that expert reasoning matters most. We start from the architecture and the risks rather than a generic checklist, think like an adversary, and demonstrate realistic impact. We build harnesses that steer agentic AI so experts have more time for the difficult problems, and we turn what we learn into shared methods, mechanisms, and detections for the rest of the team. As AWS ships agentic systems of its own, those same systems become targets we test.
Our work is measured by how much difficult security uncertainty we resolve with the human time available to us, not by how many issues we find. In this role you will investigate high-consequence risks, which are specific, testable claims about how an adversary could cause harm, and take each one to a documented conclusion. You will either demonstrate the issue, rule out the attack path with enough evidence, or expose a weakness in a shared mechanism or detection.
You must produce results in the face of ambiguity and imperfect knowledge, foster constructive dialogue, and drive resolution when faced with disagreement. You deliver autonomously on work scoped within the team, and you ask for guidance when a problem crosses into unfamiliar territory. You are trusted to run a difficult engagement without close supervision, and to say clearly when the plan needs to change.
Amazon's Leadership Principles of "Dive Deep", "Earn Trust", "Deliver Results", and "Invent and Simplify" will be called upon daily. Above all, we earn trust by choosing carefully where humans spend time, testing those areas deeply, and being honest about what we know and what we do not.
Key job responsibilities
- Lead complex security testing engagements end to end, including multi-engineer tests across interconnected microservice architectures, repeat testing across successive iterations of one launch, and campaigns that investigate a systemic issue across several services
- Perform penetration testing and AI-augmented source code review of complex proprietary AWS software, directing the tooling at trust boundaries, abuse cases, and attack paths it would not reach on its own, and confirming what it reports
- Take each agreed risk hypothesis to a documented conclusion, whether that means demonstrating the issue with proof-of-concept code, ruling out the attack path with sufficient evidence, or identifying a weakness in a shared mechanism or detection
- Challenge what a scope document assumes and identify what it misses, then keep the engagement moving when conditions change by building alternative test paths, re‑scoping, and parallelizing work with dependent teams
- Trace attack paths across chained components and demonstrate compound risk that stays invisible when components are tested in isolation
- Assess and defend the business impact of complex and ambiguous risk, not only well‑understood vulnerability classes, so service teams can act on the right things first
- Produce clear engagement results that record what you tested, why you chose those tests, what you found or ruled out, the limitations of the work, and the risk that remains
- Lead communication with developers, AppSec engineers, and Blue teams when the scope is ambiguous or a fix is not straightforward, validate the fixes, confirm remediation through Verification of Fixes, and work as an embedded security tester inside the development lifecycle when a launch calls for it
- Build automation and tune the harnesses that raise the precision of the team's AI pentest bots, measuring where they produce false positives or miss attack patterns, so expert time goes where it changes the outcome
- Test agentic AI systems as an adversary would, reasoning about how agent-to-agent (A2A) communication, tool use, memory, and orchestration can be manipulated or made to cross a trust boundary
- Leave reusable mechanisms behind, such as fuzzers, integration security tests, detection rules, tooling, or documented methodology, and track whether they are adopted