AWS Security is a global team tasked with keeping the cloud safe. To help deliver for customers on this promise the AWS Bug Bounty team is currently seeking a security engineer with strong software development skils to join our team!
The primary responsibility of this role is to leverage your experience and internal knowledge of AWS systems to effectively triage a diverse set of incoming reports which can pertain to any of AWS's 200+ services.
As part of this role you will act as the escalation point for fellow members of the team and are expected to be an experienced pen-tester.
Technical dive deep and curiosity are a way of life on this team in order to establish the true severity of a report and what defense in depth mechanisms need to happen beyond just an immediate patch.
Automation is the key to scaling and innovation at AWS and in this role you will own writing automation to reduce the load on humans;
everything from developing ticketing, reporting and trend identification automation.
AWS Bug Bounty has a diverse set of customers : service owners and engineers, security leadership as well as our external crowd of researchers.
Strong communication skills are required when providing excellent customer service for our customers, especially when growing our external crowd.
As a senior engineer on the team, you will be expected to help deliver insights to leadership and assist service teams in prioritizing and remediating difficult security problems.
The development of the AWS researcher community is paramount to ensuring the success of our program and of our customers.
As such we seek to earn researcher trust by being as transparent as possible with our responses to their reporting and our reward structures.
As part of this team you will be expected to develop external messaging for both researchers and our own customer base. Above all else, a strong sense of Customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its Customers secure with the highest priority.
This role will provide you with challenging opportunities, both technologically and as a leader to grow AWS’s Bug Bounty Program into the best on planet Earth.
Key job responsibilities
- Researching, reproducing, and responding to security vulnerabilities reported through the bug bounty program
- Technical Escalation
- Managing relationships with external security researchers working with AWS's bug bounty program
- Perform deep analysis of new vulnerability classes
- Driving improvements to team tooling, automation, and processes
- Influencing and driving program direction
- Identify and drive resolution of vulnerability trends
- Attend industry conferences and assist in hosting on site hack-a-thons and other researcher engagement activities
A day in the life
Our mornings typically start by looking at the queue of submitted reports that have already undergone initial triage by our third party partners.
We single out reports that need urgent attention and then do a deep dive : reproducing, root causing and where appropriate extending the findings in the report to demonstrate maximum impact.
Once done we coordinate with the internal stakeholders to drive the report until remediation.
We maintain a close partnership with other security teams across Amazon to surface reports and trend data that are relevant to their mission.
About the team
About Amazon Security
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply.
If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services.
We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness.
Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.
Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.
Work / Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture.
When we feel supported in the workplace and at home, there’s nothing we can’t achieve.
We are open to hiring candidates to work out of one of the following locations :
Arlington, VA, USA Austin, TX, USA Seattle, WA, USA Virtual Location - TX Virtual Location - VA Virtual Location - WA
BASIC QUALIFICATIONS
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- Bachelor's degree in computer science or equivalent
- Knowledge of networking protocols such as HTTP, DNS and TCP / IP
PREFERRED QUALIFICATIONS
- 2+ years of any combination of the following : threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
- Experience with AWS products and services
- Experience with programming languages such as Python, Java, C++