Offensive Security Engineer, AWS Bug Bounty

Amazon Development Center U.S., Inc.
Arlington, Virginia, USA
$136K a year
Full-time

AWS Security is a global team tasked with keeping the cloud safe. To help deliver for customers on this promise the AWS Bug Bounty team is currently seeking a security engineer with strong software development skils to join our team!

The primary responsibility of this role is to leverage your experience and internal knowledge of AWS systems to effectively triage a diverse set of incoming reports which can pertain to any of AWS's 200+ services.

As part of this role you will act as the escalation point for fellow members of the team and are expected to be an experienced pen-tester.

Technical dive deep and curiosity are a way of life on this team in order to establish the true severity of a report and what defense in depth mechanisms need to happen beyond just an immediate patch.

Automation is the key to scaling and innovation at AWS and in this role you will own writing automation to reduce the load on humans;

everything from developing ticketing, reporting and trend identification automation.

AWS Bug Bounty has a diverse set of customers : service owners and engineers, security leadership as well as our external crowd of researchers.

Strong communication skills are required when providing excellent customer service for our customers, especially when growing our external crowd.

As a senior engineer on the team, you will be expected to help deliver insights to leadership and assist service teams in prioritizing and remediating difficult security problems.

The development of the AWS researcher community is paramount to ensuring the success of our program and of our customers.

As such we seek to earn researcher trust by being as transparent as possible with our responses to their reporting and our reward structures.

As part of this team you will be expected to develop external messaging for both researchers and our own customer base. Above all else, a strong sense of Customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its Customers secure with the highest priority.

This role will provide you with challenging opportunities, both technologically and as a leader to grow AWS’s Bug Bounty Program into the best on planet Earth.

Key job responsibilities

  • Researching, reproducing, and responding to security vulnerabilities reported through the bug bounty program
  • Technical Escalation
  • Managing relationships with external security researchers working with AWS's bug bounty program
  • Perform deep analysis of new vulnerability classes
  • Driving improvements to team tooling, automation, and processes
  • Influencing and driving program direction
  • Identify and drive resolution of vulnerability trends
  • Attend industry conferences and assist in hosting on site hack-a-thons and other researcher engagement activities

A day in the life

Our mornings typically start by looking at the queue of submitted reports that have already undergone initial triage by our third party partners.

We single out reports that need urgent attention and then do a deep dive : reproducing, root causing and where appropriate extending the findings in the report to demonstrate maximum impact.

Once done we coordinate with the internal stakeholders to drive the report until remediation.

We maintain a close partnership with other security teams across Amazon to surface reports and trend data that are relevant to their mission.

About the team

About Amazon Security

Diverse Experiences

Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply.

If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services.

We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture

In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness.

Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth

We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work / Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture.

When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

We are open to hiring candidates to work out of one of the following locations :

Arlington, VA, USA Austin, TX, USA Seattle, WA, USA Virtual Location - TX Virtual Location - VA Virtual Location - WA

BASIC QUALIFICATIONS

  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  • Bachelor's degree in computer science or equivalent
  • Knowledge of networking protocols such as HTTP, DNS and TCP / IP

PREFERRED QUALIFICATIONS

  • 2+ years of any combination of the following : threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • Experience with AWS products and services
  • Experience with programming languages such as Python, Java, C++
  • 30+ days ago
Related jobs
Promoted
MITRE
McLean, Virginia

Use your skills as an offensive engineer and knowledge of adversary behaviors to build and emulate the cutting-edge capabilities of real-world threats. Propose and lead research to improve the state of the art of offensive security, especially in cyber autonomy. Define and lead offensive security en...

Promoted
Booz Allen Hamilton
Alexandria, Virginia

AWS Certification, including AWS Certified DevOps Engineer or AWS Certified Security - Specialty. As a DevOps infrastructure engineer at Booz Allen, you’ll work closely with cloud architects and engineers to manage server configuration for modern cloud solutions. As a DevOps engineer, you know how t...

Amazon Development Center U.S., Inc.
Arlington, Virginia

To help deliver for customers on this promise the AWS Bug Bounty team is currently seeking a security engineer with strong software development skils to join our team!. AWS Bug Bounty has a diverse set of customers: service owners and engineers, security leadership as well as our external crowd of r...

Promoted
Deloitte
Arlington, Virginia

Our Cyber Application Security team advises federal clients on integrating security activities throughout the software development lifecycle to enable the design, build, and deployment of secure applications. Standardizing Azure/GCP and/or AWS Security Best practices, processes, and procedures. You ...

Promoted
Amazon
Arlington, Virginia

As a Senior Security Engineer (SecEng) in AWS Fraud Prevention you’ll work with data scientists, software development engineers, risk managers and security engineers across multiple teams and locations to develop innovative security solutions. DescriptionWe are seeking a Senior Security Engineer to ...

Promoted
Cedent Consulting Inc
Reston, Virginia

AWS Security Engineer @ Reston, Virginia. Track security violations and identify trends or exposures that could be addressed by additional training, technical measures, or use of application tools to enhance security. May participate in simulated attacks or security violations to assess the organiza...

Promoted
ClearanceJobs
Reston, Virginia

The Swift Group is looking for a skilled AWS DevOps Engineer. The DevOps Engineer will be responsible for deploying and maintaining multiple development teams' AWS infrastructure along with utilizing CloudFormation and Ansible to automate the deployment of the entire infrastructure. Additionally, ma...

MITRE
McLean, Virginia

Use your skills as an offensive engineer and knowledge of adversary behaviors to build and emulate the cutting-edge capabilities of real-world threats. Propose and lead research to improve the state of the art of offensive security. Define and lead offensive security engagements to show blue teams h...

Capital One
McLean, Virginia

Plano 1 (31061), United States of America, Plano, TexasPrincipal Associate, Endpoint Security Engineer (AWS Endpoint Infrastructure). Bring a passion to stay on top of tech trends, experiment with and learn new technologies, participate in internal & external technology communities, and mentor other...

Amazon Development Center U.S., Inc.
Arlington, Virginia

As an AWS software development engineer, you will solve complex security challenges at a massive scale. Are you passionate about building insightful security solutions? At Amazon Web Services, security is job zero. Our team solves security hurdles in innovative ways, creating data-driven products to...