Security Engineer II, Specialized Businesses Security, External Vulnerability Operations
Core
Triage externally disclosed hardware and service security issues, identify risk trends, and collaborate with builder teams to remediate vulnerabilities in Amazon's public-facing devices and services.
Role type
Senior IC security engineer (external vulnerability operations & threat intelligence)
Builds
Amazon's Bug Bounty and Threat Intelligence programs, secure device and software development life cycle
Domain
Cybersecurity, hardware security, firmware analysis, cloud security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure
Required skills
application security frameworks, security code reviews, incident response, secure infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls, threat modeling, cryptography, threat intelligence, secure software development, system security vulnerabilities, exploit development, scripting, programming, AWS products, device technologies, firmware flashing, device debugging, log analysis, low-level programming
Preferred skills
threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, network security, Red Team support, Penetration Testing, Bug Bounty program support
Technologies
Python, Java, C++, Bash, Perl, Ruby, AWS
Responsibilities
Triage externally disclosed hardware and service security issues, suggest fixes, and collaborate with builder teams for remediation; Identify risk trends in Amazon devices and services, and collaborate with builder teams for remediation; Automate manual processes to streamline security work; Lead improvements to Amazon programs and processes; Write and deliver high-quality documents for technical and non-technical audiences; Manage relationships with Customers and security researchers
Seniority
Senior, hands-on IC