Security Engineer, Compliance Penetration Testing
Core
Conducting high-quality penetration tests on Amazon's services, applications, and websites to identify security issues and support regulatory compliance. (via careerplan.io/jobs/10497962-security-engineer-compliance-penetration-testing-at-amazon)
Role type
Senior IC application security penetration tester
Builds
Security reports, remediation guidance, and improved testing tooling
Domain
Cloud security, application security, regulatory compliance
Required skills
Application penetration testing, vulnerability identification and exploitation, report writing, Python/Go/Java/Ruby scripting, business logic flaw analysis
Preferred skills
AWS product knowledge, security automation development, regulatory framework expertise (PCI DSS, SOX, GDPR), backend service testing, OWASP standards familiarity, AI/LLM-assisted testing tools
Technologies
Python, Go, Java, Ruby, AWS, OWASP ASVS, OWASP Top 10, PTES
Responsibilities
Conduct independent or team-based penetration tests, create engagement plans and document findings with remediation recommendations, contribute to team tooling and innovation, collaborate with partner teams and leadership to drive security finding resolution
Seniority
Senior, hands-on IC