Mobile Security Engineer, Application Security
Core
Conduct offensive security assessments on Amazon's mobile applications and services to identify and remediate vulnerabilities.
Role type
Senior IC mobile security engineer (application security)
Builds
Secure mobile applications and client-side services for Amazon customers
Domain
E-commerce, retail, and cloud security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing, reverse engineering, client-side application security, web application security, authentication/authorization protocols, cryptography, automation, dynamic code auditing, interpreted/compiled languages, threat modeling, binary analysis, client-side instrumentation
Preferred skills
AWS cloud services, security tool design/implementation, mobile app penetration testing, threat modeling for consumer devices, secure coding mentorship, CTF competitions, CVE research, bug bounty recognition
Technologies
Ghidra, IDA Pro, Radare2, Hopper, Jadx, Frida, Objection, LLDB, Burp Suite
Responsibilities
Conduct high-quality application penetration tests independently or in teams; create engagement plans and document findings with remediation recommendations; contribute to team tooling and innovation; collaborate with partner teams and leadership to drive security finding resolution
Seniority
Senior, hands-on IC