Security Engineer, Compliance Penetration Testing
Core
Conducting high-quality penetration tests and offensive security assessments on Amazon's services, applications, and websites to identify vulnerabilities and support regulatory compliance.
Role type
Senior IC application security penetration tester
Builds
Detailed engagement plans, vulnerability reports, and remediation recommendations for internal teams and external auditors
Domain
Cloud security, web applications, APIs, and regulated market compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Application penetration testing, offensive security assessments, vulnerability identification and exploitation, scripting, networking protocols (HTTP, DNS, TCP/IP), report writing, stakeholder communication
Preferred skills
SDLC security integration, AWS product knowledge, backend service testing, security automation, AI/LLM-assisted testing, regulatory framework knowledge (PCI DSS, SOX, GDPR), testing standards (OWASP ASVS, PTES), offensive security certifications (OSCP, OSWE, GPEN, PenTest+)
Technologies
AWS, HTTP, DNS, TCP/IP, OWASP ASVS, OWASP Top 10, PTES
Responsibilities
Conducting independent or team-based penetration tests, creating engagement plans, documenting findings and remediation guidance, collaborating with partner teams to drive resolution, contributing to team tooling and innovation
Seniority
Senior, hands-on IC