The point where experts and best companies meet
Share
We are looking for a Security Engineer to help secure our foundational platforms with an emphasis on hardware. You will be responsible for conducting security reviews including hands-on security evaluations (penetration testing), analyzing threat models, and developing tooling that will help detect security issues at scale.You should be comfortable with tackling novel technical situations, and conducting hands-on testing of new, unique surfaces, to ensure proper security mitigations are in place. You will provide crystal-clear technical direction and risk mitigation guidance for diverse engineering and business leaders at all levels. By applying your hard-earned years of practical security engineering expertise in projects related to securing hardware, you will literally shape the future of cloud computing. Along the way, we guarantee that you will learn a ton, have fun, and make a positive impact on millions of people.
Key job responsibilities
• Security reviews for hardware including servers and devices
• Penetration testing & vulnerability research
• Threat modeling
• Security training and outreach to internal development teams
• Security guidance documentation
• Assistance with recruiting activities
Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life Balance
- BS in Computer Science or related field, or equivalent work experience
- Minimum of 3 years of experience in Security Engineering or Development of Security capabilities, supporting engineering projects from concept to delivery, and 1 years in one or more of the following technical categories:
- Virtualization security (Xen, KVM, QEMU)
- Hardware security (PCB, JTAG, UART, SPI, ROM, microcode, custom ASIC/FPGA)
- x86 and/or ARM chipset and firmware security (TPM, UEFI, TrustZone, Secure Boot, PCIe)
- Security testing including code review of compute platforms (Server, PC or Mobile)
- MS in Computer Science, Information Security, or related field, or equivalent work experience
- Demonstrated ability to prepare technical specifications and communications
- Demonstrated understanding of crypto basics (encryption, signing, certificates, common algorithms)
- Familiarity with AWS services (EC2, GuardDuty, S3, IAM, Kinesis, Lambda, KMS, VPC, etc) and familiarity with relevant security standards (TCG, IEEE, NIST, FIPS, PCI, ISO 28000 series)
- Familiarity with crypto security design concepts (e.g. certificate handling and PKI, attestation, TPM/HSM)
- Knowledge of Windows, Linux, and hypervisor security (especially in cloud environments)
- Ability to manually audit source code (One or more of: Java, Ruby, Python, JavaScript, Rust, C, others) to find security issues
These jobs might be a good fit