Finding the best job has never been easier
Share
Engineers in this role must show exemplary judgment in making technical trade-offs between short versus long term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. Conflicts should be addressed by listening, finding the best way forward and persuading one’s colleagues. Successful engineers in this role will regularly analyze their own performance with a critical eye. A broad understanding of the AWS business and its interconnections is required. This position will also provide training and mentorship to other engineers throughout AWS and will be expected to provide thought leadership for the organization as you invent and innovate in the course of your duties.Key job responsibilities
1. Vulnerability Identification and Tracking
2. Offensive security testing & vulnerability research
3. Emergent threat testing
4. Creating/maintaining automated threat emulation solutions
5. Recommendation of findings and threat mitigations
6. Produce high quality red team reports
7. Projects and research work as needed
8. Security training and outreach to internal development teams
9. Security guidance documentation
10. Security tool development
11. Security metrics delivery and improvements
12. Assistance with recruiting activitiesMentorship & Career Growth
- A Bachelor’s degree in Computer Science, Cybersecurity, similar degree, or equivalent professional experience can be used in lieu of a degree.
- Minimum of 5 years of experience in security testing (Penetration testing, Vulnerability testing, Red teaming, bug hunting or CTF experience)
- Minimum of 5 years of experience with manually auditing source code (One or more of: Java, Ruby, Python, JavaScript, Rust, C, others) to find security issues.
- Minimum of 5 years of experience scripting in Python or other equivalent interpreted languages.
- Minimum of 5 years of professional experience with security engineering practices such as in web application security, network security, authentication and authorization protocols, cryptography, automation and other software security disciplines.
- Experience with AWS technologies and services (e.g. S3, Lambda, EC2, KMS, IAM, etc.)
- Experience with bug hunting, bug bounties, capture the flag, software development
- Experience with multiple programming languagesPursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
These jobs might be a good fit