Virtual, US
3 days ago
Pentest Security Engineer II, Devices & Services Pentesting
The Amazon Devices and Services Trust & Security (DSTS) penetration testing organization is growing and seeking an experienced hardware security researcher to help shape the future of Amazon's device security. You will work with hardware teams and product owners to perform advanced hardware analysis and identify high-impact security vulnerabilities across Amazon's device ecosystem. The ideal candidate will be expected to master debugging interfaces (JTAG, SWD, UART) and perform sophisticated hardware attacks including voltage/clock glitching, side-channel analysis (power/EM), and hardware-focused fuzzing techniques. In addition to the hardware, we expect device pentesters to be skilled in assessing the software, including operating systems (Linux/Android OS or FreeRTOS), doing security reviews of C/C++ code, ability to audit bootloaders, trusted execution environments, and radio/networking protocols like bluetooth, wifi, zigbee, and LoRaWAN. This role will provide you with challenging technical opportunities to break hardware security mechanisms and will be a great deal of fun if extracting secrets from silicon sounds exciting to you!

The Amazon DSTS organization was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers’ trust, data, and the systems on which they rely. We protect customers by performing security reviews, offensive testing, vulnerability assessments, and provide guidance for remediations. DSTS builds the foundational capabilities that raise an org-wide security bar across the growing diversity of D&S businesses - securing 100+ device types, 12,000+ applications, and 100+ product lines that are developed and operated by more than 16,000+ builders.

In this role, you will be part of a dedicated team of talented penetration testers identifying vulnerabilities in the devices and services ecosystem. You will strive to understand systems, software, and services deeply and develop creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping millions of customers that rely on Amazon’s consumer products safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams. You're well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization. If you're passionate about finding security bugs, writing tools to enhance manual testing capabilities, automating repetitive tasks, and enjoy seeing your work impact Amazon consumer devices and services, then this position is for you. Candidates from mid to senior level are encouraged to apply.

Key job responsibilities
- Lead and contribute to penetration tests against hardware and software released by Amazon’s Devices & Services organization. This includes working closely with builder teams to scope pentests, develop test plans, find vulnerabilities, develop proof of concept exploits, report findings, and validate patches.
- Review and influence technical solutions to mitigate security vulnerabilities by providing actionable long-term risk mitigation guidance to drive security improvements.
- Lead impactful security improvements in large product lines through close collaboration with our partner builder teams.
- Develop detailed technical documentation describing identified vulnerabilities, associated impact, and recommended remediation to guide communication with internal engineering stakeholders and leadership.
- Mentor junior penetration testers and cultivate a culture of collaboration and research sharing.

About the team
While the majority of our Security team are based in the US, by applying to this position your application will be considered for all locations we hire for in the world, however candidates should expect to accommodate US time for necessary meetings.
Our team puts a high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren’t focused on how many hours you spend at work or online. Instead, we’re happy to offer a flexible schedule so you can have a more productive and well-balanced life—both in and outside of work.
Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about career growth and strive to assign projects based on what will help each team member develop into a better-rounded engineer and enable them to take on more complex tasks in the future.
Confirm your E-mail: Send Email