Pentest Security Engineer, Devices & Services Pentesting

Come join our penetration testing team dedicated to the detection and exploitation of vulnerabilities from Amazon’s consumer services and devices to the Kuiper satellites. This includes conducting in-depth reviews of complex service workflows including authentication mechanisms, AI, mobile, web applications, and web service APIs. Pentesters also invent new ways to automate and improve their work with techniques including AI/LLMs, fuzzing, detection at scale, and static analysis.Our team operates under the Amazon Devices and Services Trust & Security (DSTS) organization which was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers’ trust, data, and the systems on which they rely. We protect customers by performing security reviews, offensive testing, vulnerability assessments, and provide guidance for remediations. We drive down costs by building and automating security foundations and integrating them into design and release processes. DSTS builds the foundational capabilities that raise an org-wide security bar across the growing diversity of D&S businesses - securing 100+ device types, 12,000+ services, and 100+ product lines that are developed and operated by more than 16,000+ builders.The DSTS penetration testing organization is growing and seeking an experienced web penetration tester to help shape the future of Amazon’s service security. You will work with builder teams and product owners to perform penetration testing and identify high-impact security vulnerabilities across the web services ecosystem supporting Amazon’s devices. The ideal candidate will be expected to comprehend large complex web service architectures, dive deep into a service's source code, and to get some exposure to device penetration tests. This role will provide you with challenging technical opportunities and will also be a great deal of fun if hacking Amazon sounds exciting to you! In this role, you will be part of a dedicated team of talented penetration testers identifying vulnerabilities in the devices and services ecosystem. You will strive to understand systems, software, and services deeply and develop creative ways to break assumptions in order to find vulnerabilities. You care deeply about keeping millions of customers that rely on Amazon’s consumer products safe and are passionate about mitigating vulnerabilities by providing actionable guidance to product teams. You're well-known for your excellent prioritization skills as well as your ability to communicate at all levels of an organization. If you're passionate about finding security bugs, writing tools to enhance manual testing capabilities, automating repetitive tasks, and enjoy seeing your work impact Amazon consumer devices and services, then this position is for you. Candidates from mid to senior level are encouraged to apply.Key job responsibilities- Contribute to penetration tests against services and software released by Amazon’s Devices & Services organization. This includes working closely with builder teams to find vulnerabilities, develop proof of concept exploits, report findings, and validate patches.- Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.- Review and influence technical solutions to mitigate security vulnerabilities by providing actionable long-term risk mitigation guidance to drive security improvements.- Provides impactful security contributions to large product lines through close collaboration with our partner builder teams.- Develop detailed technical documentation describing identified vulnerabilities, associated impact, and recommended remediation to guide communication with internal engineering stakeholders and leadership.- Continuous growth and development of technical skillsets while contributing to standing projects for program improvement in DSPT.About the teamWhile the majority of our Security team are based in the US, by applying to this position your application will be considered for all locations we hire for in the world, however candidates should expect to accommodate US time for necessary meetings.Our team puts a high value on work-life balance. Striking a healthy balance between your personal and professional life is crucial to your happiness and success here, which is why we aren’t focused on how many hours you spend at work or online. Instead, we’re happy to offer a flexible schedule so you can have a more productive and well-balanced life—both in and outside of work.Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about career growth and strive to assign projects based on what will help each team member develop into a better-rounded engineer and enable them to take on more complex tasks in the future.Diverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.BASIC QUALIFICATIONS- Bachelor’s degree in Computer Science or related field and 1+ year of equivalent industry experience or 3+ years of equivalent industry experience.- Core understanding of web application and service API vulnerabilities (e.g. mass assignment, broken object/function level authorization, JWT/OAuth, injection, business logic flaws, excessive data exposure, etc.).- Experience tracing sources and sinks during code review to identify vulnerabilities, and providing contextual remediation guidance to address vulnerability root cause.- Experience designing and reviewing secure system architectures through the use of Threat Modeling incorporating sophisticated and modern attacks.- Knowledge of cloud service providers and their offerings, preferably AWS, and its various technologies and services. ...

Sr. Construction Manager, North America Construction Manager

Amazon is looking for a Construction Manager who will be responsible for project management ofbuilding industrial development including new builds, retrofits, expansion, and program initiatives fromsite selection through contract execution. Construction Managers are responsible for construction ofnew Fulfillment Centers (FCs) in the US as well as renovations & tenant improvements at existing FCs.Construction Managers will also handle the implementation of the facility network infrastructure; including sortation centers, delivery stations, and auxiliary buildings that support those facilities. The construction projects include new builds, retrofits, and expansions. Construction Managers are required to perform detailed deep dive reviews of job budgets and schedules to identify and resolve any discrepancies, including information in contractor bid packages. Construction Managers will partner with internal customers and external stakeholders to earn their trust and engage as a team to deliver results. The Construction Manager will serve as Amazon's representative and direct point of interface with Developers and General Contractors, as well as the primary integrator between construction and other Amazon stakeholders responsible for equipping, furnishing, and operating our FCs. This opportunity combines construction engineering, planning, project management, facilities management, and contract management.Key job responsibilities• Responsible for project management over new construction of Fulfillment Centers throughout the US as well as renovations and capacity improvements within existing facilities.• Advise on the impact of changes in schedule, costs, and permitting.• Support construction scope review and development with internal technical teams and operational customers to facilitate engineering and design efforts on new and remodel projects.• Responsible for managing multiple projects simultaneously, from relatively small renovations to large-sized ($100M+) new facilities.• Work independently in the assigned regional area with minimal direction from leadership.• Prepare reports, specifications, technical analysis to fully define the design requirements, equipment and services required on capacity expansion and remodel projects.• Provide technical direction concerning engineering design / AutoCAD, building design, layouts, build details, schedules and materials in accordance with North American Customer Fulfillment (NACF) design parameters.• Survey facilities, develop and document procedures to audit the facility, provide evaluations and analysis, and recommend solutions to facility infrastructure, safety and security problems involving facilities and people.• Negotiate contracts and contract changes with developers and General Contractors, and present formal documentation for approval when required.• Ensure that contracts are fit for purpose, cost effective, and incorporate appropriate Service Level Agreements.• Provide overall site management, coordination, planning, specification of business proposals, and coordination of subcontractors.• Facilitate and team with others on due diligence evaluation of new opportunities.• Assess project performance through Key Performance Indicators for safety, quality, cost, schedule, and sustainability.• Partner with teams tasked with transition of base building management and oversight of all turnover documentation.• Coach and guide all project teams (developers, design engineers, general contractors, sub-contractors, internal stakeholders) throughout the full project lifecycle.• Ensure that contracted resources deliver work to meet duration and quality targets, addressing and ensuring the correction of under-performance issues.• Audit contractors to check that the skills and competencies of contract labor are appropriate to need and they are fit to undertake the work on which they will be deployed.• Inform developers and contractors of projected changes in resource or work demand so that they can take appropriate action.• Identify and resolve clashes, design misses, and schedule conflicts with other Amazon execution teams.• Establish and operate the information systems necessary for effective scheduling and recording of contract work.• Review of designs and ongoing construction for conformance to current building specifications.• Provide critical review of current design standards to identify value engineering and design enhancement opportunities to be considered by internal engineering and schematic design partners.• Comprehensive budget tracking, forecasting, and management of assigned expansion, remodel, and new build projects.• Receipt, review, and analysis of all proposed cost and time change requests as presented by external project teams.• Review and guide internally requested changes for validity, impact, and ensure timely and cost sensitive incorporation once approved.• Lead or assist in negotiations with appropriate regulatory bodies and Authority Having Jurisdiction (AHJ) entities as required.• Positive, clear, concise, and transparent cross team communication for all aspects of project delivery.• The role is remote and will include upwards of 60% travel regionally, with the potential of traveling to all North America locations based on the business needs.BASIC QUALIFICATIONS- A completed Bachelor’s degree in Architecture, Engineering, Construction Management or comparable field- 7+ years of experience as an Architect, Engineer, Construction Manager, or other Construction related disciplines- 7+ years project management experience from design phase through implementation and operation- 7+ years of experience negotiating construction, procurement and labor contracts- 7+ years familiarization with AutoCAD and/or Building Information Modeling (BIM), as well as scheduling software (Primavera, MS Project, or similar) ...

We show restricted results, but there are more jobs available in our database, use Search to see them