Amazon Security Jobs Seattle

Amazon

Offensive Security Engineer, AWS Bug Bounty

DESCRIPTION

AWS Security is a global team tasked with keeping the cloud safe. To help deliver for customers on this promise the AWS Bug Bounty team is currently seeking a security engineer with strong software development skils to join our team!

The primary responsibility of this role is to leverage your experience and internal knowledge of AWS systems to effectively triage a diverse set of incoming reports which can pertain to any of AWS’s 200+ services. As part of this role you will act as the escalation point for fellow members of the team and are expected to be an experienced pen-tester. Technical dive deep and curiosity are a way of life on this team in order to establish the true severity of a report and what defense in depth mechanisms need to happen beyond just an immediate patch.

Automation is the key to scaling and innovation at AWS and in this role you will own writing automation to reduce the load on humans; everything from developing ticketing, reporting and trend identification automation.

AWS Bug Bounty has a diverse set of customers: service owners and engineers, security leadership as well as our external crowd of researchers. Strong communication skills are required when providing excellent customer service for our customers, especially when growing our external crowd. As a senior engineer on the team, you will be expected to help deliver insights to leadership and assist service teams in prioritizing and remediating difficult security problems.

The development of the AWS researcher community is paramount to ensuring the success of our program and of our customers. As such we seek to earn researcher trust by being as transparent as possible with our responses to their reporting and our reward structures. As part of this team you will be expected to develop external messaging for both researchers and our own customer base. Above all else, a strong sense of Customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its Customers secure with the highest priority.

This role will provide you with challenging opportunities, both technologically and as a leader to grow AWS’s Bug Bounty Program into the best on planet Earth.

Key job responsibilities
– Researching, reproducing, and responding to security vulnerabilities reported through the bug bounty program
– Technical Escalation
– Managing relationships with external security researchers working with AWS’s bug bounty program
– Perform deep analysis of new vulnerability classes
– Driving improvements to team tooling, automation, and processes
– Influencing and driving program direction
– Identify and drive resolution of vulnerability trends
– Attend industry conferences and assist in hosting on site hack-a-thons and other researcher engagement activities

A day in the life
Our mornings typically start by looking at the queue of submitted reports that have already undergone initial triage by our third party partners. We single out reports that need urgent attention and then do a deep dive: reproducing, root causing and where appropriate extending the findings in the report to demonstrate maximum impact. Once done we coordinate with the internal stakeholders to drive the report until remediation.

We maintain a close partnership with other security teams across Amazon to surface reports and trend data that are relevant to their mission.

About the team
Inclusive Team Culture
Here at AWS, we embrace our differences. We are committed to furthering our culture of inclusion. We have ten employee-led affinity groups, reaching 40,000 employees in over 190 chapters globally. We have innovative benefit offerings, and host annual and ongoing learning experiences, including our Conversations on Race and Ethnicity (CORE) and AmazeCon (gender diversity) conferences. Amazon’s culture of inclusion is reinforced within our 16 Leadership Principles, which remind team members to seek diverse perspectives, learn and be curious, and earn trust.

Work/Life Balance
Our team puts a high value on work-life balance. It isn’t about how many hours you spend at home or at work; it’s about the flow you establish that brings energy to both parts of your life. We believe striking the right balance between your personal and professional life is critical to life-long happiness and fulfillment. We offer flexibility in working hours and encourage you to find your own balance between your work and personal lives.

Mentorship & Career Growth
Our team is dedicated to supporting new members. We have a broad mix of experience levels and tenures, and we’re building an environment that celebrates knowledge sharing and mentorship. We care about your career growth and strive to assign projects based on what will help each team member develop into a better-rounded professional and enable them to take on more complex tasks in the future.

We are open to hiring candidates to work out of one of the following locations:

Seattle, WA, USA

BASIC QUALIFICATIONS

– Regularly writes code in a modern scripting language (Python, Go, Ruby or JavaScript)
– Ability to understand and translate complex technical problems into business impact language
– 2+ years of experience with AWS cloud services
– 5+ years in an Information Security role, preferably in application security, offensive security, vulnerability research, or related technical engineering role
– 3+ years of experience with dynamic and manual code auditing to identify security issues
– A deep understanding of web application vulnerability classes
– Strong familiarity with reverse engineering, memory corruption and mobile application security basics
– Experience in one or more of the following categories: Bug Bounty Programs (Researcher, triager, manager); Offense oriented security testing (penetration testing, red teaming); Capture-the-Flag participant or organizer

PREFERRED QUALIFICATIONS

– Experience architecting and engineering technical solutions on AWS services
– Software development background with a focus on scaling and automation
– Working knowledge of Game Theory

To apply for this job please visit www.amazon.jobs.