Bug Bounty Security Engineer, AWS Bug Bounty

31 Jul 2024
Apply

DescriptionThe AWS Proactive Security's Bug Bounty team, part of the Amazon Security organization, is growing and is seeking a security engineer to join the team. This individual will be working with customers, AWS teams, and Amazon teams to secure AWS public facing services, applications, and websites. In this role, you will be part of a team of skilled individuals and work to solicit the identification of vulnerabilities from customers and security researchers. You will be responsible for ensuring vulnerabilities are remediated with urgency by partnering with service teams, and ensuring what is learned through disclosure and mitigation improves the security of Amazon’s software development life-cycle. This role will provide you with challenging technical opportunities, and the chance to shape and grow the AWS Security Bug Bounty Program.You will be in direct contact with teams in a variety of business verticals, giving you first hand knowledge about how Amazon is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Amazon to find new ways to drive improvements to customer relationships, services, processes, and technologies throughout the company, with the ultimate goal of ensuring the continued safety and security of our customers.As a security engineer, you will use your influence and technical skills to continually lead the direction and evolution of the Bug Bounty Program and collaboration with customers and security researchers in order to maintain and raise Amazon’s high security bar. You’ll be backed up by a team of highly-skilled security engineers all working with a singular focus of maintaining customer trust. You must demonstrate resilience and navigate ambiguous situations with composure and tact. Above all else, a strong sense of Customer Obsession is necessary to focus on the ultimate goal of keeping Amazon and its customers secure with the highest priority.AWS Bug Bounty has a diverse set of customers: service owners and engineers, security leadership as well as our external crowd of researchers. Strong communication skills are required when providing excellent customer service for our customers, especially when growing our external crowd. As a senior engineer on the team, you will be expected to help deliver insights to leadership and assist service teams in prioritizing and remediating difficult security problems.The development of the AWS researcher community is paramount to ensuring the success of our program and of our customers. As such we seek to earn researcher trust by being as transparent as possible with our responses to their reporting and our reward structures. As part of this team you will be expected to develop external messaging for both researchers and our own customer base.Key job responsibilities

Available for after-hours paging for high-priority escalations

Coordinate security incident response and vulnerability management activities with service teams to do the right thing for our Customers and the business

Evaluate the potential and/or realized impact of security incidents and work with service teams to mitigate risks

Serve as an escalation point and subject matter expert in incident response, engineering operations, and team triage activities as part of day to day operations

Tactically drive initiatives by influencing key stakeholders and partnering with security and business teams throughout Amazon

Drive improvements to the team’s programs and processes

Write and deliver high-quality documents for technical and non-technical audiences

Manage relationships with Customers and security researchers

About the teamAbout Amazon SecurityDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.Basic Qualifications

5+ years experience in application security, incident response, or vulnerability management roles

5+ years of experience in Information Security related domains, with knowledge of security fundamentals, common application vulnerabilities, application attack vectors, methodologies and tools, threat modeling, code auditing, web application penetration testing, and web services pentesting.

5+ years of experience driving Information Security initiatives across large diverse organizations and communicating with a wide range of technical & non-technical partners and senior leadership

Minimum of 5 years of professional experience with 2 or more areas of security engineering practices such as in web application security, authentication and authorization protocols, automation

Experience with AWS technologies and services (e.g. S3, Lambda, EC2, KMS, IAM, etc.).

Preferred Qualifications

Ability to take ownership, self-motivate, and deliver results in highly ambiguous environments

Experience with driving remediation/mitigation of security issues and control gaps

Experience gathering and reporting metrics to measure service and program effectiveness and consistency

Technical knowledge of adversary Tactics, Techniques, and Procedures (TTPs)

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Full-time
  • ID: #52203281
  • State: Texas Virtuallocationtexas 00000 Virtuallocationtexas USA
  • City: Virtuallocationtexas
  • Salary: USD TBD TBD
  • Showed: 2024-07-31
  • Deadline: 2024-09-29
  • Category: Et cetera
Apply