Amazon logo
Amazon
Posted 44 days agoVerified live 17h ago

Mobile Security Engineer, Application Security

Brief overview

Remote
UndergradOr in progress
$159k–$202k/yrStated range
3+ yrsMinimum
17,535 H-1B approvalsDept. of Labor
9,838 green cardsCertified filings
Application Penetration TestingClient-Side Application SecurityReverse EngineeringWeb Application SecurityAuthentication and Authorization ProtocolsCryptographyDynamic and Manual Code AuditingPythonThreat ModelingBinary Analysis ToolsClient-Side Application InstrumentationDynamic TestingMobile Application Penetration Testing

About the company

Amazon is a tech firm with a focus on e-commerce, cloud computing, digital streaming, and artificial intelligence.

Visa sponsorship history

4 years sponsoring, last filed FY2026H-1B dependent

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
17,535H-1B approved
95%approval rate
4,213new H-1B hires
9,838PERM certified
$194,500median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20235,035
20245,735
20254,327
20262,438
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20233,533
20245,158
20253,940
20263,351
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20236,267
20243,567
20251
20263
Top sponsored roles
Software Development Engineer IIProfessional Services IISolutions Architect IIISoftware Development Engineer IProfessional Services III
Sponsored employees from
IndiaChinaCanadaBrazilNigeria

Job description

Summary

Amazon is seeking a Mobile Security Engineer to help protect its customers and services through offensive security work. The role conducts penetration testing of mobile applications and services, identifies and documents security issues, contributes to security tooling and innovation, and collaborates with teams and leadership to drive remediation.

Responsibilities

  • Conducting high quality application penetration tests independently, or as part of a team
  • Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
  • Contributing to team tooling, innovation, and improvements
  • Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings

Skills

  • Bachelor's degree in computer science or equivalent
  • 3+ years of experience in a penetration testing or similar offensive security role
  • 3+ years of experience in client-side application security, including reverse engineering and security assessments
  • 3+ years of professional experience with security engineering practices, including: web application security, authentication and authorization protocols, cryptography, automation, and other software security disciplines
  • 3+ years of experience with dynamic and manual code auditing to identify security issues
  • 3+ years of experience with interpreted or compiled languages (e.g. Python, Ruby, C/C++, Java, .NET)
  • Experience with threat modeling, design review, or other threat analysis techniques
  • Proficiency with binary analysis tools (e.g. Ghidra, IDA Pro, Radare2, Hopper, Jadx)
  • Experience with client-side application instrumentation and dynamic testing (e.g. Frida, Objection, LLDB, Burp Suite)
  • Knowledge of cloud services such as AWS or equivalent
  • Experience with design, implementation, support, and evaluation of security-focused tools and services
  • Experience with mobile application penetration testing
  • Familiarity with threat models for client-side applications on consumer devices and the vulnerability classes specific to their platforms and communication protocols
  • Experience mentoring developers on secure coding practices and vulnerability mitigations
  • Experience in CTF competitions, CVE research, and/or Bug Bounty recognition

Qualifications

Must Haves

  • Bachelor's degree in computer science or equivalent
  • 3+ years of experience in a penetration testing or similar offensive security role
  • 3+ years of experience in client-side application security, including reverse engineering and security assessments
  • 3+ years of professional experience with security engineering practices, including: web application security, authentication and authorization protocols, cryptography, automation, and other software security disciplines
  • 3+ years of experience with dynamic and manual code auditing to identify security issues
  • 3+ years of experience with interpreted or compiled languages (e.g. Python, Ruby, C/C++, Java, .NET)
  • Experience with threat modeling, design review, or other threat analysis techniques
  • Proficiency with binary analysis tools (e.g. Ghidra, IDA Pro, Radare2, Hopper, Jadx)
  • Experience with client-side application instrumentation and dynamic testing (e.g. Frida, Objection, LLDB, Burp Suite)

Nice to Haves

  • Knowledge of cloud services such as AWS or equivalent
  • Experience with design, implementation, support, and evaluation of security-focused tools and services
  • Experience with mobile application penetration testing
  • Familiarity with threat models for client-side applications on consumer devices and the vulnerability classes specific to their platforms and communication protocols
  • Experience mentoring developers on secure coding practices and vulnerability mitigations
  • Experience in CTF competitions, CVE research, and/or Bug Bounty recognition

Benefits

  • Sign-on payments
  • Restricted stock units (RSUs)
  • Health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage)
  • 401(k) matching
  • Paid time off
  • Parental leave
  • Ongoing DEI events and learning experiences
  • Endless knowledge-sharing, training, and other career-advancing resources
  • Flexible work hours and arrangements

More jobs like this