Summary
Amazon is seeking a Mobile Security Engineer to help protect its customers and services through offensive security work. The role conducts penetration testing of mobile applications and services, identifies and documents security issues, contributes to security tooling and innovation, and collaborates with teams and leadership to drive remediation.
Responsibilities
- Conducting high quality application penetration tests independently, or as part of a team
- Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
- Contributing to team tooling, innovation, and improvements
- Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings
Skills
- Bachelor's degree in computer science or equivalent
- 3+ years of experience in a penetration testing or similar offensive security role
- 3+ years of experience in client-side application security, including reverse engineering and security assessments
- 3+ years of professional experience with security engineering practices, including: web application security, authentication and authorization protocols, cryptography, automation, and other software security disciplines
- 3+ years of experience with dynamic and manual code auditing to identify security issues
- 3+ years of experience with interpreted or compiled languages (e.g. Python, Ruby, C/C++, Java, .NET)
- Experience with threat modeling, design review, or other threat analysis techniques
- Proficiency with binary analysis tools (e.g. Ghidra, IDA Pro, Radare2, Hopper, Jadx)
- Experience with client-side application instrumentation and dynamic testing (e.g. Frida, Objection, LLDB, Burp Suite)
- Knowledge of cloud services such as AWS or equivalent
- Experience with design, implementation, support, and evaluation of security-focused tools and services
- Experience with mobile application penetration testing
- Familiarity with threat models for client-side applications on consumer devices and the vulnerability classes specific to their platforms and communication protocols
- Experience mentoring developers on secure coding practices and vulnerability mitigations
- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
Qualifications
Must Haves
- Bachelor's degree in computer science or equivalent
- 3+ years of experience in a penetration testing or similar offensive security role
- 3+ years of experience in client-side application security, including reverse engineering and security assessments
- 3+ years of professional experience with security engineering practices, including: web application security, authentication and authorization protocols, cryptography, automation, and other software security disciplines
- 3+ years of experience with dynamic and manual code auditing to identify security issues
- 3+ years of experience with interpreted or compiled languages (e.g. Python, Ruby, C/C++, Java, .NET)
- Experience with threat modeling, design review, or other threat analysis techniques
- Proficiency with binary analysis tools (e.g. Ghidra, IDA Pro, Radare2, Hopper, Jadx)
- Experience with client-side application instrumentation and dynamic testing (e.g. Frida, Objection, LLDB, Burp Suite)
Nice to Haves
- Knowledge of cloud services such as AWS or equivalent
- Experience with design, implementation, support, and evaluation of security-focused tools and services
- Experience with mobile application penetration testing
- Familiarity with threat models for client-side applications on consumer devices and the vulnerability classes specific to their platforms and communication protocols
- Experience mentoring developers on secure coding practices and vulnerability mitigations
- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
Benefits
- Sign-on payments
- Restricted stock units (RSUs)
- Health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage)
- 401(k) matching
- Paid time off
- Parental leave
- Ongoing DEI events and learning experiences
- Endless knowledge-sharing, training, and other career-advancing resources
- Flexible work hours and arrangements