Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Amazon ищет специалиста по безопасной разработке и исследованию уязвимостей для работы удаленно в регионе UK. Роль предусматривает взаимодействие с внутренними командами, исследователями и заказчиками, анализ рисков, моделирование угроз и внедрение remediation-мероприятий.
Кандидаты должны иметь опыт в безопасном кодировании, тестировании и работе с AWS, знанием языков Python/Java/C++, владение навыками анализа прошивок и отладки.
Amazon works with external security researchers and internal teams to secure its public-facing devices and services. Its security programs focus on vulnerability remediation, improving the security of device and software development, and protecting customers.
Triage externally disclosed hardware and service security issues, suggest fixes, and collaborate with builder teams on remediation Identify risk trends in Amazon devices and services and collaborate with builder teams on remediation Automate manual processes to streamline security work Lead improvements to Amazon programs and processes Write and deliver high-quality documents for technical and non-technical audiences Manage relationships with customers and security researchers Use knowledge of Amazon to drive improvements to customer relationships, services, processes, and technologies Triage disclosed risks and collaborate with customers and security researchers to maintain and raise Amazon’s security standards Help ensure lessons learned through disclosure and mitigation improve the security of Amazon’s device and software development life cycle
Experience in one or more of application security frameworks, security code reviews, incident response, secure infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls, threat modeling, cryptography, threat intelligence, or secure software development Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and exploit development or equivalent Experience in scripting, programming, or security code reviewing in a common language such as Python, Java, or C++ Experience with AWS products and services Experience working with device technologies under development, familiarity with flashing firmware, basic device debugging and reading or pulling device logs, or scripting in one or more languages such as Bash, Python, Perl, or Ruby Deep understanding of hardware security, firmware analysis, operating system internals, and low-level programming Будет плюсом: A bachelor’s degree in a STEM field, 5+ years of experience in threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, or network security, experience supporting Red Team, Penetration Testing, or Bug Bounty programs
The role is remote anywhere within the UK; London is preferred, but other UK locations are also considered