security engineer for external vulnerability operations

HireHi

United States

Remote

USD 93,000 - 159,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Amazon ищет специалиста по безопасной разработке и исследованию уязвимостей для работы удаленно в регионе UK. Роль предусматривает взаимодействие с внутренними командами, исследователями и заказчиками, анализ рисков, моделирование угроз и внедрение remediation-мероприятий.

Кандидаты должны иметь опыт в безопасном кодировании, тестировании и работе с AWS, знанием языков Python/Java/C++, владение навыками анализа прошивок и отладки.

Qualifications

  • Опыт в рамках информационной безопасности и тестировании приложений.
  • Опыт в области безопасного кодирования, моделирования угроз и ответных действий на инциденты.
  • Знание AWS и облачных сервисов, а также HW/firmware связанных задач.

Responsibilities

  • Триаж внешних и внутренних уязвимостей и выработка remediation-решений.
  • Анализ рисков устройств и сервисов, сотрудничество с командами разработчиков.
  • Автоматизация повторяющихся задач и документирование решений.
  • Ведение документации для технической и нетехнической аудиторий.
  • Поддержка отношений с заказчиками и исследователями уязвимостей.

Skills

Security frameworks
Code reviews
Threat modeling
Penetration testing
Cloud security
Python/Java/C++
AWS services
Firmware analysis
Debugging device logs

Education

STEM degree

Tools

Bash/Python/Perl/Ruby

Job description

Описание

Amazon works with external security researchers and internal teams to secure its public-facing devices and services. Its security programs focus on vulnerability remediation, improving the security of device and software development, and protecting customers.

Задачи

Triage externally disclosed hardware and service security issues, suggest fixes, and collaborate with builder teams on remediation Identify risk trends in Amazon devices and services and collaborate with builder teams on remediation Automate manual processes to streamline security work Lead improvements to Amazon programs and processes Write and deliver high-quality documents for technical and non-technical audiences Manage relationships with customers and security researchers Use knowledge of Amazon to drive improvements to customer relationships, services, processes, and technologies Triage disclosed risks and collaborate with customers and security researchers to maintain and raise Amazon’s security standards Help ensure lessons learned through disclosure and mitigation improve the security of Amazon’s device and software development life cycle

Требования

Experience in one or more of application security frameworks, security code reviews, incident response, secure infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls, threat modeling, cryptography, threat intelligence, or secure software development Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and exploit development or equivalent Experience in scripting, programming, or security code reviewing in a common language such as Python, Java, or C++ Experience with AWS products and services Experience working with device technologies under development, familiarity with flashing firmware, basic device debugging and reading or pulling device logs, or scripting in one or more languages such as Bash, Python, Perl, or Ruby Deep understanding of hardware security, firmware analysis, operating system internals, and low-level programming Будет плюсом: A bachelor’s degree in a STEM field, 5+ years of experience in threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, or network security, experience supporting Red Team, Penetration Testing, or Bug Bounty programs

Условия

The role is remote anywhere within the UK; London is preferred, but other UK locations are also considered

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Security Engineer - External Vulnerability Ops
Remote Security Engineer - External Vulnerability Ops

HireHi • United States

Remote
USD 93,000 - 159,000
Security Engineer II, US Amazon Dedicated Cloud Security
Security Engineer II, US Amazon Dedicated Cloud Security

Amazon Web Services (AWS) • Jessup (MD)

On-site
USD 140,000 - 190,000
Security Engineer, CS Security
Security Engineer, CS Security

Amazon • Seattle (WA)

On-site
USD 90,000 - 150,000
Flexible work hours
Training and career growth opportunities
Work-life balance initiatives
+1
security engineer in cloud environments
security engineer in cloud environments

HireHi • United States

Remote
USD 90,000 - 130,000
Security Engineer, WWPS Solutions Architecture
Security Engineer, WWPS Solutions Architecture

Amazon • San Francisco (CA)

On-site
USD 90,000 - 150,000
Security Engineer, AWS Proactive Security
Security Engineer, AWS Proactive Security

Amazon • Northern (KY)

On-site
USD 136,000 - 184,000
security engineer for HR technology
security engineer for HR technology

HireHi • United States

Remote
USD 150,000 - 210,000
Annual training budget
Pension plan
Travel reimbursement
+3
Senior Security Engineer, Stores AppSec
Senior Security Engineer, Stores AppSec

Amazon • Austin (TX)

On-site
USD 90,000 - 150,000
Work-Life Harmony
Training & Career Growth
Flexible Working Culture
+1
Security Engineer II, Stores AppSec
Security Engineer II, Stores AppSec

Amazon • New York (NY)

On-site
USD 159,000 - 202,000
Health insurance
RSUs
401(k) matching
+1
Security Engineer SoC, Devices and Services Security
Security Engineer SoC, Devices and Services Security

Amazon Inc. • Seattle (WA)

On-site
USD 159,000 - 202,000
Health insurance
401(k) matching
Paid time off