Come join our penetration testing team dedicated to the detection and exploitation of vulnerabilities affecting Amazon consumer devices and supporting services. You’ll lead a team of high-performing penetration testers that conduct in-depth and low-level reviews of hardware, bootloaders, radios, secure enclaves, embedded systems as well as services including authentication mechanisms, AI, mobile, web applications, and web service APIs.

The Amazon Devices and Services Trust & Security (DSTS) organization was formed in 2014 with the mission of protecting Amazon Devices & Services (D&S) customers’ trust, data, and the systems on which they rely. We protect customers by performing security reviews, offensive testing, vulnerability assessments, incident response and remediations. We also drive down costs by building and automating security foundations and integrating them into design and release processes. DSTS builds the foundational capabilities that raise an org-wide security bar across the growing diversity of D&S businesses - securing 100+ device types, 12,000+ applications, and 100+ product lines that are developed and operated by more than 16,000+ builders. DSTS provides security foundations for the builder teams that have produced groundbreaking devices like Amazon Echo, Astro, Kuiper, Ring Always Home Cam Drone, Fire tablets, and Fire TV. What will you help us create?

Are you interested in being part of a world-class security team covering Amazon consumer devices and key Amazon services? Do you want to be part of the penetration testing team dedicated to detection and exploitation of vulnerabilities in order to keep Amazon costumers safe? Your work directly impacts the way our customers, teams, and business across the globe get things done. If you want to protect the millions of Amazon customers that rely on Amazon consumer products, then we have a job for you!

The penetration testing organization is growing and seeking an experienced manager to lead one of our internal penetration testing teams. In this role, you will lead a team of highly skilled penetration testers to assess Amazon’s devices, services, applications, and websites; and partner with other security and builder teams to remediate weaknesses and sharpen our software development lifecycle. This role will provide you with challenging leadership and technical opportunities, but will also be a great deal of fun if hacking Amazon sounds exciting to you!

You will be focused on using your technical leadership skills to continually lead the direction and evolution of the team and orchestrate penetration testing engagements to raise Amazon’s high security bar. Additionally, you’ll be driving strategic initiatives from your team by influencing key stakeholders and partnering with teams throughout Amazon to enable the implementation of innovative security solutions and controls to improve Amazon’s security and software development posture. You’ll be backed up by a team of highly-skilled penetration testers focused on attacking Amazon from a variety of perspectives, all working with a singular focus of maintaining our customer’s trust. You must also navigate ambiguous situations with composure and tact. Above all else, a strong sense of Customer Obsession is necessary to focus on the ultimate goal of keeping Amazon and its customers secure.


Key job responsibilities
* Lead, manage, and develop a high-performing Penetration Testing Team across multiple locations
* Manage and coordinate complex penetration testing projects involving multiple penetration testers, technology stacks, and development teams
* Lead the strategic direction and evolution of the Penetration Testing Team, including setting goals and establishing priorities
* Drive strategic initiatives by influencing leadership, key stakeholders, and partnering with teams throughout Amazon
* Lead effective teamwork, communication, collaboration, and commitment across multiple disparate groups with competing priorities
* Lead improvements to internal program and process
* Write and deliver high-quality documents for technical and non-technical audiences

A day in the life
The internal penetration testing team is part of the Devices and Services Trust & Security organization, which is responsible for the entire SDLC, vulnerability management, incident response, and overall security across Amazon Consumer Devices & Services (Kindle, Ring, FireOS, Kuiper, Alexa, eero, and more). The internal penetration testing team is responsible for reviewing these products, with focus on penetration testing, fuzzing, and vulnerability research.

While the majority of our Security team are based in the US, by applying to this position your application will be considered for all locations we hire for in the world, however candidates should expect to accommodate US time for necessary meetings.

About the team
What We Do
Kuiper Trust Services owns the creation and operation of services to protect customer data and Kuiper devices. Candidates for this role should have an interest in any of the following: AWS Services, PKI (public key infrastructure), HSMs (Hardware Security Modules), Firmware Signing, Secure Boot, Encryption, Cryptography, Key Management, and Secure Device Provisioning.

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

BASIC QUALIFICATIONS

- 3+ years experience in a technical security leadership (people manager) role
- 5+ years of experience in Information Security related domains, with knowledge of security fundamentals, application vulnerabilities, application attack vectors, penetration testing methodologies, and tools
- 3+ years of experience driving Information Security initiatives across large diverse organizations
- Experience communicating with a wide range of technical & non-technical partners and senior leadership
- BA/BS in Computer Science or 4+ years of related experience

PREFERRED QUALIFICATIONS

- Ability to exercise sound judgement, problem solve, and make decisions in the face of ambiguity and imperfect knowledge
- Ability to write effective communications with sharp analytical abilities and attention to detail
- Ability to handle multiple competing priorities and deliver results in a fast-paced, deadline-driven environment
- Experience gathering and reporting metrics to measure service and program effectiveness and consistency
- Understanding of and experience in pentesting the embedded devices ecosystem including operating systems, Firmware, Bootloaders, Bluetooth, WiFi, Web service APIs, etc.
- Experience with cloud service providers and their offerings, preferably AWS, and its various technologies and services
- Experience designing and reviewing secure system architectures through the use of Threat Modeling incorporating sophisticated and modern attacks

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $157,600/year in our lowest geographic market up to $272,400/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.