Overview
In this role you secure Amazon’s public-facing devices and services by coordinating with external researchers and internal teams to remediate vulnerabilities. You’ll shape and scale Amazon’s Bug Bounty and Threat Intelligence programs, acting across business verticals to raise the security bar while maintaining customer trust. You’ll triage disclosed risks, drive improvements to development life cycles, and lead cross-functional collaboration with a focus on tangible security outcomes.
Responsibilities
- Triage externally disclosed hardware and service security issues, propose fixes, and work with builder teams for remediation
- Identify risk trends in Amazon devices and services and coordinate remediation with builder teams
- Automate manual security processes to improve efficiency
- Lead improvements to security programs and processes across the organization
- Produce clear, high-quality documentation for technical and non-technical audiences
- Manage relationships with customers and security researchers
Key requirements
- Experience in security domains such as application security, incident response, secure infrastructure, penetration testing, cloud security, threat modeling, cryptography, or secure software development
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and exploit development
- Proficiency in scripting, programming, or code review in Python, Java, or C++
- Experience with AWS products and services
- Experience with device technologies development, firmware flashing, device debugging, and reading hardware logs; scripting in Bash, Python, Perl, or Ruby
- Resilience and composure in ambiguous situations
- Customer obsession and strong stakeholder management
- Strong written and verbal communication for diverse audiences
- Threat modeling
- Penetration testing
- Secure software development
…
