Overview
In this Senior Security Engineer role, you lead complex security testing engagements within AWS’s Point-in-Time Security Testing team. You apply expert reasoning to high-consequence risks and drive end-to-end engagements from architecture to proof-of-concept validation. You shape testing strategy across interconnected services and build reusable, automated methods to scale security outcomes. You will mentor others and push for durable improvements that reduce risk across multiple teams.
Pay / Benefits
- work-life balance
- flexible working culture
- career growth and training resources
- diverse experiences and inclusive environment
- DEI programs and learning events
Responsibilities
- Own security for a portfolio of testing engagements across the team and partner-orgs, including leading individual complex engagements
- Set testing strategy across microservice architectures, launch iterations, and cross-service campaigns
- Perform penetration testing and AI-augmented source code review of complex proprietary AWS software
- Conclude each risk hypothesis with documented results—demonstrate, rule out, or identify weaknesses
- Define approaches for engagements with ambiguous security strategy and adapt to changing conditions
- Trace attack paths across chained components and demonstrate cross-boundary risks
- Lead communication with developers and security stakeholders and embed security testing in the development lifecycle
- Build frameworks, runbooks, and rubrics to enable repeatable testing across problem domains
- Create reusable mechanisms (fuzzers, tests, rules) and track adoption to improve security outcomes
- Set the peer-review bar for test plans, scopes, runbooks, and reports
- Lead multi-engineer engagements and mentor engineers across teams
Key requirements
- Experience developing software in one or more languages (e.g., Java, Python)
- Knowledge of security design review, threat modeling, risk analysis, and software testing techniques
- Knowledge of authentication, authorization, SSO, cryptography and related concepts
- Experience in risk assessment and communicating impacts to business and operations teams
- Experience in enterprise software environments
- Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, or related field
- 5+ years in professional penetration testing, source code auditing, or bug hunting
- Proven ability to find non-trivial vulnerabilities through offensive testing and code review
- Mastery of two or more complex security domains (e.g., networking, IAM, cryptography) and ability to automate expertise
- Experience building and guiding AI-assisted security tooling and workflows
- Excellent communication with engineers and management
- Mentoring and leadership across engineering teams
- Ability to operate with ambiguity and drive to resolution
- Penetration testing
- AI-augmented source code review
- Threat modeling
…
