10 hours ago
Remote, United States or New York, NY, USAMid Level
H1B sponsor
Base Salary
$159k - $202k/yr
Responsibilities
- Conduct high-quality penetration tests independently or as part of a team.
- Create engagement plans and document vulnerabilities, gaps, evidence, severity, and remediation recommendations.
- Manually identify, exploit, and document application vulnerabilities involving authentication, authorization, business logic, and input validation.
- Test web applications, APIs, cloud services, service-oriented or RPC-based backend services, and web front ends.
- Contribute to security testing tooling, automation, innovation, and process improvements.
- Communicate findings and remediation guidance to software development teams, service owners, Information Security, senior leadership, and partner teams.
- Help translate regulatory and compliance requirements into penetration-testing scope and evidence.
Requirements
- Bachelor’s degree in a STEM field or experience in IT Security.
- At least 3 years of hands-on application penetration testing or offensive security assessment experience, excluding internships.
- At least 2 years of programming or scripting experience in Python, Go, Java, C++, or a similar language, excluding internships.
- Knowledge of networking protocols such as HTTP, DNS, and TCP/IP.
- Experience writing penetration-test reports and communicating findings, severity, and remediation guidance directly to software development teams.
- Preferred: experience with security design reviews, threat modeling, secure code review, and other software development lifecycle security activities.
- Preferred: experience with AWS products and services and service-oriented or RPC-based backend testing.
- Preferred: experience building security automation for testing, triage, reporting, or evidence collection.
- Preferred: experience using AI or LLM-assisted tooling for security testing.
- Preferred: knowledge of PCI DSS, SOX, MAS TRM, RBI, or GDPR and recognized standards such as OWASP ASVS, OWASP Top 10, or PTES.
- Preferred: offensive security certification such as OSCP, OSWE, GPEN, or PenTest+.
Benefits
- Comprehensive benefits including medical, dental, vision, prescription, life and AD&D insurance, supplemental life-plan options, an employee assistance program, mental health support, a medical advice line, flexible spending accounts, and adoption and surrogacy reimbursement.
- 401(k) matching, paid time off, and parental leave.
- Flexible work hours and arrangements.
- Training, knowledge-sharing, and career-development resources.
- The position is listed as a virtual location in New York.
About Amazon
Amazon builds and operates a global e-commerce marketplace, logistics network, and consumer devices, and provides cloud computing via AWS for businesses and developers. The company earns revenue from online retail, third‑party seller services, subscriptions like Prime, advertising, and AWS usage. Founded in 1994 and headquartered in Seattle, it is publicly traded on NASDAQ (AMZN) and serves customers in dozens of countries.
