Mobile Security Engineer, Application Security
About the role
Amazon’s Stores Application Security Team is seeking a Mobile Security Engineer to help keep Amazon secure for its customers. In this role, you will attack Amazon’s services and mobile applications to discover security issues and report them to our internal technology teams. This position offers challenging opportunities, both technologically and as a leader, while working alongside a team of highly skilled individuals.
In Amazon Stores, we ship some of the widest arrays of technology found at any company—from amazon.com to world-class machine learning pipelines, innovative digital healthcare, and no-checkout retail. A Security Engineer at Amazon is expected to be strong in multiple domains and will work closely with teams throughout Information Security, as well as provide technical leadership and advice to teams and leaders across Amazon. You will gain firsthand knowledge of how Amazon is built and operates at a deep, technical level, leveraging this knowledge to find new ways to break services, processes, and technologies.
Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. You will demonstrate resilience and navigate ambiguous situations with composure and tact while providing thought leadership for the organization.
Responsibilities
- Conducting high-quality application penetration tests independently or as part of a team
- Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
- Contributing to team tooling, innovation, and improvements
- Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings
Requirements
- Bachelor's degree in computer science or equivalent
- 3+ years of experience in a penetration testing or similar offensive security role
- 3+ years of experience in client-side application security, including reverse engineering and security assessments
- 3+ years of professional experience with security engineering practices, including web application security, authentication and authorization protocols, cryptography, automation, and other software security disciplines
- 3+ years of experience with dynamic and manual code auditing to identify security issues
- 3+ years of experience with interpreted or compiled languages (e.g., Python, Ruby, C/C++, Java, .NET)
- Experience with threat modeling, design review, or other threat analysis techniques
- Proficiency with binary analysis tools (e.g., Ghidra, IDA Pro, Radare2, Hopper, Jadx)
- Experience with client-side application instrumentation and dynamic testing (e.g., Frida, Objection, LLDB, Burp Suite)
Preferred Qualifications
- Knowledge of cloud services such as AWS or equivalent
- Experience with design, implementation, support, and evaluation of security-focused tools and services
- Experience with mobile application penetration testing
- Familiarity with threat models for client-side applications on consumer devices and the vulnerability classes specific to their platforms and communication protocols
- Experience mentoring developers on secure coding practices and vulnerability mitigations
- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
About the team
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed, we encourage candidates to apply. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer opportunities to build experience in a wide variety of areas, including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.
In Amazon Security, ongoing DEI events and learning experiences inspire us to embrace our uniqueness. We seek out and celebrate a diversity of ideas, perspectives, and voices to address the toughest security challenges.
Benefits
- Comprehensive health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance, and optional supplemental life plans)
- Employee Assistance Program (EAP), Mental Health Support, and Medical Advice Line
- Flexible Spending Accounts
- Adoption and Surrogacy Reimbursement coverage
- 401(k) matching
- Paid time off and parental leave
- Sign-on payments and restricted stock units (RSUs)
Pay
Base salary range: $159,300.00 – $202,400.00 USD annually. Final compensation will be determined based on experience, qualifications, and location.