We are looking for a Senior Security Engineer to help ensure that our hardware platforms, software deliverables, and devices are secured against the latest threats.
You will be responsible for the security assurance of our products. Influencing and scrutinizing design and implementation. Develop elaborate threat models, suggest and review solutions and mitigations. You will lead vulnerability research, penetration testing, automated penetration testing solutions and methodologies such as fuzzing, static analysis and other security checkers. You will mentor service teams in adding security testing tools and practices to their development processes.
Key job responsibilities:
A Security Engineer is expected to be proficient in multiple domains. This is a leadership role within the Annapurna security team and you will be sought out for advice on technical and business issues. Efficient time management skills are required along with the ability to deliver results in the face of uncertainty. A Senior Security Engineer will proactively share knowledge across the Amazon community and will be a key company resource in one or more of the core areas of security. He will lead security reviews of large Amazon projects while setting standards and defining best practices for our Security teams.
Engineers in this role must show exemplary judgment in making technical trade-offs between short versus long term security and business goals. They must also demonstrate resilience and navigate difficult situations with composure and tact. A broad understanding of the business and its interconnections is required. This position will also provide training, advice, and mentorship to other engineers throughout us.
Requirements: Basic Qualifications:
- 5+ years of low-level systems security research and vulnerability testing experience.
- Experience developing security tools (fuzzers, scanners, analysis frameworks).
- Security architecture design and threat modeling experience.
- Proficiency in C and experience with Python.
- Deep knowledge of security aspects of ARM/x86 processor architectures.
- Strong understanding of hardware security (secure boot, cryptographic implementations, side-channel attacks).
- Knowledge of security protocols and cryptographic primitives
- Technical English proficiency.
Preferred Qualifications:
- Background in firmware reverse engineering and vulnerability research.
- Experience with fuzzing frameworks (AFL++, libFuzzer, Syzkaller).
- Knowledge of virtualization security or hypervisor technologies.
- Familiarity with AWS services.
- Technical leadership, mentoring, and cross-functional collaboration.
- Security publications (research, CVEs).
- CTF, bug bounty, or competitive security research background.
This position is open to all candidates.