Company
Amazon Data Services Spain, S.L. - C94
Amazon Data Services Spain, S.L. - C94
We are looking for a Penetration Testing Engineer who has a strong passion for security-at-scale. You will be on a team responsible for the delivery of continuous assessments. You will be asked to solve complex technology problems, build tools to automate your way out of manual efforts, and influence the way Amazon services respond to and mitigate threats.Amazon is on the cutting edge of many security issues for a wide variety of platforms and technologies including cloud services, Internet of things (IoT), identity and access management, mobile devices, virtualization and custom hardware, all operating at massive scale.We are looking for a Security Engineer to help ensure our services, applications, and websites are designed and implemented to the highest security standards. You will be responsible for web application, network, and operations penetration testing. You will be responsible for automating repetitive tasks. You will be responsible for influencing Amazon services through the creation of threat mitigation plans. You will work directly with internal teams to solve challenging software problems.You must produce results in the face of ambiguity and imperfect knowledge, and foster constructive dialogue and drive resolution when faced with disagreement. You are considered a technical leader on your team. You work efficiently and routinely deliver the right things with limited guidance. Your work focuses on ambiguous problem areas in existing or new hardware and software initiatives. You take a long term view of your team's processes & software, understanding how it fits into the business. You proactively fix architectural deficiencies and/or propose larger project scopes, which may require the work of a team. You split that work into parallel tasks that can be performed by you and others and then reassembled successfully.Amazon's Leadership Principles of "Dive Deep", "Earn Trust", "Deliver Results", and "Invent and Simplify" will be called upon daily. A successful candidate will need a combination of troubleshooting, technical, and communication skills, as well as the ability to handle a mix of complex decisions.Key job responsibilities- Perform penetration testing complex proprietary software and hardware for AWS services- Manually audit the source code of web services and software authored in house by Amazon- Write proof of concept code to demonstrate the severity of a potential security issue- Provide clear communication on issues to developers that suggest and help to test the fix- Partner with AWS developers to drive improvement in application security as a result of security About the teamDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.Mentorship & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, mentorship and other career-advancing resources here to help you develop into a better-rounded professional. We are open to hiring candidates to work out of one of the following locations:Madrid, M, ESPBASIC QUALIFICATIONS- Bachelor's degree in computer science or equivalent- A Bachelor’s degree in Computer Science, Cybersecurity, similar degree, or equivalent professional experience can be used in lieu of a degree.- Minimum of 1 years of experience in security testing (Penetration testing, Vulnerability testing, Red teaming, bug hunting or CTF experience)- Minimum of 1 years of experience with manually auditing source code (One or more of: Java, Ruby, Python, JavaScript, Rust, C, others) to find security issues.- Minimum of 1 years of experience scripting in Python or other equivalent interpreted languages.- Minimum of 1 years of professional experience with security engineering practices such as in web application security, network security, authentication and authorization protocols, cryptography, automation and other software security disciplines.PREFERRED QUALIFICATIONS- Experience with AWS technologies and services (e.g. S3, Lambda, EC2, KMS, IAM, etc.)- Experience with bug hunting, bug bounties, capture the flag, software development- Experience with multiple programming languages
Madrid
Our jobs portal is fully automated and finds daily new job opportunities related to the companies listed on EVE Score.
Please remember that we do not endorse any websites related to these jobs opportunities and stay alerts to avoid scams.
A few reminders:
- Never, ever pay anything to apply for a job. Companies should be the one paying, not you
- Never agree to buy equipment in order to start a job - this includes buying a laptop, work from home equipment
- Never agree to pay for mandatory training to onboard for a new position (even if they say that they will reimburse you for later)
- If the recruiter sends you an email from a domain that is different from the company website, ask them to communicate with you via email belonging to the company. Stay away from Gmail, Hotmail, Yahoo or domain that looks close to the company they are portraying
- Don’t give personal information during the application process - social security number, bank account, home address, date of birth - this could be used to target you through a social engineering attack later on
- Don’t complete a project for free. Many companies might ask you to get through a test, that’s one thing. But less scrupulous companies will actually ask you to deliver a project for free