Senior Security Engineer, Devices, Devices and Services Security
Seattle, Washington, USA
Full Time Senior-level / Expert USD 143K - 247K
Amazon.com
Free shipping on millions of items. Get the best of Shopping and Entertainment with Prime. Enjoy low prices and great deals on the largest selection of everyday essentials and other products, including fashion, home, beauty, electronics, Alexa...
Have you wanted an opportunity to find security issues in the embedded systems/devices and low level software that enables day to day corporate functions? Are you able to break into embedded systems/devices by exploiting vulnerabilities in wireless, Bluetooth, using fault injections or other attacks? This position will provide you with a unique opportunity to find security issues into every day devices
The Security team is responsible for identifying security flaws into corporate technology solutions such as conference room equipment as well as Amazon solutions including Alexa, Ring, Blink. This team partners with business teams and perform device level security testing, secure architecture design reviews and security review for bootloader code and firmware.
In this role, you will:
*Ensure hardware based corporate solutions deployed across Amazon are secure
*Identify security flaws in various Amazon device products
*Guide Amazon businesses toward secure development of devices. This will range from design and code review, threat modeling to security testing
*Propose, research and develop tools and techniques to improve the security posture of devices at scale
*Provide technical security expertise and consultation to device product teams
*Identify security risks and work with product engineers to create mitigations
*Participate in projects that develop new intellectual property
EXPORT CONTROL:
Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
- Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Systems Engineering, or other related field or equivalent work experience
- 6+ years of experience in security engineering, systems engineering, or software development
- 3+ years of experience with hardware security, anti-tamper techniques, or embedded systems security utilizing mechanisms such as secure boot, trusted execution environments, and hardware roots of trust
- Experience developing security architectures, creating threat models, performing trade studies, analyzing risk, and designing test strategies
- Knowledge of cryptographic protocols and implementations
- Experience working with ITAR, EAR, or other controlled data
- Experience with device security, IoT security, or consumer electronics security
- Strong programming skills in C/C++, Python, or similar languages
- Familiarity with the development governance and policy or knowledge of common security control frameworks such as NIST 800-53 or ISO 27001
- Experience with reverse engineering, vulnerability analysis, anti-tamper technologies and techniques
- Knowledge of current security threats, trends, and mitigations
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.
The Security team is responsible for identifying security flaws into corporate technology solutions such as conference room equipment as well as Amazon solutions including Alexa, Ring, Blink. This team partners with business teams and perform device level security testing, secure architecture design reviews and security review for bootloader code and firmware.
In this role, you will:
*Ensure hardware based corporate solutions deployed across Amazon are secure
*Identify security flaws in various Amazon device products
*Guide Amazon businesses toward secure development of devices. This will range from design and code review, threat modeling to security testing
*Propose, research and develop tools and techniques to improve the security posture of devices at scale
*Provide technical security expertise and consultation to device product teams
*Identify security risks and work with product engineers to create mitigations
*Participate in projects that develop new intellectual property
EXPORT CONTROL:
Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
Basic Qualifications
- Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Systems Engineering, or other related field or equivalent work experience
- 6+ years of experience in security engineering, systems engineering, or software development
- 3+ years of experience with hardware security, anti-tamper techniques, or embedded systems security utilizing mechanisms such as secure boot, trusted execution environments, and hardware roots of trust
- Experience developing security architectures, creating threat models, performing trade studies, analyzing risk, and designing test strategies
- Knowledge of cryptographic protocols and implementations
Preferred Qualifications
- Master's degree in Computer Science, Computer Engineering, or related field- Experience working with ITAR, EAR, or other controlled data
- Experience with device security, IoT security, or consumer electronics security
- Strong programming skills in C/C++, Python, or similar languages
- Familiarity with the development governance and policy or knowledge of common security control frameworks such as NIST 800-53 or ISO 27001
- Experience with reverse engineering, vulnerability analysis, anti-tamper technologies and techniques
- Knowledge of current security threats, trends, and mitigations
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.
Job stats:
1
0
0
Category:
Security Engineering Jobs
Tags: C Computer Science Governance IoT ISO 27001 NIST NIST 800-53 Python Reverse engineering Vulnerabilities
Perks/benefits: Career development Equity / stock options
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information System Security Officer jobsInformation Security Specialist jobsSenior Security Analyst jobsSenior Cloud Security Engineer jobsSystems Engineer jobsSenior Cybersecurity Engineer jobsSystems Administrator jobsSenior Information Security Analyst jobsInformation Security Manager jobsCyber Security Specialist jobsSenior Network Security Engineer jobsIT Security Analyst jobsChief Information Security Officer jobsIT Security Engineer jobsSecurity Consultant jobsSecurity Specialist jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsSenior Information Security Engineer jobsSenior Cyber Security Engineer jobsSenior Product Security Engineer jobsCyber Threat Intelligence Analyst jobsCyber Security Architect jobsSecurity Operations Analyst jobsCybersecurity Specialist jobs
TS/SCI jobsEDR jobsSaaS jobsBash jobsJava jobsTop Secret jobsThreat detection jobsTerraform jobsSplunk jobsRMF jobsIDS jobsSDLC jobsIPS jobsSOC 2 jobsSQL jobsMalware jobsFinance jobsForensics jobsCompTIA jobsDocker jobsActive Directory jobsGIAC jobsIntrusion detection jobsITIL jobsDoDD 8570 jobs
VPN jobsOWASP jobsHIPAA jobsCRISC jobsIT infrastructure jobsAnsible jobsTCP/IP jobsCCSP jobsData Analytics jobsClearance Required jobsNIST 800-53 jobsOSCP jobsMITRE ATT&CK jobsBanking jobsZero Trust jobsCISO jobsUNIX jobsSOAR jobsDNS jobsIndustrial jobsJira jobsSOX jobsEndpoint security jobsPolygraph jobsJavaScript jobs