security engineer for external vulnerability operations
ориентир по рынку
вакансия
зп не указана
в среднем
188 293 ₽
мэтч
Загрузи резюме, чтобы видеть мэтчи с вакансией
подготовься к отклику
ai-инструменты
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме
описание
Job ID: A10494640
Amazon works with external security researchers and internal teams to secure its public-facing devices and services. Its security programs focus on vulnerability remediation, improving the security of device and software development, and protecting customers.
задачи
Triage externally disclosed hardware and service security issues, suggest fixes, and collaborate with builder teams on remediation
Identify risk trends in Amazon devices and services and collaborate with builder teams on remediation
Automate manual processes to streamline security work
Lead improvements to Amazon programs and processes
Write and deliver high-quality documents for technical and non-technical audiences
Manage relationships with customers and security researchers
Use knowledge of Amazon to drive improvements to customer relationships, services, processes, and technologies
Triage disclosed risks and collaborate with customers and security researchers to maintain and raise Amazon’s security standards
Help ensure lessons learned through disclosure and mitigation improve the security of Amazon’s device and software development life cycle
требования
Experience in one or more of application security frameworks, security code reviews, incident response, secure infrastructure, penetration testing, mobile security, cloud security, AI security, identity and access controls, threat modeling, cryptography, threat intelligence, or secure software development
Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and exploit development or equivalent
Experience in scripting, programming, or security code reviewing in a common language such as Python, Java, or C++
Experience with AWS products and services
Experience working with device technologies under development, familiarity with flashing firmware, basic device debugging and reading or pulling device logs, or scripting in one or more languages such as Bash, Python, Perl, or Ruby
Deep understanding of hardware security, firmware analysis, operating system internals, and low-level programming
Будет плюсом: A bachelor’s degree in a STEM field, 5+ years of experience in threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, or network security, experience supporting Red Team, Penetration Testing, or Bug Bounty programs
условия
The role is remote anywhere within the UK; London is preferred, but other UK locations are also considered