• Join Amazon’s External Vulnerability Operations team in London, securing Amazon’s public-facing devices and services.
• Work with external security researchers and internal teams to ensure vulnerabilities are remediated with urgency.
• Turn lessons from disclosure and mitigation into improvements across Amazon’s device and software development life cycle.
• Help grow Amazon’s Bug Bounty and Threat Intelligence programmes into the best in the world.
• Work directly with teams across many business verticals, gaining deep technical insight into how Amazon is built and operates.
• Triage disclosed risks and collaborate with customers and researchers to maintain and raise Amazon’s security bar.
• Join a team of highly skilled security engineers focused on maintaining customer trust and security.
📋 Job Requirements
• Bring experience across areas such as application security, security code reviews, incident response, penetration testing, cloud security, AI security, threat modelling, or cryptography.
• Understand system security vulnerabilities and remediation techniques, including penetration testing and exploit development or equivalent.
• Script, program, or review code for security in a common language such as Python, Java, or C++.
• Bring experience with AWS products and services.
• Work with devices under development, including flashing firmware, basic device debugging, and reading or pulling device logs.
• Bring a deep understanding of hardware security, firmware analysis, operating system internals, and low-level programming.
• Show resilience and navigate ambiguous situations with composure and tact.
• Apply a strong sense of customer obsession to keeping Amazon and its customers secure.
🌟 Nice-to-have
• Hold a bachelor’s degree in a STEM field.
• Bring 5+ years of experience across threat modelling, secure coding, identity and authentication, software development, cryptography, system administration, or network security.
• Bring experience supporting Red Team, penetration testing, or Bug Bounty programmes.
• Request workplace accommodations or adjustments during the application and interview process if you need them.
🎯 Responsibilities
• Triage externally disclosed hardware and service security issues, suggest fixes, and work with builder teams on remediation.
• Identify risk trends across Amazon devices and services and drive remediation with builder teams.
• Automate manual processes to streamline security work.
• Lead improvements to Amazon’s security programmes and processes.
• Write and deliver high-quality documents for technical and non-technical audiences.
• Manage relationships with customers and external security researchers.
About Amazon
😃 What Amazon offers
• Gain firsthand, deep technical knowledge of how Amazon is built across multiple business verticals.
• Take on challenging leadership and technical opportunities.
• Help shape Amazon’s Bug Bounty and Threat Intelligence programmes.
• Work alongside a team of highly skilled security engineers.
• Join an inclusive culture that values diverse backgrounds and experiences.
💖 What makes Amazon unique
Amazon is one of the world’s largest technology and e-commerce companies, known for its customer obsession and its passion to invent, simplify, and build. Its security teams protect the devices and services used by hundreds of millions of customers, working closely with builder teams and external researchers to keep Amazon and its customers safe.
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.