Skip to main content

Senior Hardware Security Engineer, AWS Hardware Supply Chain Security

Job ID: 2772676 | Amazon Development Center U.S., Inc.

DESCRIPTION

Help us protect not only the Amazon Web Services (AWS) cloud computing environment but all of our customers as well! Since 2006, our great team at AWS has been enabling our customers to bring great ideas to life in ways that aren’t possible in traditional IT environments. With AWS you can flexibly harness compute, storage, security, and other services from across the globe as your business demands them.

The AWS Hardware Supply Chain Security (HSCS) organization is looking for a Sr. Hardware Security Engineer who has a passion for security and the curiosity to analyze and report conclusions on the integrity of AWS hardware at any stage in its life cycle. You will work with a team of professionals around the world to help assess and mitigate risks in partner manufacturing and logistics, contribute to new mechanisms for defense and response, and analyze the ever-shifting threat landscape to help us prioritize continuous improvement. You will have the opportunity to work in a supportive, collaboration-filled environment to build and secure the future of the cloud.

The HSCS organization exists to set the bar for AWS hardware life cycle security from design through end of life and drives durable mechanisms to meet requirements. If you have experience in areas such as modern semiconductor manufacturing and test, hardware/firmware analysis, or supply chain security your expertise is needed more than ever and we are interested in talking to you!

In order to inform your recommendations and steer AWS in the right direction, you will be called upon to provide risk assessment and investigative analysis on hardware at any life cycle within AWS and to provide perspective on security controls for hardware. This could include hands on experience to understand and diagnose electronics PCB assembly, using test equipment (Multimeters, Oscilloscopes, Logic Analyzers, Xray, Shredder, Decap, etc), ability to apply judgement to test results and analysis along with understanding of fundamentals of hardware security. The ideal candidate will have past experience in technical equipment manufacturing operations, and a fundamental understanding of threat modeling and risk assessments.

Key job responsibilities
* Assess and prioritize malicious findings and recommend appropriate mitigations
* Understand threat modeling, risk assessment & prioritization, and manufacturing security validation
* Hands on experience with ARM based hardware, reading electronic schematics, PCBA soldering, fundamentals of hardware/firmware security and embedded systems, able to interpret component data sheets
* Data driven, quantitative mentality, ability to work independently on projects, fundamentals of hardware reverse engineering
* Security training and outreach to internal teams and external supply chain partners
* Work with lab technicians on daily work schedule, lab asset management, manage test procedures
* Travel as needed to provide insight and feedback to suppliers and data centers around the world

A day in the life
In this role you will help assess risks to AWS infrastructure by validating hardware security controls through inspection and testing of various devices across the whole lifecycle beginning with suppliers and ending in decommissioning. You will help define testing plans for projects exercising both simple and advanced testing techniques, oversee their execution, provide revision and follow-on testing, and perform analysis and reporting of the data. You will assist in refining and growing our capabilities to provide pinnacle protection to all of Amazon and its customers while working with fellow security professionals from across Amazon as well as supplier and data center operations teams to partner in keeping the AWS infrastructure secure.

About the team
About Amazon Security

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

BASIC QUALIFICATIONS

- BS in Electrical/Computer Engineering, Computer Science, or equivalent professional experience.
- Minimum 3 years of demonstrated experience in lab environments
- Knowledge of firmware development
- Experience in computer security, including threat modeling, penetration testing, incident response, security architecture, cloud infrastructure or other efforts related to enterprise network defense.

PREFERRED QUALIFICATIONS

- Master’s degree in Electrical/Computer Engineering, Computer Science, or equivalent professional experience
- Practical understanding of AWS cloud services and concepts such as S3, EC2, Lambda, and VPC
- 5 years of demonstrated experience in hardware lab environments
- Experience with hardware reverse engineering including the ability to solder and desolder
- Demonstrated mastery of inventory control principles and test equipment maintenance
- 3 years of experience with advanced analysis equipment (Optical, UV, IR, X-Ray, SAM or similar testing stations, 4-qaxis milling & laser etch machines, etc)

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.