Senior Security Engineer, Devices, Devices and Services Security
DESCRIPTION
Have you wanted an opportunity to find security issues in the embedded systems/devices and low level software that enables day to day corporate functions? Are you able to break into embedded systems/devices by exploiting vulnerabilities in wireless, Bluetooth, using fault injections or other attacks? This position will provide you with a unique opportunity to find security issues into every day devices
The Security team is responsible for identifying security flaws into corporate technology solutions such as conference room equipment as well as Amazon solutions including Alexa, Ring, Blink. This team partners with business teams and perform device level security testing, secure architecture design reviews and security review for bootloader code and firmware.
In this role, you will:
*Ensure hardware based corporate solutions deployed across Amazon are secure
*Identify security flaws in various Amazon device products
*Guide Amazon businesses toward secure development of devices. This will range from design and code review, threat modeling to security testing
*Propose, research and develop tools and techniques to improve the security posture of devices at scale
*Provide technical security expertise and consultation to device product teams
*Identify security risks and work with product engineers to create mitigations
*Participate in projects that develop new intellectual property
BASIC QUALIFICATIONS
- Bachelor’s degree in computer science, computer engineering, cyber security, electrical engineering, systems engineering, or equivalent
- 6+ years of experience in converting vulnerabilities into real device level security attack
- Strong expertise in identifying issues by reviewing PCB/motherboard designs including schematic capture, stack up and circuit board layout
- Knowledge of common interfaces and communication protocols (e.g., JTAG, PCIe, UART, USB, I2C, Bluetooth, WiFi)
- Knowledge of hardware security mechanisms, including secure boot, trusted execution environments
PREFERRED QUALIFICATIONS
- Master’s degree in computer science, computer engineering, cyber security, electrical engineering, systems engineering, or equivalent
- Excellent written and verbal communication skills with the ability to present complex technical information in a clear and concise manner to a variety of audiences
- Experience with hardware security, system and network security, authentication and security protocols, cryptography, and application security
- Familiarity with penetration testing and the development of exploits
- Experience in developing security tooling and automation applying technologies such as symbolic execution, code analysis, and fuzzing
- Hands-on hardware reverse engineering experience using tools such as microscopes, x-ray machines, oscilloscopes, multimeters, data acquisition systems, and signal generators
Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.
Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $143,300/year in our lowest geographic market up to $247,600/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.