Amazon Web Services (AWS) is a global team tasked with keeping the cloud safe, and they are seeking a Security Engineer for their Bug Bounty team. The role involves triaging security reports, developing automation, and managing relationships with external researchers to enhance AWS's security posture.
Responsibilities:
- Researching, reproducing, and responding to security issues reported through the bug bounty program
- Technical Escalation
- Managing relationships with external security researchers working with AWS's bug bounty program
- Perform deep analysis of new vulnerability classes
- Driving improvements to team tooling, automation, and processes
- Influencing program direction
- Identify and drive resolution of vulnerability trends
- Attend industry conferences and assist in hosting on site hack-a-thons and other researcher engagement activities
Requirements:
- Knowledge of industry-based security vulnerabilities and remediation techniques
- 2+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
- Bachelor's degree in computer science or equivalent
- Experience with AWS products and services
- 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience