Talent.com
Amazon
Security Engineer, Security Verification & Validation TeamAmazon • milan, Lombardy, Italy
Security Engineer, Security Verification & Validation Team

Security Engineer, Security Verification & Validation Team

Amazon • milan, Lombardy, Italy
9 giorni fa
Descrizione dell’offerta di lavoro

We are looking for a Security Engineer to join Point-in-Time Security Testing AWSs expert security assurance function for the launches and architectures where security automation alone is not enough. You will own complex security testing engagements end-to-end and you will leave behind mechanisms that make each engagement worth more than itself.

Amazon Web Services (AWS) is the leading cloud service provider providing virtualized infrastructure storage networking messaging and many other services to customers all over the world including government customers. AWS runs a globally distributed environment operating at massive scale and businesses from start-ups to large enterprises and governments run their most sensitive workloads on it. Point-in-Time Security Testing takes on the engagements where the architecture threat model or potential impact is complex enough that expert reasoning matters most. We start from the architecture and the risks rather than a generic checklist think like an adversary and demonstrate realistic impact. We build harnesses that steer agentic AI so experts have more time for the difficult problems and we turn what we learn into shared methods mechanisms and detections for the rest of the team. As AWS ships agentic systems of its own those same systems become targets we test.

Our work is measured by how much difficult security uncertainty we resolve with the human time available to us not by how many issues we this role you will investigate high-consequence risks which are specific testable claims about how an adversary could cause harm and take each one to a documented conclusion. You will either demonstrate the issue rule out the attack path with enough evidence or expose a weakness in a shared mechanism or detection.

You must produce results in the face of ambiguity and imperfect knowledge foster constructive dialogue and drive resolution when faced with disagreement. You deliver autonomously on work scoped within the team and you ask for guidance when a problem crosses into unfamiliar territory. You are trusted to run a difficult engagement without close supervision and to say clearly when the plan needs to change.

Amazons Leadership Principles of Dive Deep Earn Trust Deliver Results and Invent and Simplify will be called upon daily. Above all we earn trust by choosing carefully where humans spend time testing those areas deeply and being honest about what we know and what we do not.

Key job responsibilities
- Lead complex security testing engagements end to end including multi-engineer tests across interconnected microservice architectures repeat testing across successive iterations of one launch and campaigns that investigate a systemic issue across several services
- Perform penetration testing and AI-augmented source code review of complex proprietary AWS software directing the tooling at trust boundaries abuse cases and attack paths it would not reach on its own and confirming what it reports
- Take each agreed risk hypothesis to a documented conclusion whether that means demonstrating the issue with proof-of-concept code ruling out the attack path with sufficient evidence or identifying a weakness in a shared mechanism or detection
- Challenge what a scope document assumes and identify what it misses then keep the engagement moving when conditions change by building alternative test paths re-scoping and parallelizing work with dependent teams
- Trace attack paths across chained components and demonstrate compound risk that stays invisible when components are tested in isolation
- Assess and defend the business impact of complex and ambiguous risk not only well-understood vulnerability classes so service teams can act on the right things first
- Produce clear engagement results that record what you tested why you chose those tests what you found or ruled out the limitations of the work and the risk that remains
- Lead communication with developers AppSec engineers and Blue teams when the scope is ambiguous or a fix is not straightforward validate the fixes confirm remediation through Verification of Fixes and work as an embedded security tester inside the development lifecycle when a launch calls for it
- Build automation and tune the harnesses that raise the precision of the teams AI pentest bots measuring where they produce false positives or miss attack patterns so expert time goes where it changes the outcome
- Test agentic AI systems as an adversary would reasoning about how agent-to-agent (A2A) communication tool use memory and orchestration can be manipulated or made to cross a trust boundary
- Leave reusable mechanisms behind such as fuzzers integration security tests detection rules tooling or documented methodology and track whether they are adopted
- Peer review test plans scopes runbooks and reports from other peers questioning coverage gaps and adding the test cases that are missing
- Onboard and mentor engineers on your engagements helping them grow technically while the engagement stays on track

About the team
Why AWS Security
At Amazon security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazons products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience across cloud devices retail entertainment healthcare operations and physical stores.

Point-in-Time Security Testing sits within Proactive Security. While the wider organisation builds the ability to find risk through signals automation AI Bug Bounty and continuous testing our role is different. We take on the situations where expert reasoning matters most and we make that expertise go further every year. Our vision is that every critical AWS launch receives the right depth of expert security testing and every hour our team spends makes future testing more effective.

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed we encourage you to apply. If your career is just starting hasnt followed a traditional path or includes alternative experiences dont let it stop you from applying.

Inclusive Team Culture
In Amazon Security its in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to keep learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas perspectives and voices.

Training & Career Growth
Were continuously raising our performance bar as we strive to become Earths Best Employer. Youll find endless knowledge-sharing mentorship training and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home which is why we strive for flexibility as part of our working culture.

- Perform offensive testing of web applications and services and source code review to identify non-trivial issues
- Script your way out of problems and deploy code in an enterprise environment
- Suggest secure design architecture including related to cryptography and infrastructure
- Demonstrate a propensity to learn new ideas and concepts extremely quickly
- Be data-driven and support your conclusions with evidence
- Experience with AWS technologies and services (e.g. S3 Lambda EC2 KMS IAM)
- A Bachelors degree in Computer Science Cybersecurity or a related field from an accredited university. Equivalent professional experience can be used in lieu of a degree
- Minimum of 3 years of experience in professional penetration testing source code auditing bug hunting or CTF experience
- Demonstrable depth in at least two complex security domains such as networking workload and tenant isolation web application and API security or identity and access management (IAM)
- Working competence across the wider set of areas being security architecture and engineering communication and network security IAM security assessment and testing cryptography and software development security
- Experience finding security issues in multiple languages including one or more of Java Ruby Python JavaScript Rust and C
- Minimum of 2 years code development using Python or equivalent language
- Demonstrable experience using boto3
- Minimum of 2 years of professional experience with security engineering practices such as web application security network security AuthN/AuthZ protocols cryptography and automation

- Experience acting as the testing point of contact for a service or technology area across more than one engagement
- Experience running an initiative such as a CTF or an apprenticeship
- Experience performing or supporting Red Team engagements with an understanding of holistic assessment
- Experience with full-stack (Linux / Unix) software architectures from UI to infrastructure
- Experience with serverless architectures and common virtualization techniques (hypervisors / containers / jails) and escapes and exploits within those environments
- Experience with micro-service API-based or service-oriented software architectures
- Operations experience with CI/CD or managing distributed systems
- Web service assessment experience with authentication controls session management access controls logic flaws injection vulnerabilities request smuggling cloud privilege escalation and tenant isolation

Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover invent simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( to know more about how we collect use and transfer the personal data of our candidates.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process including support for the interview or onboarding process please visit
for more information. If the country/region youre applying in isnt listed please contact your Recruiting Partner.

The minimum gross base salary for this position is listed below. The base salary listed corresponds to working on a full-time basis. For part-time hours the salary will be pro-rated.

Amazon reserves the right to offer a higher salary and/or level depending on the candidates skills competencies and experience. Amazons package may include a sign on addition the candidate may be eligible to participate in a restricted stock unit scheme operated independently by USA. Your recruiting team will share final salary and any restricted stock unit scheme if applicable depending on skills and requirements.

In addition to statutory benefits and those applicable to the relevant CBA company supplementary benefits may apply subject to further terms.

See below the minimum gross base salary for this position:



Milan ITA - 62800.00 EUR Annually


Required Experience:

IC


Employment Type : Full-Time
Experience: years
Vacancy: 1
Yearly Salary Salary: 62800 - 62800

Creare un avviso di lavoro per questa ricerca

Security Engineer, Security Verification & Validation Team • milan, Lombardy, Italy

Offerte simili

SASE Security Engineer – Netskope Expert

DGS S.P.A.sesto san giovanni, lombardia, Italy

Un'azienda di cyber security leader in Lombardia cerca un Cyber Security Engineer con esperienza in Netskope per la gestione operativa di architetture di sicurezza cloud.La posizione include suppor... Mostra di più

 • In evidenza

AI Security Operations & Response (Flexible 4x9)

Intesa Sanpaolo GroupMilano, lombardia, Italy

Global Security Operations Center.Il candidato monitorerà eventi di sicurezza relativi a sistemi, applicazioni e workflow che usano frontier LLM, agenti IA e RAG, contribuendo a detection e respons... Mostra di più

 • In evidenza

Senior Microsoft Security Architect – Azure & Entra

SynSphereMilano, lombardia, Italy

SynSphere, azienda leader in sicurezza informatica, cerca un Microsoft Security Specialist per progettare e gestire soluzioni di sicurezza nell'ecosistema Microsoft.Si offre assunzione diretta a te... Mostra di più

 • In evidenza

Cyber Security Expert – Identity & Access Management

UniCreditmilano, lombardia, Italy

We are looking for a highly motivated Cyber Security Expert specialized in Identity Access Management (IAM) to strengthen our Group Security function.In this role, you will contribute to key secur... Mostra di più

 • In evidenza

IAM CyberArk Security Senior Engineer

DGSSesto San Giovanni, lombardia, Italy

In DGS il talento diventa impatto perché entra in progetti reali, dove competenze tecnologiche, visione di business e collaborazione si incontrano per accompagnare aziende e organizzazioni nei loro... Mostra di più

 • In evidenza

Cyber Security Engineer

NETGROUPmilano, lombardia, Italy

Chi siamo /strong /ppstrongNetgroup S.Cybersecurity /strong che opera dal 1994 a supporto delle più rilevanti realtà nazionali ed internazionali contribuendo alla loro evoluzione tecnologica e comp... Mostra di più

 • In evidenza

CYBER SECURITY ENGINEER (L2/L3)

Lansol GmbhMilano, lombardia, Italy

CYBER SECURITY ENGINEER (L2/L3).In WIIT, società italiana di respiro internazionale quotata al segmento Star, abbiamo scelto di fare la differenza per i nostri clienti.Siamo leader nell’erogazione ... Mostra di più

 • In evidenza

Cyber Security & Resilience Engineer

Riggs D.Cmilano, lombardia, Italy

Snam cerca uno Cyber Security Resilience Specialist per rafforzare le capacità di detection, analysis e risposta agli incidenti in ambienti IT, OT e cloud.Inizia collaborando con il SOC, definendo... Mostra di più

 • In evidenza

Senior Network Security Engineer

Var GroupMilano, lombardia, Italy

Proteggi infrastrutture critiche e garantisci la sicurezza di ambienti complessi!.Hai esperienza nella gestione di infrastrutture di rete e sicurezza in contesti enterprise e vuoi lavorare su proge... Mostra di più

 • In evidenza

Senior Security Architect

Cassa Centrale GroupMilano, lombardia, Italy

Al fine di rafforzare il servizio Security & Resilience di Capogruppo, Cassa Centrale Banca sta ricercando un profilo.Ufficio Enterprise Security Architecture & Security by Design.La missione dell’... Mostra di più

 • In evidenza

Pre-Sales Engineer — Security Systems & Solutions

Ajax SystemsMilano, lombardia, Italy

Ajax Systems is a leading security technology company providing end-to-end solutions for homes and businesses worldwide.The role involves conducting technical seminars, presenting product roadmaps,... Mostra di più

 • In evidenza

Security engineer

Bending SpoonsMilano, lombardia, Italy

At Bending Spoons, we're striving to build one of the all-time great companies.A company that serves a huge number of customers.A company where team members grow to their full potential.A company t... Mostra di più

 • In evidenza

Security Engineer

Energent S.p.A.Milano, lombardia, Italy

Il Gruppo EIES, composto da Energent, I&M, Enway e Skienda è una realtà di consulenza e di prodotto consolidata nel mercato delle soluzioni e dei servizi ICT.Ricerchiamo un Security Engineer con es... Mostra di più

 • In evidenza

Detection Researcher/Security Engineer (iOS Focused)

ZimperiumMilano, lombardia, Italy

Zimperium® is the world leader in mobile security, purpose-built to protect the modern mobile enterprise.Trusted by leading organizations and governments, our AI-driven platform delivers real-time,... Mostra di più

 • In evidenza

SASE Cyber Security Engineer

DGS S.P.A.sesto san giovanni, lombardia, Italy

DGS /b fornisce servizi e soluzioni di valore in ambito bCyber Security, Digital Solutions e Management Consulting /b.Lo scopo che guida le nostre azioni è il pieno soddisfacimento delle esigenze d... Mostra di più

 • In evidenza

Remote Offensive Security Penetration Tester Lead

Accenture Italiamilano, lombardia, Italy

A leading consulting firm in Milan is looking for a Penetration Tester Expert to engage in offensive security practices.The role involves conducting penetration tests on a variety of platforms and ... Mostra di più

 • In evidenza

Network Security Engineer

AGM SOLUTIONSmilano, lombardia, Italy

Overview /h3pAGM Solutions si occupa di studiare ed implementare soluzioni tecnologiche ed innovative offrendo servizi per ICT Governance, ICT Security GDPR Compliance.Siamo un’azienda certificata... Mostra di più

 • In evidenza

Global Security Operations Center (SOC) Lead – Vendor Governance

MatchtechMilano, lombardia, Italy

Hybrid – Bollate (Milano), 2 days a week in the office.This is a permanent role with strong local responsibility and high visibility within a global organization.You will play a key role ensuring t... Mostra di più

 • In evidenza

OT Security Architect: Hybrid, ICS Network Protection

Michael Page International Italia S.r.l.Milano, lombardia, Italy

Michael Page International Italia S.OT Security Consultant per la progettazione di architetture sicure e protezione delle reti critiche in contesti produttivi internazionali.Il candidato ideale avr... Mostra di più

 • In evidenza

AI Security Architect Senior

Intesa Sanpaolo GroupMilano, lombardia, Italy

Seleziona la frequenza (in giorni) di ricezione di un avviso: Crea avviso.Entrerai in un team altamente specializzato che si occupa della definizione e del disegno dei presidi e dei processi di sic... Mostra di più