Penetration Testing Engineer, AWS Gen AI Security

Penetration Testing Engineer, AWS Gen AI Security

26 Jun 2024
New York, New york city 00000 New york city USA

Penetration Testing Engineer, AWS Gen AI Security

DescriptionDo you enjoy finding unique security flaws in artificial intelligence and cloud systems? Do you enjoy protecting customers by securing AI and AWS services at scale? Do you enjoy mentoring and leading engineers to solve complex security problems in cutting-edge technologies? On the AWS Generative AI security team, as a Penetration Testing Engineer you will be responsible for the delivery of continuous testing assgenessments. You will be asked to solve complex technology problems, build tools to automate your way out of manual efforts, and influence the way Amazon services, primarily Generative AI services respond to and mitigate threats.Our team is responsible for manually evaluating the security of all Generative AI products, services and software released by AWS. We specialize in uncovering subtle vulnerabilities that automated tools miss, and develop custom tooling to scale our security efforts across Amazon's expanding Generative AI landscape. The AWS surface area is large and diverse, and we use insights from manual testing to continually improve our focused automation to proactively identify and fix potential issues before customers are impacted.We are looking for a Penetration Testing Engineer to help ensure our services, applications, and websites are designed and implemented to the highest security standards. You will be responsible for application and/or hardware penetration testing. You will be responsible for automating repetitive tasks using various scripting languages. You will be responsible for mentoring and leading other engineers to deliver complex penetration tests and vulnerability assessments. You will be expected to drive automation, tooling, efficiency and advance the teams penetration testing capabilities. You will be responsible for influencing Amazon services through the creation of threat mitigation plans. You will work directly with internal teams to solve challenging software and security problems.Key job responsibilities

Perform penetration testing complex proprietary software and hardware for AWS Generative AI services like Bedrock, Amazon Q for Business, and Q Developer.

Manually audit the source code of web services and software authored in house by Amazon

Write proof of concept code to demonstrate the severity of a potential security issue

Provide clear communication on issues to developers that suggest and help to test the fix

Partner with AWS developers to drive improvement in application security as a result of security review engagements

Provide actionable long-term risk mitigation guidance to internal and external stakeholder

Conduct independent vulnerability research pertaining to Generative AI technologies

About the teamAbout Amazon SecurityDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.Basic Qualifications

A Bachelor’s degree in Computer Science, Cybersecurity, Information Security, degree in similar technical field, or equivalent professional experience can be used in lieu of a degree.

Minimum one year of experience in auditing AI/ML systems, models, and frameworks for security vulnerabilities.

Minimum of 3 years of experience in security testing (Penetration testing, Vulnerability testing, Red teaming, bug hunting, CTF experience, or related field).

Minimum of 3 years of experience with manually auditing source code (One or more of: Java, Ruby, Python, JavaScript, Rust, C, others) to find security issues.

Minimum of 3 years of experience scripting in Python or other equivalent interpreted languages.

Minimum of 3 years of professional experience with 2 or more areas of security engineering practices such as in web application security, network security, authentication and authorization protocols, cryptography, automation and other software security disciplines.

Preferred Qualifications

Experience testing and securing distributed systems at AWS scale.

Experience with the architecture of Generative AI models, platforms, and applications.

Knowledge of common AI/ML attack techniques such as prompt injection and ability to automate testing for these vulnerabilities.

Ability to identify vulnerabilities and threats specific to Generative AI and other AI/ML systems.

Experience with languages commonly used in AI/ML like Python, R, Java, C.

Meets/exceeds Amazon’s leadership principles for this role.

Meets/exceeds Amazon’s functional/technical depth and complexity expectations for this role.

Amazon is committed to a diverse and inclusive workplace. Amazon is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status. For individuals with disabilities who would like to request an accommodation, please visit https://www.amazon.jobs/en/disability/us.Pursuant to the Los Angeles Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.Our compensation reflects the cost of labor across several US geographic markets. The base pay for this position ranges from $136,000/year in our lowest geographic market up to $212,800/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, please visit https://www.aboutamazon.com/workplace/employee-benefits. This position will remain posted until filled. Applicants should apply via our internal or external career site.

Related jobs

  • Description

  • Our CompanyChanging the world through digital experiences is what Adobe\'s all about. We give everyone-from emerging artists to global brands-everything they need to design and deliver exceptional digital experiences! We\'re passionate about empowering people to create beautiful and powerful images, videos, and apps, and transform how companies interact with customers across every screen.We\'re on a mission to hire the very best and are committed to creating exceptional employee experiences where everyone is respected and has access to equal opportunity. We realize that new ideas can come from everywhere in the organization, and we know the next big idea could be yours!

  • We\'re Celonis, the global leader in Process Mining technology and one of the world\'s fastest-growing SaaS firms. We believe there is a massive opportunity to unlock productivity by placing data and intelligence at the core of business processes - and for that, we need you to join us.

  • Senior Security Content Engineer

  • Senior Operations Analytics Engineer

  • Who We Are:SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners in the car, at home, and anywhere on the go with connected devices. Our vision is to shape the future of audio, where everyone can be effortlessly connected to the voices, stories and music they love wherever they are.This is the place where a diverse group of emerging talent and legends alike come to share authentic and purposeful songs, stories, sounds and insights through some of the best programming and technology in the world. Our critically-acclaimed, industry-leading audio entertainment encompasses music, sports, comedy, news, talk, live events, and podcasting. No matter their individual role, each of our employees plays a vital part in bringing SiriusXM\'s vision to life every day.SiriusXM is the leading audio entertainment company in North America, and the premier programmer and platform for subscription and digital advertising-supported audio products. SiriusXM\'s platforms collectively reach approximately 150 million listeners, the largest digital audio audience across paid and free tiers in North America, and deliver music, sports, talk, news, comedy, entertainment and podcasts. Pandora, a subsidiary of SiriusXM, is the largest ad-supported audio entertainment streaming service in the U.S. SiriusXM\'s subsidiaries Simplecast and AdsWizz make it a leader in podcast hosting, production, distribution, analytics and monetization. The Company\'s advertising sales organization, which operates as SiriusXM Media, leverages its scale, cross-platform sales organization and ad tech capabilities to deliver results for audio creators and advertisers. SiriusXM, through SiriusXM Canada Holdings, Inc., also offers satellite radio and audio entertainment in Canada. In addition to its audio entertainment businesses, SiriusXM offers connected vehicle services to automakers.How you\'ll make an impact:As a Senior Salesforce Systems Engineer on our Customer Experience team, you will be responsible for the implementation, management, and enhancement of our Salesforce Service Cloud instance. You will collaborate with business stakeholders, engineering, and product teams to design and develop key features and functionality of the platform as well as the broader contact center infrastructure. Your technical expertise will be pivotal in driving innovation and efficiency within our Customer Service ecosystem. You will build integrations to other internal systems and services, including contact center, identity, commerce, and data platforms for a seamless, omnichannel experience.What you\'ll do:Collaborate with a team of world-class team of Salesforce developers and administrators, as well as cross-functional teams to understand business requirements and translate them into scalable Salesforce Service Cloud solutionsDrive the end-to-end development and maintenance of Salesforce Service Cloud, including configuration, enhancement, and integrations with internal services and APIsFollow CI/CD best practices and tools to streamline the deployment processDesign and develop solutions that leverage omnichannel contact center tools like AWS Connect for enhanced customer engagement and supportImplement generative AI technologies and chatbot solutions to optimize customer interactionsUtilize your knowledge of the Salesforce ecosystem, including Data Cloud and Marketing Cloud, to enhance our implementationStay updated on the latest Salesforce releases, features, and industry trends related to contact center technologies, and recommend innovative solutions to enhance customer service capabilitiesWhat you\'ll need:Bachelor\'s degree in Computer Science, Engineering, or related field5-8+ years of experience in Salesforce platform development and administration, with a focus on Service Cloud implementationsSalesforce Certified Platform Developer, Salesforce Certified Administrator, or Salesforce Certified Architect preferredStrong proficiency in Salesforce configuration and customization, including development languages such as Apex and JavaScript, Visualforce, Lightning Components, and other UI frameworks (e.g., Angular, React)Experience with integrations to internal services and APIs from SalesforceAdvanced troubleshooting capabilities using internal and external tools (e.g, Postman, logging, VStudio)Strong understanding of CI/CD principles and experience with related tools (e.g., GitHub Actions, Copado)Experience with agile project management processes and tooling (Atlassian, etc.)Excellent communication and interpersonal skills, with the ability to collaborate effectively with stakeholders at all levelsMust have legal right to work in the U.S.At SiriusXM, we carefully consider a wide range of factors when determining compensation, including your background and experience. These considerations can cause your compensation to vary. We expect the base salary for this position to be in the range of $114,000 to $166,050 and will depend on your skills, qualifications, and experience. Additionally, this role might be eligible for discretionary short-term and long-term incentives. We encourage all interested candidates to apply.Our goal at SiriusXM is to provide and maintain a work environment that fosters mutual respect, professionalism and cooperation. SiriusXM is an equal opportunity employer that does not discriminate on the basis of actual or perceived race, creed, color, religion, national origin, ancestry, alienage or citizenship status, age, disability or handicap, sex, gender identity, marital status, familial status, veteran status, sexual orientation or any other characteristic protected by applicable federal, state or local laws.The requirements and duties described above may be modified or waived by the Company in its sole discretion without notice. R-2024-06-105

  • Senior Software Engineer, Fraud Prevention at Justworks (View all jobs)

Job Details

Jocancy Online Job Portal by jobSearchi.