Taro Logo

Penetration Testing Engineer (Hardware/Firmware/Virtualization), AWS Proactive Security

Amazon Web Services (AWS) is the leading cloud service provider, providing virtualized infrastructure, storage, networking, messaging, and many other services to customers worldwide.
Milan, Metropolitan City of Milan, Italy
Security
Entry-Level Software Engineer
In-Person
5,000+ Employees
1+ year of experience
Cybersecurity · Enterprise SaaS

Description For Penetration Testing Engineer (Hardware/Firmware/Virtualization), AWS Proactive Security

Amazon Web Services (AWS) is seeking a Penetration Testing Engineer with a strong passion for security-at-scale to join their Proactive Security team. This role is part of AWS Security, responsible for conducting comprehensive security assessments of all AWS products, services, and software. The position focuses on hardware security, requiring expertise in virtualization, firmware, and platform security.

The successful candidate will be responsible for performing penetration testing of complex proprietary software and hardware, conducting manual source code audits, and developing proof-of-concept code to demonstrate security vulnerabilities. They will work closely with AWS developers to implement security improvements and provide strategic risk mitigation guidance.

Key responsibilities include conducting security reviews, analyzing threat models, and developing automated tooling to detect security issues at scale. The role requires strong technical skills in areas such as virtualization security (Xen, KVM, QEMU), hardware security (PCB, JTAG, UART, SPI), and firmware security (TPM, UEFI, TrustZone).

The position offers excellent career growth opportunities through continuous learning, mentorship, and exposure to diverse technical challenges. AWS values work-life harmony and maintains an inclusive team culture with ongoing DEI initiatives. The team operates in a collaborative environment where security professionals can make significant impacts on protecting AWS's global infrastructure and customers.

This role is ideal for security professionals who are passionate about hardware security, enjoy solving complex technical challenges, and want to work at scale in a dynamic cloud computing environment. The position requires excellent communication skills, the ability to work independently, and a dedication to maintaining AWS's high security standards.

Last updated 11 hours ago

Responsibilities For Penetration Testing Engineer (Hardware/Firmware/Virtualization), AWS Proactive Security

  • Perform penetration testing of complex proprietary software and hardware for Amazon servers and devices
  • Manually audit the source code of services and software authored in house by Amazon
  • Write proof of concept code to demonstrate the severity of potential security issues
  • Provide clear communication on issues to developers
  • Partner with AWS builders to drive improvement as a result of security review engagements
  • Provide actionable long term risk mitigation guidance

Requirements For Penetration Testing Engineer (Hardware/Firmware/Virtualization), AWS Proactive Security

Linux
  • BS in Computer Science or related field, or equivalent work experience
  • Minimum of 1 years of professional experience with Security Engineering
  • Experience with Virtualization security (Xen, KVM, QEMU) and hardware security
  • Experience with x86 and/or ARM chipset and firmware security

Benefits For Penetration Testing Engineer (Hardware/Firmware/Virtualization), AWS Proactive Security

  • Training & Career Growth opportunities
  • Work/Life Balance
  • Mentorship & Career Development
  • Inclusive Team Culture
  • Ongoing DEI events and learning experiences

Interested in this job?

Jobs Related To Amazon Penetration Testing Engineer (Hardware/Firmware/Virtualization), AWS Proactive Security

Security Engineer I, Threat Hunting, Security Incident Response Team (SIRT)

Entry-level Security Engineer position at Amazon's Threat Hunting team, focusing on identifying and eliminating security threats at scale using advanced analysis and detection techniques.

Security Engineer I, Threat Hunting, Security Incident Response Team (SIRT)

Entry-level Security Engineer position at Amazon's Threat Hunting team, focusing on identifying and eliminating security threats at scale while protecting customer trust.

Security Engineer I, Threat Hunting, Security Incident Response Team (SIRT)

Entry-level Security Engineer position at Amazon's Threat Hunting team, focusing on detecting and eliminating security threats at scale using advanced analysis techniques and tools.

Security Engineer I, Threat Hunting, Security Incident Response Team (SIRT)

Security Engineer role at Amazon focusing on threat hunting and incident response, requiring 1+ years of security experience and expertise in security monitoring and log analysis.

Security Engineer I, Vulnerability Management and Remediation Operations

Security Engineer I position at Amazon focusing on vulnerability management and remediation, requiring programming skills and security expertise, based in London.