Amazon is the largest online retailer in the world. The Fortune 500 company offers traditional and e-books, household items, apparel, electronics, movies, music
Senior Security Engineer
Location
United States
Posted
2 days ago
Salary
$178.4K - $226.7K / year
Seniority
Senior
Job Description
Senior Security Engineer
Amazon
Role Description Amazon’s STORM Red Team (SDO Threat Operations, Research & Monitoring) is looking for a Senior Security Engineer to join our team of offensive security operators. We hack Amazon’s services, infrastructure, AI/ML systems, processes, and controls, then work with defensive and service teams to fix what we find and sharpen detection, prevention, and response capabilities across the company. This is a fully remote position by design. The team is distributed and operates remotely as a core part of how we work. We’re looking for someone who can independently lead Red Team engagements end-to-end, identify and drive remediation of systemic security issues, mentor other operators, and influence security outcomes across organizational boundaries. You’ll be working alongside experienced operators on high-impact engagements against Amazon’s most critical systems. - Lead Red Team engagements end-to-end: scoping, target identification, execution, reporting, and driving remediation with service teams - Build and execute complex, multi-stage attack paths across diverse environments including cloud infrastructure, AI/ML systems, and corporate networks - Identify systemic security issues that span multiple teams and drive ownership, prioritization, and resolution through escalation when needed - Own a functional area on the Red Team (e.g., detection engineering partnership, threat intelligence integration, tooling, response collaboration) and drive it forward - Produce high-quality engagement reports with sufficient background, context, and actionable recommendations for both technical and leadership audiences - Mentor and develop other engineers on the team by overseeing engagements, providing report reviews, and raising the technical bar - Proactively identify valuable engagement targets and drive their prioritization through understanding of Amazon’s threat landscape and business context - Collaborate with detection engineering, incident response, and security leadership to translate offensive findings into defensive improvements - Develop and maintain offensive tooling, automation, and methodologies that improve team efficiency - Leverage AI to accelerate offensive workflows and assess AI/ML systems for security weaknesses Qualifications - Knowledge of cloud computing services and deployment architecture - Bachelor’s degree in computer science or equivalent, or 6+ years of hands-on Red Team / offensive security experience in lieu of a degree - 5+ years of programming in Python, Ruby, Go, Java, C++, or similar - 5+ years of experience on a Red Team or in offensive security roles (penetration testing, adversary simulation, vulnerability research) - 2+ years of experience leading or technically directing multi-person offensive engagements Preferred Qualifications - Experience leading multi-week adversary emulation campaigns from scoping through remediation - Experience identifying and driving resolution of systemic security issues across organizational boundaries - Experience with cloud-native red teaming (AWS, Azure, or GCP attack paths, privilege escalation, cross-account lateral movement) - Experience assessing or attacking AI/ML systems (prompt injection, agent manipulation, model extraction, training data poisoning, RAG exploitation) - Experience leveraging AI/ML for offensive purposes (automated recon, exploit development, payload generation, building offensive agents) - Published security research, CVEs, conference talks, or open-source offensive tooling Benefits - Comprehensive health insurance (medical, dental, vision, prescription) - Basic Life & AD&D insurance and option for Supplemental life plans - EAP, Mental Health Support, Medical Advice Line - Flexible Spending Accounts - Adoption and Surrogacy Reimbursement coverage - 401(k) matching - Paid time off - Parental leave
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Constantly improve automation, develop new tools and skills that make our secure practices easier for users to adopt and deploy • Partner with engineering and product management from earliest design through release. This entails tracking evolving discussions, surfacing security implications, and translating them into practical mentorship • Run security reviews across code, dependencies, containers, cloud, and CI/CD • Triage, prioritize, and drive remediation to closure • Build automation and developer-facing tooling that make secure-by-default the easy path • Ask sharp questions. Challenge assumptions. Surface risks that don't appear on standard checklists • Improve secure development practices, standards, and workflows • Communicate risk crisply to technical and non-technical audiences • Stay ahead of emerging threats relevant to modern software and cloud.
Cybersecurity Expert
Bespoke LabsBespoke Labs is a venture funded startup creating AI tools for data curation and post-training LLMs. (We are hiring!)
• Monitor and analyze evolving cyber threats as they intersect with AI systems and training pipelines • Track attacker TTPs, threat-group behavior, and AI-targeting trends across a 6–24 month horizon • Conduct adversarial analysis and scenario planning to stay ahead of emerging risks • Probe AI models for security boundaries through structured prompt testing and red-teaming exercises • Run independent security audits and penetration tests across systems and infrastructure • Identify, document, and prioritize vulnerabilities with clear remediation recommendations • Produce executive-ready risk assessments and intelligence reports that drive decision-making
OT Security Engineer
Adapture RenewablesIncorporated in 2011, Adapture Renewables develops, acquires, owns, and operates utility-scale solar energy assets and battery energy storage systems across the U.S., aiming to
Role Description Adapture Renewables, Inc. is on a mission to be a leader in this new era of sustainable energy. Our Technology team is looking for a talented OT Security Engineer to help support the efforts of our fast-growing company. This position will work in our Technology team and is responsible for designing, implementing, and maintaining cybersecurity controls across ARI’s SCADA and industrial control system (ICS) environments, including the interfaces between site OT networks and our enterprise IT infrastructure. The role owns NERC CIP Low impact compliance across the operating fleet, the vendor security relationships that gate access to our plants, and the security telemetry that feeds our centralized monitoring stack. This role reports to the Director of Technology & Security. The candidate may be based remotely in the U.S., with regular travel to operating PV and BESS sites and periodic travel to our Bay Area home office. Core Responsibilities - Design and implement OT network segmentation between site SCADA, control, and enterprise zones across the operating fleet. - Own secure remote access for vendors and ARI staff: jump hosts, MFA, session recording, and just-in-time access patterns. - Deploy and tune EDR on plant servers and engineering workstations within OT reliability constraints. - Maintain hardened baselines and configuration control for site servers, HMIs, RTUs/RTACs, and OT network equipment. - Run vulnerability assessment and patch / mitigation cycles for OT assets in coordination with site operations. - Maintain and execute the technical controls required under CIP-003 R2 Attachment 1 across all Low impact BES Cyber Systems. - Maintain BES Cyber System asset inventories and categorization evidence (CIP-002). - Maintain CIP-013 Low impact supply chain risk management evidence for vendors with electronic access. - Support CIP-008 incident reporting workflows and CIP-011 information protection requirements. - Participate in self-certifications, internal controls testing, and external audits; produce audit-quality artifacts. - Establish and enforce security requirements for SCADA, inverter, and BESS OEMs, ISPs, and field service vendors. - Drive contractual and technical supply chain controls in partnership with Procurement and Legal. - Integrate OT telemetry and security logs into ARI’s centralized monitoring stack. - Triage and lead response for OT security events; coordinate with site operations, the Compliance team, and the MSSP / enterprise SOC. - Develop and run tabletop exercises; maintain CIP-008 playbooks and capture post-incident lessons learned. - Conduct site visits to operating PV and BESS plants for inventories, validations, and control testing. - Deliver OT security awareness training for operators, technicians, and vendor partners. - Contribute to ARI’s broader cybersecurity program, aligned to CIS Controls v8, NIST CSF v2, and the in-progress IEC 62443 and ISO 27001 implementations. Qualifications - 3–5+ years in OT / ICS / SCADA security, industrial cybersecurity, or critical infrastructure security; utility, IPP, or owner-operator experience strongly preferred. - Bachelor’s degree in Electrical Engineering, Computer Engineering, Cybersecurity, or related discipline, or equivalent demonstrated experience. - Hands-on experience implementing and evidencing NERC CIP controls, with direct exposure to CIP-002, CIP-003, CIP-008, CIP-011, and CIP-013. - Working knowledge of OT networking: VLANs, L2/L3 switching and routing, industrial firewalls, DMZ design, jump architectures, and certificate-based authentication. - Familiarity with common ICS hardware and protocols: PLCs, RTUs, RTACs, HMIs; Modbus, DNP3, SEL. - Experience with SIEM / logging platforms and tuning detections for OT environments. - Preferred certifications: GICSP, ISA / IEC 62443 Cybersecurity Specialist, CompTIA Security+, or CISSP. - Strong documentation discipline; ability to produce evidence that survives audit scrutiny. - Clear written and verbal communication; able to translate security requirements into reliability outcomes for plant operations. - Solar and BESS operations experience, ERCOT market exposure, and prior NERC CIP audit participation are pluses. - Comfortable with field work, planned outage coordination, and occasional on-call response. - Valid driver’s license and ability to travel to operating sites as needed. Benefits - 401(k) plan with company matching contribution - Competitive health, vision, and dental benefits - Attractive personal time off and company holiday package - Work-from-home policy - Salary commensurate with experience Note Qualified candidates only. No search firms. Adapture Renewables, Inc. is committed to equal employment opportunity.
• The Project Manager administers assigned project(s) from ramp-up to completion; planning and executing the projects within the terms of the signed agreement ensuring the project is delivered on time and within budget • Implement project and process management methodology, standards and tools to drive and facilitate successful project delivery. • Lead project kick-off meetings to ensure proper initiation of a given project. Act as initial point of escalation for all issues that require further investigation. Complete accurate monthly forecasting report to aid in proper staffing and future financial analysis • Proactively mitigate risk and forecast the trajectory of projects to ensure that timely action is taken to keep projects on time and budget • Accurately estimate costs and revenue for the life cycle of Projects and/or Work Orders according to our company goals and standards



