Network Security Penetration Tester, AppSTAR Network Security

AmazonApplyPublished 1 days agoFirst seen 4 hours ago
Apply
Application deadline: Aug 15, 2026

Amazon's AppSTAR Network Security (NetSec) team is seeking a Security Engineer to help keep Amazon Stores’ network infrastructure secure for its customers. In this role, you will conduct penetration tests against Amazon's network environments—including fulfillment center (FC) site networks and cloud-based and non-cloud-based infrastructure supporting Amazon Stores’ services—to identify vulnerabilities before adversaries can exploit them. This position offers challenging opportunities to work at the intersection of physical and cloud-based network security, alongside a team of highly skilled offensive security professionals.

A Security Engineer at Amazon is expected to be strong in multiple domains. Engineers in this role work closely with teams throughout Amazon Security, as well as provide technical leadership and advice to teams and leaders throughout Amazon. You will be in direct contact with teams across a variety of business verticals, giving you first-hand knowledge about how Amazon's network infrastructure is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Amazon to find new ways to compromise network environments across the company.

This role is primarily remote, with up to approximately 15% travel required for on-site network penetration testing at Amazon facilities across North America. You will conduct assessments both remotely and in-person, adapting your approach based on the target environment and engagement requirements.

Engineers in this role must show exemplary judgment in making technical trade-offs between short-term fixes and long-term security and business goals. You will demonstrate resilience and navigate ambiguous situations with composure and tact. You will be expected to provide thought leadership for the organization as you discover, invent, and innovate throughout the course of your duties. Above all else, a strong sense of customer obsession is necessary to focus on the ultimate goal of keeping Amazon and its customers secure.

Key job responsibilities
  • Conducting high-quality network penetration tests as part of a team against Amazon fulfillment networks, and cloud (AWS)-based and non-cloud-based network infrastructure supporting Amazon Stores’ services
  • Devising engagement test plans and thoroughly documenting findings, gaps, and remediation recommendations in written reports for both technical and leadership audiences
  • Performing remote and on-site network assessments at Amazon facilities (up to approximately 15% travel), including physical network reconnaissance, VLAN enumeration, and lateral movement
  • Contributing to team tooling, automation, and methodology improvements that increase the efficiency and coverage of network security assessments
  • Communicating and collaborating with partner teams, service owners, and network engineering to influence and prioritize the resolution of discovered security findings
  • Mentoring junior team members and contributing to knowledge-sharing through peer review, training, and documentation of tradecraft
A day in the life
You'll spend the majority of your day deep in network penetration tests — scoping engagements, enumerating targets, exploiting misconfigurations, and chasing lateral movement paths across Amazon's fulfillment center networks and cloud infrastructure. When you're not actively testing, you're building automation and tooling that helps the team scale its coverage and efficiency. You'll also partner with network engineers, Business Security Teams, and service owners to communicate what you found and ensure issues get fixed. No two engagements look the same — one week you may be remotely pivoting through a FC network, the next you're mapping attack paths in a cloud environment.

About the team
AppSTAR Network Security (NetSec) is a dedicated team formed at the start of 2026 to strengthen Amazon's network security posture through proactive and responsive penetration testing. We partner with security organizations, network teams, and service teams across Amazon Stores to identify vulnerabilities in network infrastructure at scale. Our culture is collaborative and autonomous — we hack hard, help our customers, and favor systemic solutions over point fixes. We're growing the team and looking for engineers who thrive on idea-driven problem solving and want to shape how network security scales across Amazon.

Diverse Experiences
Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.

Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive Team Culture
In Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth
We’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance
We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.

Basic Qualifications

  • 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • 3+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent
  • Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP
  • Experience applying threat modeling or other risk identification techniques or equivalent
  • 3+ years of experience in network penetration testing, infrastructure security assessment, or related offensive security role

Preferred Qualifications

  • Experience with AWS products and services
  • Experience with programming languages such as Python, Java, C++
  • Bachelor's degree in computer science or equivalent
  • Relevant industry certifications such as OSCP, GPEN, OSEP
  • Experience testing industrial control systems (ICS), operational technology (OT), or IoT network environments
  • Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Los Angeles County applicants: Job duties for this position include: work safely and cooperatively with other employees, supervisors, and staff; adhere to standards of excellence despite stressful conditions; communicate effectively and respectfully with employees, supervisors, and staff to ensure exceptional customer service; and follow all federal, state, and local laws and Company policies. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness and professionalism, and safeguard business operations and the Company’s reputation. Pursuant to the Los Angeles County Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.


USA, , - 159,300.00 - 202,400.00 USD annually