Network Security Penetration Tester
Job Description
Amazon’s AppSTAR Network Security (NetSec) team is building a stronger security posture through proactive and responsive network penetration testing. This role is primarily remote, with up to approximately 15% travel for on-site assessments across North America. You’ll work in a culture that values collaboration and autonomy, where the team focuses on systemic solutions and shared learning.
What you’ll do
- Perform high-quality network penetration tests as part of a team across Amazon fulfillment networks and AWS-based and non-cloud infrastructure that supports Amazon Stores services.
- Develop engagement test plans and produce detailed written reports documenting findings, gaps, and remediation recommendations for both technical and leadership audiences.
- Conduct remote and on-site network assessments at Amazon facilities, including physical network reconnaissance, VLAN enumeration, and lateral movement.
- Improve the team’s tooling, automation, and assessment methodology to increase efficiency and coverage.
- Collaborate with partner teams, service owners, and network engineering to influence and prioritize remediation for discovered security findings.
- Support team growth through mentoring junior members and contributing to knowledge sharing via peer review, training, and documentation of tradecraft.
Skills and experience
- 3+ years of any combination of: threat modeling, secure coding, identity management and authentication, software development, cryptography, system administration, and network security.
- 3+ years of scripting, programming, and security code review in a common programming language (non-internship).
- Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits (or equivalent).
- Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP.
- Experience applying threat modeling (or other risk identification techniques, or equivalent).
- 3+ years of experience in network penetration testing, infrastructure security assessment, or a related offensive security role.
Team technologies
Work will center on AWS, Python, Java, C++, HTTP(S), DNS, and TCP/IP.
Benefits
- Sign-on payments
- Restricted stock units (RSUs)
- Health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance, and option for Supplemental life plans), plus EAP, Mental Health Support, Medical Advice Line, and Flexible Spending Accounts
- 401(k) matching
- Paid time off
- Parental leave
- Adoption and Surrogacy Reimbursement coverage
Preferred qualifications
- Experience with AWS products and services
- Experience with Python, Java, C++
- Bachelor’s degree in computer science or equivalent
- Relevant industry certifications such as OSCP, GPEN, OSEP
- Experience testing ICS, OT, or IoT network environments
- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
Application deadline: Aug 15, 2026
Compensation: USD 159,300 - 202,400 per year
Experience level: 3+ years