Penetration Tester, AWS Security
Job Description
In this role, you will support continuous, adversarial testing of AWS production services. The work blends manual assessment with outputs from GenAI security tools and automation to produce demonstrated exploit paths, actionable findings, and validated fixes.
Responsibilities
- Conduct adversarial testing of AWS production services within scoped work, following established team methodologies and guidance from senior engineers.
- Use and extend results from GenAI security tools and automation by combining candidate weaknesses into demonstrated exploits, rather than forwarding raw alerts as final conclusions.
- Manually audit source code for web services and in-house software, focusing on defined components and known risk areas that tooling may cover less effectively.
- Follow a suspected flaw through its impact within your scope, and escalate to senior engineers when the issue reaches across a service boundary.
- Produce proof of concept code that demonstrates provable, reproducible impact for identified issues.
- Communicate findings in written and verbal formats, covering what is wrong, why it matters, and what to do about it, and assist in validating that remediation works.
- Take ownership of tickets you create and drive them toward a validated fix, treating “resolved” as unproven until you confirm impact is eliminated.
- Feed limitations and gaps back to GenAI tool owners to improve tooling effectiveness and reduce reliance on the human-only frontier.
- Contribute to team runbooks, tools, and automation, and help automate any manual techniques the team performs more than twice.
- Act on signals used to set team targets, including change signals, tool output, bug bounty reports, and threat models, and apply judgment on when to work independently versus when to seek guidance.
Required Qualifications
- Knowledge of one or more scripting languages, such as Python, Ruby, or Perl.
- Knowledge of security fundamentals including common vulnerability classes, threat modeling, and secure coding, obtained through self teaching, a skills program, formal education, or equivalent experience.
- Ability to communicate security risk for low complexity problems in written and verbal form.
Preferred Qualifications
- Bachelor’s degree in Engineering, Computer Science, or related field.
- Hands on experience with penetration testing, CTFs, bug bounties, or security research.
- Exposure to cloud environments such as AWS (or similar) and web application security.
- Experience writing automation or tooling to reduce manual effort.
Technologies
- AWS
- GenAI
- Python, Ruby, Perl
Location
Texas (onsite)
Compensation
USD 136,000 - 184,000 per year
Benefits
- Health insurance (medical, dental, vision, prescription), Basic Life & AD&D insurance, option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage.
- 401(k) matching.
- Paid time off.
- Parental leave.
- Sign-on payments.
- Restricted stock units (RSUs).