Application deadline: Aug 25, 2026
Amazon's Stores Application Security Team is seeking a Mobile Security Engineer to help keep Amazon secure for its customers. In this role, you will attack Amazon's services, mobile applications to discover security issues and report them to our internal technology teams. This position will provide you with challenging opportunities, both technologically and as a leader, but will also be a great deal of fun if hacking Amazon alongside a team of highly skilled individuals sounds exciting to you.
Key job responsibilities
* Conducting high quality application penetration tests independently, or as part of a team
* Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations
* Contributing to team tooling, innovation, and improvements
* Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings
BASIC QUALIFICATIONS
- Bachelor's degree in computer science or equivalent
- 3+ years of experience in a penetration testing or similar offensive security role
- 3+ years of experience in client-side application security, including reverse engineering and security assessments
- 3+ years of professional experience with security engineering practices, including: web application security, authentication and authorization protocols, cryptography, automation, and other software security disciplines
- 3+ years of experience with dynamic and manual code auditing to identify security issues
- 3+ years of experience with interpreted or compiled languages (e.g. Python, Ruby, C/C++, Java, .NET)
- Experience with threat modeling, design review, or other threat analysis techniques
- Proficiency with binary analysis tools (e.g. Ghidra, IDA Pro, Radare2, Hopper, Jadx)
- Experience with client-side application instrumentation and dynamic testing (e.g. Frida, Objection, LLDB, Burp Suite)
PREFERRED QUALIFICATIONS
- Knowledge of cloud services such as AWS or equivalent
- Experience with design, implementation, support, and evaluation of security-focused tools and services
- Experience with mobile application penetration testing
- Familiarity with threat models for client-side applications on consumer devices and the vulnerability classes specific to their platforms and communication protocols
- Experience mentoring developers on secure coding practices and vulnerability mitigations
- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, , - 159,300.00 - 202,400.00 USD annually
USA, TX, Virtual Location - Texas - 159,300.00 - 202,400.00 USD annually