Security Engineer, Compliance Penetration Testing
$159.3k - $202.4kAmazon Locker
Amazon Stores Security is hiring a Security Engineer for our Application Security Compliance Penetration Testing (CPT) team.In this role you will attack Amazon's services, applications, and websites to find security issues, and work directly with the owning technology teams to get them resolved. CPT's testing is driven by Amazon's regulatory and compliance commitments, which means your findings support Amazon's ability to operate in regulated markets, and your reports are read by external auditors as well as internal teams.You will be in direct contact with teams across a range of business verticals, which gives you first hand knowledge of how Amazon is built and operated at a deep technical level. You will use that knowledge to find new ways to break services, processes, and technologies across the company, and to improve the tooling the team tests with.Engineers in this role are expected to show good judgment in making trade-offs between short term fixes and long term security goals, to navigate ambiguous situations with composure, and to bring a strong sense of customer obsession to the work of keeping Amazon and its customers secure.Key job responsibilities* Conducting high quality penetration tests independently, or as part of a team* Creating detailed engagement plans and thoroughly documenting findings, gaps, and remediation recommendations* Contributing to team tooling, innovation, and improvements* Communicating and collaborating with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findingsAbout the teamDiverse ExperiencesAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn’t followed a traditional path, or includes alternative experiences, don’t let it stop you from applying.Why Amazon Security?At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores.Inclusive Team CultureIn Amazon Security, it’s in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.Training & Career GrowthWe’re continuously raising our performance bar as we strive to become Earth’s Best Employer. That’s why you’ll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional.Work/Life BalanceWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there’s nothing we can’t achieve.Basic qualifications- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security- Knowledge of networking protocols such as DNS and TCP/IP- 3+ years of hands-on application penetration testing or offensive security assessments across web applications, APIs, or cloud services (non-internship) experience- 2+ years of programming or scripting in Python, Go, Java, C++, or a similar language (non-internship) experience- Experience manually identifying, exploiting, and documenting application vulnerabilities, including authentication, authorization, business logic, and input validation flaws- Experience writing penetration test reports and communicating findings, severity, and remediation guidance directly to software development teamsPreferred qualification - Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing- Experience with AWS products and services- Experience testing service-oriented or RPC-based backend services in addition to web front ends- Experience building security automation, for example scripting or tooling that automates testing, finding triage, reporting, or evidence collection- Experience using AI or LLM-assisted tooling to accelerate security testing- Working knowledge of one or more regulatory or compliance frameworks such as PCI DSS, SOX, MAS TRM, RBI, or GDPR, and how their requirements translate into penetration testing scope and evidence- Familiarity with recognized testing standards such as OWASP ASVS, OWASP Top 10, or PTES- Offensive security certification such as OSCP, OSWE, GPEN, or PenTest+Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at .USA, NY, Virtual Location - New York - 159,300.00 - 202,400.00 USD annually
- ...POSITION: Part-Time Sr.Penetration Tester SUMMARY: IMRI... ...and penetration testing activities focused on... ...guidance while maintaining compliance with approved rules... ...testing, web application security testing, wireless... ...security, or security engineering experience, including...SuggestedPart timeFor contractorsLocal areaMonday to FridayNight shift
$158k - $194k
...provide more details. Job Summary: The Penetration Testing Lead (Vice President) serves as the... .... This position evaluates the security posture of traditional enterprise systems... ...insights for stakeholders Partner with engineering, infrastructure, and security teams to...SuggestedTemporary workWork at officeLocal areaRemote work1 day per week- ...and this role owns the security posture that makes... ...possible. As Senior Security Engineer, you'll lead security... ..., operations, compliance, and customer trust: a... ...tabletop exercises, backup testing coordination, and BCP... ...vulnerability management, penetration testing programmes,...SuggestedRemote workWorldwide
- IMRI is seeking a part-time OT Penetration Tester to support OT, ICs, SCADA, and critical infrastructure environments. The role involves hands-on testing, risk-based analysis, and delivering practical remediation guidance while maintaining operational continuity. You will...SuggestedPart time
- .../ Houston, TX Drive the security of critical banking applications... ...through hands-on offensive testing. As an Assessments &... ...plan, execute, and report on penetration tests targeting high-impact... ...). Experience in reverse engineering thick-client and mobile applications...Suggested
- Working remotely, the full-time Senior Penetration Tester will independently conduct penetration testing of applications and systems, identify security flaws, and develop strategies to mitigate cybersecurity risks. Key responsibilities Perform application and network...Full timeRemote work
- ...to create a culture of compliance. DCWP empowers... ...seeking to hire a Cyber Security Analyst Level II to join... ...conducting disaster recovery tests, publishing test... ...programming, computer engineering, information technology... ...enterprise risk management, penetration tester, red team/...Work at office
$140k - $190k
...About Method Security Method Security is dedicated to reshaping... ...Role Overview As a Security Engineer at Method Security, you will... ...virtualization software for continuous testing and simulation.... ...tools, such as networking and penetration testing tools, and integrating...Shift work- ...seeking a Senior AWS Cloud Security Consultant to help design remotely... ...architecture, policy engineering, and AWS governance, with a... ...business platforms where security, compliance, and operational rigor are... ...development ~ Policy testing and validation Advanced...Full timeRemote work
- ...Description Job Description Job Duties Develop a security plan for best standards and practices for the company... ...new methods to protect the company's systems Conduct penetration/vulnerability testing and risk analysis to expose weak points and identify potential...Weekend work
$170.4k - $255.7k
...responsible for identifying vulnerabilities and security weaknesses across Stripe's systems,... ...hybrid offensive function: conducting penetration testing, emulating real-world threat actors... ...believe the best offensive security engineers are equal parts hacker and engineer....Remote workWork from homeWorldwide$170k - $200k
...automate property access, operations, and security from a single platform. Our products... ...is looking for a Senior Security Engineer to join our growing security team. In... ...threat modeling and secure code review to penetration testing and vulnerability management. You will...Temporary workRemote workWorldwideFlexible hoursShift work- Join to apply for the Security Engineer (Remote) role at Jobright.ai Join... ...portfolio tracking and tax compliance. They are seeking a Security... ...party audits (e.g. SOC 2, pen test) to validate and strengthen... ...third-party audits (e.g. SOC 2, penetration testing), security...Remote jobFull timeTemporary workH1b
$2,000 per month
...investors and staffed by leading engineers, Etched is redefining the... ..., building and maintaining a secure yet friction-free computing environment... ...or a compromised silicon testing machine. Conducting regular... ...assessments and penetration testing on internal systems and...Remote jobWork at officeRelocation packageFlexible hours- ...Position As our first dedicated Senior Security Engineer, you will join a remote, global health... ...time zones. The Impact Lead security testing for our web apps, APIs, cloud (AWS/OCI... ...infrastructure security roles. Strong hands-on penetration testing and vulnerability discovery...Remote work
- ...transformation across cloud, data, software engineering, and artificial intelligence . We work... .... We are looking for an Application Security Engineer to join a greenfield digital... .... Support vulnerability scanning and penetration-testing activities — coordinating findings and...
$110k - $130k
...Description: KPA is seeking a Senior Security Engineer to serve as the senior technical... ...identity security, privileged access, penetration testing, and security hardening initiatives.... ...security audit requirements, and technical compliance initiatives. Own Cisco Meraki...- ...ll Do: We are seeking an experienced Security Engineer to join our growing security team in... ...Track vulnerability aging and SLA compliance Generate management reports and dashboards... ...security configurations Support penetration testing and red team activities Conduct WAF/...Flexible hours
$85.4k - $168.1k
Overview The Microsoft Windows Security team is looking for a learn-it-all security engineer that will help secure Microsoft Windows products and devices, with... ...security design reviews, code reviews, penetration testing, vulnerability research and driving systematic...Ongoing contractLocal areaWorldwide$120k
...solutions in the areas of Cyber Security, Instructional Design and Training, Software Engineering and IT Support Services to... ...MKS2. Ethical Hacker / Penetration Tester Principal Location: Hybrid... ...security, penetration testing, secure coding practices, and...Full timeRemote work$133k - $173k
...can make a difference As a Principal Security Engineer, AI Offensive Security, you build and... ...security expertise to automate security testing and vulnerability workflows across web... ...effectiveness of agentic systems. Support penetration testing and purple-team activities...Work experience placementRemote work- Position Overview The Senior Cyber Security Engineer will bridge the gap between "Compliance" and "Engineering." You will not just audit the system, you will help... ...vulnerabilities Integrate automated security testing (SAST/DAST) tools (e.g., SonarQube, OWASP ZAP) into...Remote workMonday to FridayFlexible hoursWeekend work
$90.9k - $129.9k
Select how often (in days) to receive an alert: Advisor Security Compliance Date: Sep 24, 2026 Location: Any city, GA, US, 99999 Work Mode... ...and problem solving skills for design, creation and testing of security systems Leadership skills to guide and mentor the...Full timeFlexible hoursAfternoon shift- ...Job Description Job Description Senior Software Engineer – Cybersecurity & Backend Job Type: Contractor (~15 hrs/week... ...Implementation Codebase Refactoring Performance Optimization Penetration Testing Security Auditing Job Summary Work on challenging coding and...For contractorsRemote workFlexible hours
- ...focus on the following role: The IT Security Engineer is responsible for identifying,... .... This role is critical to sustaining compliance with CMMC requirements, meeting corporate... ...Apply patches and updates after proper testing for compatibility Remediate...
$180k - $240k
...Information Security Engineer Where Medicine Meets Intelligence Doctronic is the first... ...'ll Do Maintain SOC 2 Type II compliance and manage ongoing audits with... ...Conduct and coordinate regular penetration testing, vulnerability assessments, and security...Flexible hours$99k - $232k
...Summary The Opportunity As a Cloud Security Manager you will guide the design,... ...security controls, support vulnerability testing, and help clients strengthen their security... ...implementing security architecture, controls, and engineering solutions across cloud platforms -...Full timeH1b$189k - $255.5k
...creator economy and are looking for a Security Engineer to support our mission.This role is Fully... ...by fast iteration: shipping MVPs, testing hypotheses, and evolving products based... ...believe in fair and transparent pay. In compliance with New York and California pay...Work at officeLocal areaRemote workWorldwideFlexible hours3 days per week$155k - $410k
...Summary The Opportunity As a Cloud Security Consultant - Director you will help... ...vulnerabilities, conduct risk assessments and testing activities, and contribute to secure... ...Computer and Information Science, Computer Engineering, Computer Programming, Computer Science,...Full timeH1b- Leading a critical AI Security Operating Capability workstream, the full-time Senior Cybersecurity... ...configure security controls, and ensure compliance for AI use cases on Microsoft Power... ...Own execution of control configuration, testing, and documentation across selected AI...Permanent employmentFull timeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer, Compliance Penetration Testing. Be the first to apply!
- dlp security engineer New York, NY
- application security engineer New York, NY
- principal security engineer New York, NY
- security software engineer New York, NY
- aws cloud security engineer New York, NY
- sr security engineer New York, NY
- endpoint security engineer New York, NY
- offensive security engineer New York, NY
- sr information security engineer New York, NY
- security infrastructure engineer New York, NY



