841,941open jobs
53,762companies
142,138added this week
Browse all
Salary
$72k per year
Location
In office (Milan)
Seniority
Middle · 3+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 27, 2026. First seen by Alion on Sep 15, 2026.

Overview
Company
Impact
Profile match
Amazon is an American technology and retail conglomerate founded by Jeff Bezos in 1994 as an online bookstore and headquartered in Seattle, Washington. It operates the world's largest online marketplace together with a global logistics network, physical grocery stores and a third-party seller platform that accounts for most units sold. Amazon Web Services, launched in 2006, is the leading public cloud provider and generates the majority of the group's operating profit, while advertising, Prime Video, Alexa devices and Kuiper satellite broadband round out the business.

We are looking for a Security Engineer to join Point-in-Time Security Testing, AWS's expert security assurance function for the launches and architectures where security automation alone is not enough. You will own complex security testing engagements end-to-end, and you will leave behind mechanisms that make each engagement worth more than itself.

Amazon Web Services (AWS) is the leading cloud service provider, providing virtualized infrastructure, storage, networking, messaging, and many other services to customers all over the world, including government customers. AWS runs a globally distributed environment operating at massive scale, and businesses from start-ups to large enterprises and governments run their most sensitive workloads on it. Point-in-Time Security Testing takes on the engagements where the architecture, threat model, or potential impact is complex enough that expert reasoning matters most. We start from the architecture and the risks rather than a generic checklist, think like an adversary, and demonstrate realistic impact. We build harnesses that steer agentic AI so experts have more time for the difficult problems, and we turn what we learn into shared methods, mechanisms, and detections for the rest of the team. As AWS ships agentic systems of its own, those same systems become targets we test.

Our work is measured by how much difficult security uncertainty we resolve with the human time available to us, not by how many issues we find. In this role you will investigate high-consequence risks, which are specific, testable claims about how an adversary could cause harm, and take each one to a documented conclusion. You will either demonstrate the issue, rule out the attack path with enough evidence, or expose a weakness in a shared mechanism or detection.

You must produce results in the face of ambiguity and imperfect knowledge, foster constructive dialogue, and drive resolution when faced with disagreement. You deliver autonomously on work scoped within the team, and you ask for guidance when a problem crosses into unfamiliar territory. You are trusted to run a difficult engagement without close supervision, and to say clearly when the plan needs to change.

Amazon's Leadership Principles of "Dive Deep", "Earn Trust", "Deliver Results", and "Invent and Simplify" will be called upon daily. Above all, we earn trust by choosing carefully where humans spend time, testing those areas deeply, and being honest about what we know and what we do not.

Key job responsibilities

- Lead complex security testing engagements end to end, including multi-engineer tests across interconnected microservice architectures, repeat testing across successive iterations of one launch, and campaigns that investigate a systemic issue across several services

- Perform penetration testing and AI-augmented source code review of complex proprietary AWS software, directing the tooling at trust boundaries, abuse cases, and attack paths it would not reach on its own, and confirming what it reports

- Take each agreed risk hypothesis to a documented conclusion, whether that means demonstrating the issue with proof-of-concept code, ruling out the attack path with sufficient evidence, or identifying a weakness in a shared mechanism or detection

- Challenge what a scope document assumes and identify what it misses, then keep the engagement moving when conditions change by building alternative test paths, re-scoping, and parallelizing work with dependent teams

- Trace attack paths across chained components and demonstrate compound risk that stays invisible when components are tested in isolation

- Assess and defend the business impact of complex and ambiguous risk, not only well-understood vulnerability classes, so service teams can act on the right things first

- Produce clear engagement results that record what you tested, why you chose those tests, what you found or ruled out, the limitations of the work, and the risk that remains

- Lead communication with developers, AppSec engineers, and Blue teams when the scope is ambiguous or a fix is not straightforward, validate the fixes, confirm remediation through Verification of Fixes, and work as an embedded security tester inside the development lifecycle when a launch calls for it

- Build automation and tune the harnesses that raise the precision of the team's AI pentest bots, measuring where they produce false positives or miss attack patterns, so expert time goes where it changes the outcome

- Test agentic AI systems as an adversary would, reasoning about how agent-to-agent (A2A) communication, tool use, memory, and orchestration can be manipulated or made to cross a trust boundary

- Leave reusable mechanisms behind, such as fuzzers, integration security tests, detection rules, tooling, or documented methodology, and track whether they are adopted

- Peer review test plans, scopes, runbooks, and reports from other peers, questioning coverage gaps and adding the test cases that are missing

- Onboard and mentor engineers on your engagements, helping them grow technically while the engagement stays on track

About the team

Why AWS Security?

At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience across cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Point-in-Time Security Testing sits within Proactive Security. While the wider organisation builds the ability to find risk through signals, automation, AI, Bug Bounty, and continuous testing, our role is different. We take on the situations where expert reasoning matters most, and we make that expertise go further every year. Our vision is that every critical AWS launch receives the right depth of expert security testing, and every hour our team spends makes future testing more effective.

Diverse Experiences

Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed, we encourage you to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying.

Inclusive Team Culture

In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to keep learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices.

Training & Career Growth

We're continuously raising our performance bar as we strive to become Earth's Best Employer. You'll find endless knowledge-sharing, mentorship, training, and other career-advancing resources here to help you develop into a better-rounded professional.

Work/Life Balance

We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture.

Basic qualifications

- Perform offensive testing of web applications and services, and source code review, to identify non-trivial issues

- Script your way out of problems and deploy code in an enterprise environment

- Suggest secure design architecture, including related to cryptography and infrastructure

- Demonstrate a propensity to learn new ideas and concepts extremely quickly

- Be data-driven and support your conclusions with evidence

- Experience with AWS technologies and services (e.g. S3, Lambda, EC2, KMS, IAM)

- A Bachelor's degree in Computer Science, Cybersecurity, or a related field from an accredited university. Equivalent professional experience can be used in lieu of a degree

- Minimum of 3 years of experience in professional penetration testing, source code auditing, bug hunting, or CTF experience

- Demonstrable depth in at least two complex security domains such as networking, workload and tenant isolation, web application and API security, or identity and access management (IAM)

- Working competence across the wider set of areas being security architecture and engineering, communication and network security, IAM, security assessment and testing, cryptography, and software development security

- Experience finding security issues in multiple languages, including one or more of Java, Ruby, Python, JavaScript, Rust, and C

- Minimum of 2 years code development using Python or equivalent language

- Demonstrable experience using boto3

- Minimum of 2 years of professional experience with security engineering practices such as web application security, network security, AuthN/AuthZ protocols, cryptography, and automation

Preferred qualifications

- Experience acting as the testing point of contact for a service or technology area across more than one engagement

- Experience running an initiative such as a CTF or an apprenticeship

- Experience performing or supporting Red Team engagements with an understanding of holistic assessment

- Experience with full-stack (Linux / Unix) software architectures from UI to infrastructure

- Experience with serverless architectures and common virtualization techniques (hypervisors / containers / jails) and escapes and exploits within those environments

- Experience with micro-service, API-based, or service-oriented software architectures

- Operations experience with CI/CD or managing distributed systems

- Web service assessment experience with authentication controls, session management, access controls, logic flaws, injection vulnerabilities, request smuggling, cloud privilege escalation, and tenant isolation

Amazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice (https://www.amazon.jobs/en/privacy_page) to know more about how we collect, use and transfer the personal data of our candidates.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The minimum gross base salary for this position is listed below. The base salary listed corresponds to working on a full-time basis. For part-time hours, the salary will be pro-rated.

Amazon reserves the right to offer a higher salary and/or level, depending on the candidate's skills, competencies, and experience. Amazon's package may include a sign on payment. In addition, the candidate may be eligible to participate in a restricted stock unit scheme operated independently by Amazon.com Inc. in USA. Your recruiting team will share final salary and any restricted stock unit scheme if applicable, depending on skills and requirements.

In addition to statutory benefits, and those applicable to the relevant CBA, company supplementary benefits may apply subject to further terms.

See below the minimum gross base salary for this position:

Milan, ITA - 62,800.00 EUR Annually

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
841,941 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Milan
Security Engineer 5 months ago
$70k – $87k per year • In office • Full-Time • 4+ years exp • Rome
Python
PowerShell
DevOps
GCP
Azure
CI/CD
AWS
IAM
Cybersecurity
Nessus
Qualys Cloud Platform
ISO 27001
OWASP Top 10
SOC 2
GDPR
Threat Modeling
SIEM
Apply
≈ $40k – $94k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Rome • Milan
DevOps
Splunk
SLI/SLO/SLA
Cybersecurity
Volatility
Microsoft Sentinel
Autopsy
YARA
Velociraptor
VirusTotal
MITRE ATT&CK
IBM QRadar
FTK
REMnux
SIEM
Analytics
Informatica
Apply
≈ $45k – $119k per year (Estimated) • In office • Internship • Bachelor's Degree • Milan
Cybersecurity
ISO 27001
Analytics
Power BI
Informatica
Management
SharePoint
Apply
SOC Analyst L2 11 days ago
≈ $41k – $96k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Rome • Milan • Bologna • Turin • Naples
Cybersecurity
SIEM
Analytics
Informatica
Apply
≈ $47k – $123k per year (Estimated) • In office • Internship • Turin
DevOps
Incident Management
Cybersecurity
ISO 27001
GDPR
Analytics
Azure Data Factory
Management
Agile
Apply
Cloud Engineer 1 day ago
$72k – $77k per year • Remote (United States) • 5+ years exp • Bachelor's Degree • Princeton
Python
Go
JavaScript
TypeScript
Node JS
Databases
Databricks
AI/ML
MLFlow
Anomaly Detection
Hugging Face
Machine Learning
Frontend
React.js
DevOps
Rest API
Terraform
Azure DevOps
GitHub Actions
Loki
Prometheus
Azure
CI/CD
Docker
Kubernetes
Grafana
Bicep
Azure AKS
FinOps
IAM
Cybersecurity
ISO 27001
SOC 2
HIPAA
Microsoft Entra ID
Apply
Remote (Greece) • Part-Time • Athens
Python
JavaScript
SQL
Python
Django
Databases
PostgreSQL
DevOps
GCP
DigitalOcean
Heroku
Azure
AWS
Apply
$130k – $176k per year • Equity • In office • Full-Time • Master's Degree • Tempe
Python
SQL
Databases
Amazon Redshift
AI/ML
Hadoop
Machine Learning
DevOps
AWS
Amazon S3
Apply
In office
Python
SQL
Databases
Google BigQuery
BigQuery
Analytics
Erwin
Apply
≈ $34k – $91k per year (Estimated) • In office • Internship • South Korea
JavaScript
TypeScript
Databases
PostgreSQL
ClickHouse
Frontend
Tailwind CSS
React.js
Radix UI
TanStack Router
shadcn/ui
DevOps
Terraform
GitHub Actions
CI/CD
Git
Cloudflare
GitHub
Management
Slack
Confluence
Jira
Apply
$178k – $227k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Seattle
Python
Java
C++
Scala
DevOps
AWS
Wi-Fi
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
$159k – $202k per year • Equity • In office • Full-Time • 3+ years exp • Bachelor's Degree • Seattle
Python
Java
C++
DevOps
AWS
TCP/IP
DNS
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
$250k – $338k per year • Equity • Hybrid • 15+ years exp • Bachelor's Degree • Herndon
Apply
≈ $95k – $213k per year (Estimated) • In office • Full-Time • 7+ years exp • Sydney
DevOps
AWS
Apply
$159k – $202k per year • Equity • In office • Full-Time • 3+ years exp • Bachelor's Degree • Redmond
Python
JavaScript
Java
Ruby
C++
Frontend
Bootstrap
DevOps
AWS
TCP/IP
DNS
Cybersecurity
Threat Modeling
Apply
≈ $25k – $32k per year (Estimated) • Hybrid • Internship • Milan
AI/ML
Machine Learning
Management
Slack
Outlook
SharePoint
Xero
Apply
≈ $21k – $40k per year (Estimated) • In office • Milan
Management
Agile
Apply
In office • Internship • Bachelor's Degree • Milan
Management
Agile
Apply
$63k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Milan
Databases
DynamoDB
DevOps
AWS
AWS Lambda
Amazon EC2
Amazon S3
Apply
$86k per year • Equity • In office • Full-Time • Bachelor's Degree • Milan
Management
Microsoft Office
Marketing
Salesforce
Apply
See all jobs
This is one of many
841,941 more open roles from verified company boards, updated every day.