✦ Luna Orbit — Cybersecurity

Security Engineer III - AMZ9689562

at Amazon.com

📍 US, NY, New York Unknown 💰 $175K – $175K USD / year Posted April 14, 2026
Salary $175K – $175K USD / year
Type Full-Time
Experience senior
Exp. Years four years of experience
Education Bachelor's degree or foreign equivalent degree in Computer Science, Cybersecurity, Information Security, or a related field
Category Cybersecurity

Perform penetration testing and independent vulnerability research on proprietary software and hardware for AWS services. Manually audit in-house source code, write proof-of-concept code, communicate findings to developers, and provide long-term risk mitigation guidance.

  • Perform penetration testing of complex AWS-related software and hardware
  • Manually audit source code to find security issues
  • Write proof of concept code to demonstrate severity
  • Partner with AWS developers to improve application security
  • Provide actionable long-term risk mitigation guidance

This role combines offensive and verification-oriented security testing (penetration testing, red teaming, bug hunting, CTF) with manual source code auditing and Python scripting. It requires deep AWS security knowledge across S3, Lambda, EC2, KMS, and IAM, plus expertise in web application security, network security, authentication/authorization, cryptography, and security automation.

The ideal candidate is a senior Security Engineer with 4+ years of hands-on security testing experience including penetration testing, vulnerability testing, and red teaming. They can manually audit source code across languages (including Python) to identify security issues and provide AWS-focused risk mitigation guidance using services like S3, Lambda, EC2, KMS, and IAM.

experience in security testing (penetration testingvulnerability testingred teamingbug huntingCTF experienceor a related field)manually auditing source code (JavaRubyPythonJavaScriptRustCor related) to find security issuesscripting in Python or other equivalent interpreted languagesexperience with at least two areas of security engineering practices (web application securitynetwork securityauthentication and authorization protocolscryptographyautomationor related)experience with AWS technologies and services (S3LambdaEC2KMSand IAM)
Security Engineer IIIpenetration testingvulnerability testingred teamingbug huntingCTF experiencemanually auditing source codeJavaRubyPythonJavaScriptRustCscripting in Pythonweb application securitynetwork securityauthentication and authorization protocolscryptographyautomationAWS technologies and services (S3LambdaEC2KMSIAM)proof of concept codesecurity review engagementsrisk mitigation guidancevulnerability research
penetration testingvulnerability testingred teamingbug huntingCTF experiencemanually auditing source codeJavaRubyPythonJavaScriptRustCscripting in Pythonweb application securitynetwork securityauthentication and authorization protocolscryptographyautomationAWS technologies and servicesAmazon Simple Storage Service (Amazon S3)AWS LambdaAmazon Elastic Compute Cloud (Amazon EC2)AWS Key Management Service (AWS KMS)AWS Identity and Access Management (AWS IAM)proof of concept code
clear communication on issues to developersactionable risk mitigation guidanceindependent vulnerability researchstakeholder managementpartnering with developersdocumentation
Industry SaaS
Job Function Test, research, and remediate security vulnerabilities for AWS services
Role Subtype Security Engineer
Tech Domains Cybersecurity, Amazon Web Services
Security Engineer IIISecurity Engineerpenetration testingvulnerability testingred teamingbug huntingCTF experienceproof of concept codemanually audit the source codesource codeJavaRubyPythonJavaScriptRustCscripting in Pythonweb application securitynetwork securityauthentication and authorization protocolscryptographyautomationAWSS3AWS LambdaEC2AWS KMSIAMAWS technologies and servicessecurity review engagementsrisk mitigation guidancevulnerability researchmanually auditing source codeAWS Identity and Access Management (AWS IAM)

Bachelor's degree required (or foreign equivalent in specified fields), 4+ years of experience in required security testing and manual source code auditing, Experience with AWS technologies and services (S3, Lambda, EC2, KMS, and IAM)

Apply for this Position →

Get matched to jobs like this

Luna finds roles that fit your skills and career goals — no endless scrolling required.

Create a Free Profile