Crea un profilo in modo da poter essere trovato dalle aziende, ottenere offerte di lavoro più adatte alle tue esigenze e candidarti più velocemente.
  • Cerca lavoro
  • Preferiti
  • Crea CV
    Novità
  • Stipendi
  • Iscrizioni

Security Engineer, Security Verification & Validation Team

62.800 €
Full time

Amazon Web Services (AWS)

ph3Description /h3 pWe are looking for a Security Engineer to join Point-in-Time Security Testing, AWS's expert security assurance function for the launches and architectures where security automation alone is not enough. You will own complex security testing engagements end to end, and you will leave behind mechanisms that make each engagement worth more than itself. /p h3Description /h3 pWe are looking for a Security Engineer to join Point-in-Time Security Testing, AWS's expert security assurance function for the launches and architectures where security automation alone is not enough. You will own complex security testing engagements end to end, and you will leave behind mechanisms that make each engagement worth more than itself. /p pAmazon Web Services (AWS) is the leading cloud service provider, providing virtualized infrastructure, storage, networking, messaging, and many other services to customers all over the world, including government customers. AWS runs a globally distributed environment operating at massive scale, and businesses from start-ups to large enterprises and governments run their most sensitive workloads on it. Point-in-Time Security Testing takes on the engagements where the architecture, threat model, or potential impact is complex enough that expert reasoning matters most. We start from the architecture and the risks rather than a generic checklist, think like an adversary, and demonstrate realistic impact. We build harnesses that steer agentic AI so experts have more time for the difficult problems, and we turn what we learn into shared methods, mechanisms, and detections for the rest of the team. As AWS ships agentic systems of its own, those same systems become targets we test. /p pOur work is measured by how much difficult security uncertainty we resolve with the human time available to us, not by how many issues we find. In this role you will investigate high-consequence risks, which are specific, testable claims about how an adversary could cause harm, and take each one to a documented conclusion. You will either demonstrate the issue, rule out the attack path with enough evidence, or expose a weakness in a shared mechanism or detection. /p pYou must produce results in the face of ambiguity and imperfect knowledge, foster constructive dialogue, and drive resolution when faced with disagreement. You deliver autonomously on work scoped within the team, and you ask for guidance when a problem crosses into unfamiliar territory. You are trusted to run a difficult engagement without close supervision, and to say clearly when the plan needs to change. /p pAmazon's Leadership Principles of "Dive Deep", "Earn Trust", "Deliver Results", and "Invent and Simplify" will be called upon daily. Above all, we earn trust by choosing carefully where humans spend time, testing those areas deeply, and being honest about what we know and what we do not. /p h3Key job responsibilities /h3 ul liLead complex security testing engagements end to end, including multi-engineer tests across interconnected microservice architectures, repeat testing across successive iterations of one launch, and campaigns that investigate a systemic issue across several services /li liPerform penetration testing and AI-augmented source code review of complex proprietary AWS software, directing the tooling at trust boundaries, abuse cases, and attack paths it would not reach on its own, and confirming what it reports /li liTake each agreed risk hypothesis to a documented conclusion, whether that means demonstrating the issue with proof-of-concept code, ruling out the attack path with sufficient evidence, or identifying a weakness in a shared mechanism or detection /li liChallenge what a scope document assumes and identify what it misses, then keep the engagement moving when conditions change by building alternative test paths, re-scoping, and parallelizing work with dependent teams /li liTrace attack paths across chained components and demonstrate compound risk that stays invisible when components are tested in isolation /li liAssess and defend the business impact of complex and ambiguous risk, not only well-understood vulnerability classes, so service teams can act on the right things first /li liProduce clear engagement results that record what you tested, why you chose those tests, what you found or ruled out, the limitations of the work, and the risk that remains /li liLead communication with developers, AppSec engineers, and Blue teams when the scope is ambiguous or a fix is not straightforward, validate the fixes, confirm remediation through Verification of Fixes, and work as an embedded security tester inside the development lifecycle when a launch calls for it /li liBuild automation and tune the harnesses that raise the precision of the team's AI pentest bots, measuring where they produce false positives or miss attack patterns, so expert time goes where it changes the outcome /li liTest agentic AI systems as an adversary would, reasoning about how agent-to-agent (A2A) communication, tool use, memory, and orchestration can be manipulated or made to cross a trust boundary /li liLeave reusable mechanisms behind, such as fuzzers, integration security tests, detection rules, tooling, or documented methodology, and track whether they are adopted /li liPeer review test plans, scopes, runbooks, and reports from other peers, questioning coverage gaps and adding the test cases that are missing /li liOnboard and mentor engineers on your engagements, helping them grow technically while the engagement stays on track /li /ul h3About The Team /h3 pWhy AWS Security? /p pAt Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience across cloud, devices, retail, entertainment, healthcare, operations, and physical stores. /p pPoint-in-Time Security Testing sits within Proactive Security. While the wider organisation builds the ability to find risk through signals, automation, AI, Bug Bounty, and continuous testing, our role is different. We take on the situations where expert reasoning matters most, and we make that expertise go further every year. Our vision is that every critical AWS launch receives the right depth of expert security testing, and every hour our team spends makes future testing more effective. /p h3Diverse Experiences /h3 pAmazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed, we encourage you to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying. /p h3Inclusive Team Culture /h3 pIn Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to keep learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices. /p h3Training Career Growth /h3 pWe're continuously raising our performance bar as we strive to become Earth's Best Employer. You'll find endless knowledge-sharing, mentorship, training, and other career-advancing resources here to help you develop into a better-rounded professional. /p h3Work/Life Balance /h3 pWe value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why we strive for flexibility as part of our working culture. /p h3Basic Qualifications /h3 ul liPerform offensive testing of web applications and services, and source code review, to identify non-trivial issues /li liScript your way out of problems and deploy code in an enterprise environment /li liSuggest secure design architecture, including related to cryptography and infrastructure /li liDemonstrate a propensity to learn new ideas and concepts extremely quickly /li liBe data-driven and support your conclusions with evidence /li liExperience with AWS technologies and services (e.g. S3, Lambda, EC2, KMS, IAM) /li liA Bachelor's degree in Computer Science, Cybersecurity, or a related field from an accredited university. Equivalent professional experience can be used in lieu of a degree /li liMinimum of 3 years of experience in professional penetration testing, source code auditing, bug hunting, or CTF experience /li liDemonstrable depth in at least two complex security domains such as networking, workload and tenant isolation, web application and API security, or identity and access management (IAM) /li liWorking competence across the wider set of areas being security architecture and engineering, communication and network security, IAM, security assessment and testing, cryptography, and software development security /li liExperience finding security issues in multiple languages, including one or more of Java, Ruby, Python, JavaScript, Rust, and C /li liMinimum of 2 years code development using Python or equivalent language /li liDemonstrable experience using boto3 /li liMinimum of 2 years of professional experience with security engineering practices such as web application security, network security, AuthN/AuthZ protocols, cryptography, and automation /li /ul h3Preferred Qualifications /h3 ul liExperience acting as the testing point of contact for a service or technology area across more than one engagement /li liExperience running an initiative such as a CTF or an apprenticeship /li liExperience performing or supporting Red Team engagements with an understanding of holistic assessment /li liExperience with full-stack (Linux / Unix) software architectures from UI to infrastructure /li liExperience with serverless architectures and common virtualization techniques (hypervisors / containers / jails) and escapes and exploits within those environments /li liExperience with micro-service, API-based, or service-oriented software architectures /li liOperations experience with CI/CD or managing distributed systems /li liWeb service assessment experience with authentication controls, session management, access controls, logic flaws, injection vulnerabilities, request smuggling, cloud privilege escalation, and tenant isolation /li /ul pAmazon is an equal opportunities employer. We believe passionately that employing a diverse workforce is central to our success. We make recruiting decisions based on your experience and skills. We value your passion to discover, invent, simplify and build. Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice ( to know more about how we collect, use and transfer the personal data of our candidates. /p pOur inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner. /p pThe minimum gross base salary for this position is listed below. The base salary listed corresponds to working on a full-time basis. For part-time hours, the salary will be pro-rated. /p pAmazon reserves the right to offer a higher salary and/or level, depending on the candidate's skills, competencies, and experience. Amazon's package may include a sign on payment. In addition, the candidate may be eligible to participate in a restricted stock unit scheme operated independently by Amazon.com Inc. in USA. Your recruiting team will share final salary and any restricted stock unit scheme if applicable, depending on skills and requirements. /p pIn addition to statutory benefits, and those applicable to the relevant CBA, company supplementary benefits may apply subject to further terms. /p pSee below the minimum gross base salary for this position: /p pMilan, ITA - 62,800.00 EUR Annually /p h3Company /h3 p- AWS EMEA SARL (Italy Branch) /p pJob ID: A /p /p #J-18808-Ljbffr

Offerta di lavoro pubblicata 1 giorno fa
Offerte di lavoro simili
  •  ...As the world’s leading vendor of Cyber Security, protecting organizations against the most...  ...threats and attacks, we’ve assembled a global team of driven, creative, and innovative...  ...cyber threats. As a Workspace Security Engineer , you will play a critical role in protecting... 
    Consigliato
    Tempo pieno
    Disponibilità immediata

    Check Point Software Technologies

    Milano
    3 giorni fa
  • 180 - 200 €/giorno

     ...selezione di personale ICT, ricerca per proprio cliente un/una Security Engineer - WAF / Application Security Full remote Ricerchiamo un...  ...Conoscenza di API Security, architetture Zero Trust e principi di Secure Application Design; Esperienza con normative e framework di... 
    Consigliato
    Tempo pieno
    Contratto con partita IVA
    Lavoro ibrido
    Remoto

    Gielle Informatica Recruiting

    Milano
    23 giorni fa
  •  ...WHAT WE ARE LOOKING FOR Firewall & Network Security Engineer | Space & European Programmes Join our client’s international team in Rome (Anagnina Area), supporting hands-on...  ...-EU Citizens already based in the EU with a valid work permit Once we receive your CV, we will... 
    Consigliato
    Impiego permanente
    Lavoro ibrido
    Disponibilità immediata
    Lavoro da casa
    Permesso di lavoro
    Orario flessibile

    Etinars

    Milano
    2 mesi fa
  • WHAT WE ARE LOOKING FOR IT Security & Network Engineer | Space Join our client’s international team in Rome (Anagnina Area), supporting...  ...institutions, contributing to secure, compliant and high-...  ...already based in the EU with a valid work permit Once we receive... 
    Consigliato
    Lavoro ibrido
    Disponibilità immediata
    Lavoro da casa
    Permesso di lavoro
    Orario flessibile

    Etinars

    Milano
    2 mesi fa
  •  ...dell’organico ricerchiamo figura di OT Security Analyst - Incident Responder L’ OT Security...  ...Cyber Kill Chain relativa all’attacco Validare o modificare il livello di priorità...  ...Cyber Threat Analyst Collaborazione con team IT/OT in caso di anomalie o attacchi su infrastrutture... 
    Consigliato
    Tempo pieno
    Lavoro ibrido

    Energent Spa

    San Donato Milanese (MI)
    9 giorni fa
  • 33.000 € - 44.000 €

     ...OT Security Specialist – Technology Consulting At EY, we’re all in to shape your future with confidence. Se cerchi un percorso...  ...Scopri nel concreto che cosa fa un/una OT Security Specialist nel team di Cyber Security. Nello specifico, ti occuperai di:... 
    Smart working
    Lungo termine
    Lavoro ibrido

    Ernst & Young

    Milano
    28 giorni fa
  • 30.000 € - 38.000 €

     ...con l’obiettivo di verificare periodicamente l’accesso e l’utilizzo di account privilegiati (es. tramite CyberArk, PSW); • Validare gli account tecnici secondo policy di segregazione e ownership Requisiti • Iinglese livello c1 • IAM (Broadcom) • PPT... 
    Tempo pieno
    Impiego permanente
    Tempo determinato
    Lavoro ibrido

    SILICONDEV SPA

    Milano
    un mese fa
  •  ...Lead the Communications and Networking scope. Review EPC engineering deliverables, network architectures, specifications, and vendor...  ...activities. Liaise with EPC Contractor, Vendors, and Operations teams to resolve technical issues. Monitor progress, identify... 
    Tempo pieno

    Kintec Recruitment Limited

    Milano
    9 giorni fa
  • 50.000 € - 60.000 €

     ...strengthening of the Chief Information Security Office (CISO) function...  ...with cross-functional teams to design, implement, and continuously...  ...to the design and validate secure architectures for enterprise...  ...Computer Science, Computer Engineering, Cybersecurity, Information... 
    Tempo pieno
    Impiego permanente
    Lavoro ibrido

    ion

    Milano
    2 mesi fa
  • 40.000 € - 50.000 €

     ...pubblica amministrazione. Posizione: Per ampliamento dell’Ufficio Tecnico siamo alla ricerca di un/una Pre-Sales Engineer che collaborerà con il team per la definizione delle soluzioni tecniche e la loro presentazione a clienti ed a prospect. Il ruolo prevede una... 
    Smart working

    W EXECUTIVE S.R.L.

    Milano
    2 mesi fa
  •  ...HWG Sababa, società leader nella cyber security ricerca per potenziamento del proprio organico...  ...interno una figura di un/a: PRESALES ENGINEER CYBER SECURITY Posizione:...  ...potenziali Collaborare strettamente con il team di vendita per proporre e identificare soluzioni... 
    Remoto

    HWG SABABA SRL

    Milano
    3 giorni fa
  • 27.000 € - 32.000 €

     ...routinely partnering with top academic and engineering research institutions. Moviri...  ...Moviri Consulting Performance Engineering team optimizes performance of IT systems to make...  ...What you'll do As part of our  Cyber Security team. Your responsibilities will... 
    Stage/Tirocinio
    Lavoro ibrido
    Orario flessibile

    Moviri SpA

    Milano
    15 giorni fa
  • 45.000 € - 50.000 €

     ...Senior Network Security Engineer Proteggi infrastrutture critiche e garantisci la sicurezza di ambienti complessi! Hai esperienza nella...  ...prevenendo incidenti e interruzioni di servizio • Collaborerai con team tecnici e stakeholder per garantire continuità operativa... 
    Impiego permanente

    Var Group

    Milano
    2 mesi fa
  • 25.000 € - 32.000 €

     ..., della governance IT e della sicurezza informatica, siamo alla ricerca di uno/una Cyber Security Engineer_appartenente alle categorie protette da inserire all'interno del team dedicato ai servizi di Cyber Security e Compliance. La figura selezionata sarà coinvolta... 
    Smart working

    W EXECUTIVE S.R.L.

    Milano
    un mese fa
  • 40.000 € - 50.000 €

     ...strengthening of the Chief Information Security Office (CISO) function within Cedacri companies...  ...will collaborate with cross-functional teams to strengthen the organization’s...  ...Cybersecurity, Computer Science, Computer Engineering, Information Technology, or a related field... 
    Tempo pieno
    Impiego permanente
    Lavoro ibrido

    ion

    Milano
    2 mesi fa
  •  ...Infrastructure Collaborative Solutions Enterprise network Physical security Cyber security Dalla consulenza alla progettazione, dalla...  ...al raggiungimento degli obiettivi Attitudine al lavoro in team e capacità di confronto costruttivo Approccio consulenziale,... 
    Part-time
    Tempo pieno
    Lavoro ibrido
    Orario flessibile

    Axians Italia

    Corsico (MI)
    un mese fa
  •  ...globally connected powerhouse of diverse teams and take your career wherever you want...  ...working world.  The EY Global Information Security team is looking for new members helping...  ...certifications such as AZ-500 Azure Security Engineer Product Management – working with a... 
    Disponibilità immediata
    Orario flessibile

    Ernst & Young

    Milano
    7 giorni fa
  • 25.000 €

     ...Junior Cyber Security Specialist Contribuisci a proteggere persone, dati e sistemi, promuovendo...  ...Cosa farai Entrerai a far parte del team Cyber Security e contribuirai alla...  ...informatiche legate a phishing, social engineering e compromissione delle identità digitali... 
    Tempo determinato

    Var Group

    Milano
    9 giorni fa
  •  ...Bicocca we are looking for a: Junior IT Security Specialist We are seeking a motivated...  ...security activities and grow within the IT team. The role focuses on security assessments...  ...support, monitoring activities, and secure development practices. Key Responsibilities... 
    Tempo pieno
    Orario flessibile

    MainStreaming

    Milano
    1 giorno fa
  • 35.000 € - 45.000 €

     ...organico interno un profilo di: Cyber Security Specialist In qualità di Cyber Security Specialist entrerai a far parte del team Platform & Security e lavorerai su...  ...DevSecOps, in collaborazione con un Security Engineer senior che ne coordina l’indirizzo tecnico... 
    Smart working
    Orario flessibile

    PRIMATON

    Milano
    14 giorni fa
  •  ...Senior Cybersecurity to join a global Cybersecurity Operations team responsible for protecting critical environments and supporting...  ...organizations against evolving cyber threats. You’ll be part of a 24x7 Security Operations Centre (SOC) , working with cybersecurity specialists... 
    Tempo pieno
    Impiego permanente
    Remoto
    Orario flessibile

    Talan

    Milano
    6 giorni fa
  • 36.000 € - 40.000 €

     ...endpoint, network, identity, cloud, email security, vulnerability management e referenti Cliente2. • Valutare, insieme ai team tecnici, se l’evento riguarda sistemi condivisi...  ..., SOC/CERT, cyber defense, security engineering o cyber crisis management. • Esperienza... 
    Tempo pieno
    Impiego permanente
    Tempo determinato
    Lavoro ibrido

    SILICONDEV SPA

    Milano
    un mese fa
  •  ...Investing banking un/una: DATA PROTECTION SPECIALIST La risorsa sarà inserita all'interno del reparto Compliance e farà parte del team dedicato alla gestione degli adempimenti privacy del Cliente. Contribuirà al rafforzamento del modello di governance della... 
    Impiego permanente
    Tempo determinato
    Lavoro ibrido

    NAM spa Filiale di Milano

    Milano
    16 giorni fa
  • 32.000 € - 43.000 €

     ...Cyber Security Senior Consultant – Security Strategy & Governance At EY, we’re all in to shape your future with confidence. Se...  ...Cybersecurity; Capacità di problem solving, comunicazione e team work; Un mindset analitico, flessibilità e spirito di squadra... 
    Smart working
    Lungo termine
    Lavoro ibrido

    Ernst & Young

    Milano
    4 giorni fa
  • 25.000 € - 28.000 €

     ...Software Development, è alla ricerca di un Security Technical Advisor da inserire in contesti...  ...la valutazione dei rischi, la verifica della conformità ai requisiti di sicurezza...  ...di analisi e predisposizione al lavoro in team. Modalità di lavoro: ibrida Cosa... 
    Tempo pieno
    Impiego permanente
    Tempo determinato
    Lavoro ibrido

    SILICONDEV SPA

    Milano
    un mese fa
  • 46.000 €

     ...digitale del Gruppo. Il ruolo prevede audit sui processi ICT e Cyber Security, sulle applicazioni, sui servizi e sulle infrastrutture...  ...innovativo. Quali saranno le tue attività Svolgere audit e verifiche sugli aspetti ICT e Cyber Security di applicazioni, servizi e... 
    Orario flessibile

    Intesa Sanpaolo Group

    Milano
    7 giorni fa
  • 50.000 €

     .... Overview Entrerai in un team altamente specializzato che si occupa della definizione e del disegno dei presidi e dei processi...  ...di sicurezza di riferimento per l'intero ciclo di vita dell'AI (Secure MLOps) Condurre l'attività di Threat Modeling specifiche per l... 
    Orario flessibile

    Intesa Sanpaolo Group

    Milano
    28 giorni fa
  • 35.000 € - 45.000 €

     ...in ambito Information Technology – Cyber Security_ Governance, Risk & Compliance – un profilo...  ...: capacità di interfacciarsi con team IT, Security, Audit e fornitori per garantire...  ...e controlli regolatori, certificazioni e verifiche di terza parte, gestione delle evidenze... 

    FiberCop

    Milano
    22 giorni fa
  •  ...International Payroll & Social Security Senior Consultant - Milano At EY, we’re all in...  ...figura sarà inserita all’interno del nostro Team di People Advisory Services Tax e sarà...  ...Nello specifico, ti occuperai di:  Verifica e controllo dei cedolini paga relativi a... 
    Smart working
    Contratto con partita IVA
    Lungo termine
    Lavoro ibrido

    Ernst & Young

    Milano
    7 giorni fa
  • 35.000 € - 42.000 €

     ...Esperienza in penetration testing , vulnerability management e security assessment . Conoscenza del framework OWASP e delle...  ...cui ISO/IEC 27001 , NIS2 e GDPR . Attitudine al lavoro in team e capacità di operare in contesti internazionali. Ottima conoscenza... 
    Impiego permanente
    Lavoro ibrido

    Itconsulting

    Milano
    28 giorni fa