logo
AI Resume Tailoring Sign in to use this AI Cover Letter Sign in to use this

Job Description

The Annapurna Labs Security Team secures the firmware at the foundation of AWS custom silicon. We work on Graviton processors and the Nitro System — hardware that runs a substantial share of the world's cloud workloads — in close collaboration with the silicon architects and firmware developers who design it. Our engineers operate at the lowest levels of the stack: secure boot chains, hardware root of trust, attestation, cryptographic protocol design, and the boundaries between trust domains within the system.



Key job responsibilities
As a Security Engineer, you will threat model new silicon and firmware architectures, conduct low-level penetration testing against privileged and externally reachable interfaces, review designs and code across multiple firmware components, and build the fuzzing and analysis tooling that makes this work repeatable at silicon scale. You will also help raise the security bar across the wider organization through direct engagement with firmware and hardware teams. We are looking for engineers fluent in C and ARM assembly, with real depth in secure boot, applied cryptography, or embedded exploitation, and the technical credibility to hold a position in a room full of people who designed the system you are testing.

Basic qualifications

- 4+ years of low-level systems security research and vulnerability testing experience
- Experience developing security tools (fuzzers, scanners, analysis frameworks)
- Security architecture design and threat modeling experience
- Proficiency in C and experience with Python
- Deep knowledge of security aspects of ARM/x86 processor architectures
- Strong understanding of hardware security (secure boot, cryptographic implementations, side-channel attacks)
- Knowledge of security protocols and cryptographic primitives
- Experience in AI usage for security research
- Technical English proficiency

Preferred qualifications

- Background in firmware reverse engineering and vulnerability research
- Experience with fuzzing frameworks (AFL++, libFuzzer, Syzkaller)
- Knowledge of virtualization security or hypervisor technologies
- Familiarity with AWS services
- Technical leadership, mentoring, and cross-functional collaboration
- Security publications (research, CVEs)
- CTF, bug bounty, or competitive security research background

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.
Do you match this job?

Here is what this employer asked for. Sign in and we will fill in your half.

  • Role Software Security Engineer, Infra & DevOps team Annapurna
  • Experience 3-4 years
  • Education Any
  • Work type On-site
  • Location Haifa, Haifa, ISR
Check my match
Amazon
Consumer Apps & Media · 500+ Members · Seattle, WA, United States

Amazon operates a broad portfolio spanning online retail, third-party marketplaces, logistics, cloud computing, advertising, devices, entertainment, and subscription services. Its consumer businesses include Amazon stores and Prime, while Amazon Web Services provides cloud infrastructure, databases, analytics, and AI services. The company also develops products such as Alexa and Kindle, produces and distributes media, and runs fulfillment and delivery networks. Amazon serves consumers, sellers, developers, enterprises, creators, and public-sector customers through interconnected commerce and technology platforms.

All jobs at Amazon
Job Overview
Eligibility
Not stated The posting does not say.
Workplace
On-site
Job Posted:
3 days ago
Job Type
Full Time
Education
Any
Experience
3-4 years

Share This Job: