Amazon.com Services LLC
Technology
SecurityEngineerII,StoresRedTeam
Neural analysis suggests this role is
optimal for Mid candidates.
“Security Engineer II, Stores Red Team at Amazon.com Services LLC. Skills: Red Teaming, Offensive Security, AI/ML Security, Adversary Emulation. Conduct red team engagements. Create engagement plans”
What You'll Achieve.
Sharpen detection capabilities; Sharpen prevention capabilities; Sharpen response capabilities
Industry & Context.
Sharpen detection capabilities; Sharpen prevention capabilities; Sharpen response capabilities; Discover weaknesses
What They're Looking For.
Must Have
3+ years programming Python, 3+ years Red Team experience, Familiarity with AI/ML vulnerability classes, Bachelor's degree in computer science, 4+ years Red Team experience in lieu of degree
Nice to Have
Cloud-native red teaming experience, Leveraging AI/ML for offensive purposes, Published security research, CVEs, Conference talks, Open-source offensive tooling, Implant/C2 development experience, Experience evading EDR/XDR platforms, Familiarity with adversary emulation frameworks, Threat-informed operations
What You'll Do.
Conduct red team engagements
Create engagement plans
Emulate adversary TTPs
Document attack paths
Document findings/gaps
Document recommendations
Communicate with partner teams
Collaborate with service owners
Influence security findings resolution
Prioritize security findings resolution
Drive security findings resolution
Perform manual examination
Document exploit chains
Document proof of concept scenarios
Assess security of AI/ML systems
Assess LLM applications
Assess agentic architectures
Assess model serving infrastructure
Leverage AI/ML capabilities
Build offensive tooling
Enhance offensive tooling
Automate security research workflows
Improve engagement efficiency
Contribute to tooling
Contribute to processes
Contribute to documentation
Contribute to red team operations quality
Help recruit engineers
How You'll Work.
Team & Collaboration
Partnering with AWS Red Team; Collaborating with defensive teams; Collaborating with service teams; Partner teams; Service owners; Amazon Security teams; Senior leadership
Communication Scope
Communicate findings clearly; Communicate to technical audiences; Communicate to non-technical audiences
Process & Methodology
Engagement scoping
Full Job Description
Application deadline: Jun 7, 2026 Amazon’s STORM Red Team (SDO Threat Operations, Research & Monitoring) is looking for a Security Engineer to join our team of offensive security operators. We hack Amazon’s services, infrastructure, AI/ML systems, processes, and controls, then work with defensive and service teams to fix what we find and sharpen detection, prevention, and response capabilities across the company. STORM Red Team is a 10-person team that operates with significant autonomy. We choose our own targets, scope our own engagements, and operate across Amazon (retail, devices, entertainment, healthcare, subsidiaries, and more), partnering with the AWS Red Team when our paths overlap. Our scope is expansive and always challenging, with new business areas and attack surfaces constantly emerging across Amazon. We run multi-week adversary emulation campaigns, purple team exercises, shortest-path assessments, and targeted research efforts. The work ranges from emulating nation-state actors against critical infrastructure to testing whether a financially motivated threat group’s public playbook would work against us. We report directly into SDO security leadership and our work regularly reaches VP and SVP audiences. This is a fully remote position by design. The team is distributed and operates remotely as a core part of how we work. We’re looking for someone who can independently execute Red Team engagements, build attack paths in complex environments, and communicate findings clearly to both technical and non-technical audiences. You’ll be working alongside experienced operators who will push you to grow. Key job responsibilities • Conducting red team engagements throughout Amazon independently, or as part of a team, targeting traditional infrastructure, cloud services, and AI/ML systems. • Creating detailed engagement plans, performing operations, and emulating adversary tactics, techniques, and procedures (TTPs). • Thoroughly documenting timelines, attack paths
Applying for this Security Engineer II, Stores Red Team role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
ANONYMOUS · UNFILTERED
What do employees actually say about Amazon.com Services LLC?
Real rants from real employees. Read before you apply.