> Markdown version of [/jobs/ext/2629595-network-security-penetration-tester-appstar-network-security](https://www.wearedevelopers.com/jobs/ext/2629595-network-security-penetration-tester-appstar-network-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Network Security Penetration Tester, AppSTAR Network Security - **Company:** Amazon.com, Inc. - **Location:** Los Angeles County, CA, United States (Remote available) - **Experience:** Experienced - **Salary:** $159,300.0 - $202,400.0 - **Contract:** Internship / Graduate position - **Skills:** Java (Programming Language), Amazon Web Services, Software System Penetration Testing, User Authentication, C++ (Programming Language), Cloud Computing, Code Review, Cyber Security, Computer Programming, Domain Name System (DNS), HTTP Secure, Identity and Access Management, Python (Programming Language), Network Security, Network Architecture, Network Protocols, Secure Coding, Software Engineering, TCP/IP, Virtual Local Area Networks, Scripting, Information Technology, Process Control Systems, Operational Systems, Programming Languages - **Published:** August 10, 2026 - **Apply:** https://www.amazon.jobs/en/jobs/10498016/network-security-penetration-tester-appstar-network-security ## About the Role 3+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience - 3+ years of scripting, programming, and security code review in a common programming language (non-internship) experience - Knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits or equivalent - Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP - Experience applying threat modeling or other risk identification techniques or equivalent - 3+ years of experience in network penetration testing, infrastructure security assessment, or related offensive security role, Experience with AWS products and services - Experience with programming languages such as Python, Java, C++ - Bachelor's degree in computer science or equivalent - Relevant industry certifications such as OSCP, GPEN, OSEP - Experience testing industrial control systems (ICS), operational technology (OT), or IoT network environments - Experience in CTF competitions, CVE research, and/or Bug Bounty recognition ## Description * Conducting high-quality network penetration tests as part of a team against Amazon fulfillment networks, and cloud (AWS)-based and non-cloud-based network infrastructure supporting Amazon Stores' services * Devising engagement test plans and thoroughly documenting findings, gaps, and remediation recommendations in written reports for both technical and leadership audiences * Performing remote and on-site network assessments at Amazon facilities (up to approximately 15% travel), including physical network reconnaissance, VLAN enumeration, and lateral movement * Contributing to team tooling, automation, and methodology improvements that increase the efficiency and coverage of network security assessments * Communicating and collaborating with partner teams, service owners, and network engineering to influence and prioritize the resolution of discovered security findings * Mentoring junior team members and contributing to knowledge-sharing through peer review, training, and documentation of tradecraft A day in the life You'll spend the majority of your day deep in network penetration tests - scoping engagements, enumerating targets, exploiting misconfigurations, and chasing lateral movement paths across Amazon's fulfillment center networks and cloud infrastructure. When you're not actively testing, you're building automation and tooling that helps the team scale its coverage and efficiency. You'll also partner with network engineers, Business Security Teams, and service owners to communicate what you found and ensure issues get fixed. No two engagements look the same - one week you may be remotely pivoting through a FC network, the next you're mapping attack paths in a cloud environment. About the team AppSTAR Network Security (NetSec) is a dedicated team formed at the start of 2026 to strengthen Amazon's network security posture through proactive and responsive penetration testing. We partner with security organizations, network teams, and service teams across Amazon Stores to identify vulnerabilities in network infrastructure at scale. Our culture is collaborative and autonomous - we hack hard, help our customers, and favor systemic solutions over point fixes. We're growing the team and looking for engineers who thrive on idea-driven problem solving and want to shape how network security scales across Amazon. Diverse Experiences Amazon Security values diverse experiences. Even if you do not meet all of the qualifications and skills listed in the job description, we encourage candidates to apply. If your career is just starting, hasn't followed a traditional path, or includes alternative experiences, don't let it stop you from applying. Why Amazon Security? At Amazon, security is central to maintaining customer trust and delivering delightful customer experiences. Our organization is responsible for creating and maintaining a high bar for security across all of Amazon's products and services. We offer talented security professionals the chance to accelerate their careers with opportunities to build experience in a wide variety of areas including cloud, devices, retail, entertainment, healthcare, operations, and physical stores. Inclusive Team Culture In Amazon Security, it's in our nature to learn and be curious. Ongoing DEI events and learning experiences inspire us to continue learning and to embrace our uniqueness. Addressing the toughest security challenges requires that we seek out and celebrate a diversity of ideas, perspectives, and voices. Training & Career Growth We're continuously raising our performance bar as we strive to become Earth's Best Employer. That's why you'll find endless knowledge-sharing, training, and other career-advancing resources here to help you develop into a better-rounded professional. Work/Life Balance We value work-life harmony. Achieving success at work should never come at the expense of sacrifices at home, which is why flexible work hours and arrangements are part of our culture. When we feel supported in the workplace and at home, there's nothing we can't achieve. ## Related Videos - [Security in modern Web Applications - OWASP to the rescue!](https://www.wearedevelopers.com/videos/724-security-in-modern-web-applications-owasp-to-the-rescue) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Capture the Flag 101](https://www.wearedevelopers.com/videos/416-capture-the-flag-101) - [1, 2, 3... Fastify!](https://www.wearedevelopers.com/videos/325-1-2-3-fastify) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)