Level

Amazon

Software Security Engineer, Annapurna Labs

AI in this role

Secure AWS custom silicon and firmware at the lowest levels of the stack through threat modeling and fuzzing.

pythoncafllibfuzzersyzkaller
security-engineeringfirmwarevulnerability-researchthreat-modelingcryptography
The Annapurna Labs Security Team secures the firmware at the foundation of AWS custom silicon. We work on Graviton processors and the Nitro System — hardware that runs a substantial share of the world's cloud workloads — in close collaboration with the silicon architects and firmware developers who design it. Our engineers operate at the lowest levels of the stack: secure boot chains, hardware root of trust, attestation, cryptographic protocol design, and the boundaries between trust domains within the system.



Key job responsibilities
As a Security Engineer, you will threat model new silicon and firmware architectures, conduct low-level penetration testing against privileged and externally reachable interfaces, review designs and code across multiple firmware components, and build the fuzzing and analysis tooling that makes this work repeatable at silicon scale. You will also help raise the security bar across the wider organization through direct engagement with firmware and hardware teams. We are looking for engineers fluent in C and ARM assembly, with real depth in secure boot, applied cryptography, or embedded exploitation, and the technical credibility to hold a position in a room full of people who designed the system you are testing.

Basic qualifications

- 4+ years of low-level systems security research and vulnerability testing experience
- Experience developing security tools (fuzzers, scanners, analysis frameworks)
- Security architecture design and threat modeling experience
- Proficiency in C and experience with Python
- Deep knowledge of security aspects of ARM/x86 processor architectures
- Strong understanding of hardware security (secure boot, cryptographic implementations, side-channel attacks)
- Knowledge of security protocols and cryptographic primitives
- Experience in AI usage for security research
- Technical English proficiency

Preferred qualifications

- Background in firmware reverse engineering and vulnerability research
- Experience with fuzzing frameworks (AFL++, libFuzzer, Syzkaller)
- Knowledge of virtualization security or hypervisor technologies
- Familiarity with AWS services
- Technical leadership, mentoring, and cross-functional collaboration
- Security publications (research, CVEs)
- CTF, bug bounty, or competitive security research background

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

How we rate this

Software Security Engineer, Annapurna Labs at Amazon rates 20 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

Security EngineeringFirmwareVulnerability ResearchThreat ModelingCryptographyPythonCAfl

Questions you could be asked

  1. Tell me about a project where security engineering was part of your work. What did you do?
  2. Tell me about a project where firmware was part of your work. What did you do?
  3. Tell me about a project where vulnerability research was part of your work. What did you do?
  4. Tell me about a project where threat modeling was part of your work. What did you do?
  5. Tell me about a project where cryptography was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: Security Engineering, Firmware, Vulnerability Research, Threat Modeling, and Cryptography. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want an expert to read your CV for this job?

Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.

Get a free CV review

Get new AI jobs by email

One email a week with the new AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Amazon

Related searches

Same AI level