Mobile Security Engineer, Application Security
AmazonMobile Security Engineer, Application Security
AmazonLocation
United States
Type
Full-time
Posted
8/21/2026
Compensation
$159,300 - $202,400 per year
Job description
Amazon's Stores Application Security Team is looking for a Mobile Security Engineer to enhance security for its customers. This role involves identifying security issues in Amazon's mobile applications and services, providing technical leadership, and collaborating with various teams across the organization. The position offers opportunities for technological challenges and leadership while fostering a fun and innovative work environment. A strong focus on customer security and the ability to navigate complex situations is essential.
Requirements
- Bachelor's degree in computer science or equivalent
- 3+ years of experience in a penetration testing or similar offensive security role
- 3+ years of experience in client-side application security, including reverse engineering and security assessments
- 3+ years of professional experience with security engineering practices, including web application security, authentication and authorization protocols, cryptography, automation, and other software security disciplines
- 3+ years of experience with dynamic and manual code auditing to identify security issues
- 3+ years of experience with interpreted or compiled languages such as Python, Ruby, C/C++, Java, or .NET
- Experience with threat modeling, design review, or other threat analysis techniques
- Proficiency with binary analysis tools such as Ghidra, IDA Pro, Radare2, Hopper, or Jadx
- Experience with client-side application instrumentation and dynamic testing using tools like Frida, Objection, LLDB, or Burp Suite
- Knowledge of cloud services such as AWS or equivalent
- Experience with design, implementation, support, and evaluation of security-focused tools and services
- Experience with mobile application penetration testing
- Familiarity with threat models for client-side applications on consumer devices and the vulnerability classes specific to their platforms and communication protocols
- Experience mentoring developers on secure coding practices and vulnerability mitigations
- Experience in CTF competitions, CVE research, and/or Bug Bounty recognition
Responsibilities
- Conduct high quality application penetration tests independently or as part of a team
- Create detailed engagement plans and thoroughly document findings, gaps, and remediation recommendations
- Contribute to team tooling, innovation, and improvements
- Communicate and collaborate with partner teams, service owners, Information Security, and senior leadership to influence, prioritize, and drive the resolution of discovered security findings
Benefits
- Employees at Amazon are often offered comprehensive health benefits—including multiple medical plan options (no pre-existing condition exclusions, 100% covered in-network preventive care), dental and vision plans, a 24/7 medical advice line from day one, expert second-opinion services, and broad mental-health support with several free counseling sessions (including pediatric). Financial wellness typically includes a 401(k) with company match (up to 2%), Restricted Stock Units (equity), FSAs, an emergency savings program, product and partner discounts, and even college-savings and home-purchase programs. Overall, the package is designed to support employees and their families’ health, finances, and day-to-day life.
H-1B filing history
Public USCIS petition and DOL LCA counts · latest USCIS FY2026, LCA FY2026
Filing entity: Amazon Com Services Llc
As of Aug 23, 2026
Initial approvals
3,290
FY2026
Approval rate
99.1%
FY2026
LCA certified
32,937
FY2026
Entry-level share
10.6%
FY2026
Initial approvals YoY
+9%
Trend
LCA certified YoY
-44%
Trend
Initial approvals by fiscal year
Approval rate by fiscal year
Continuing vs initial approvals
LCA certified positions by quarter
LCA certified positions by fiscal year
Based on public USCIS and DOL filings; not a sponsorship guarantee.
Is this posting expired or inaccurate?
