Role Overview
At AMD, we believe technology has the power to solve the world’s most important challenges. The Security Vulnerability Testing/Assessment Engineer will drive the success of power IP and features through leadership, coordination, and resolution of technical dependencies. This high-visibility role spans pre-silicon architecture to post-silicon implementation and product delivery.
Responsibilities
- Conduct black-box and grey-box security assessments across web applications, REST APIs, SPAs, and thick-client/desktop applications.
- Test modern web attack surfaces including authentication, session management, access control, and LLM/AI-assisted features.
- Evaluate thick-client applications for insecure IPC, local privilege escalation, and DLL hijacking.
- Perform static and dynamic analysis of Windows drivers, firmware interfaces, and IOCTL attack surfaces.
- Develop proof-of-concept (PoC) exploits ranging from API abuse scripts to kernel-level triggers.
- Build custom tooling and automation scripts using Python, PowerShell, or C/C++.
- Contribute to internal threat models and security architecture reviews.
Requirements
- 3–10 years of experience in application or product security with substantial hands-on assessment work.
- Strong foundation in web application security and the OWASP Top 10.
- End-to-end experience assessing REST APIs and web management interfaces.
- Solid scripting and automation skills in Python, PowerShell, or C/C++.
- Familiarity with Windows internals, including the driver model and kernel/user boundaries.
- Experience developing and reviewing threat models.
- Bachelor’s or master's degree in computer or electrical engineering or equivalent.
Skills
- Python
- C/C++
- REST APIs
- Windows Internals
- OWASP