I applied online. The process took 4 weeks. I interviewed at Amazon in May 2022
Interview
I applied for a particular Security Engineering role (Blue Team focused) and interviewed for that role. After the interview, the recruiter said that they thought I would be a better fit for a different role and set up a 1hr chat for that role.
The job ID the recruiter sent me DID NOT exist on Amazon's Jobs page. I emailed her back and asked for specifics of the role - got no response. Emailed the recruiter again - no response. Finally get a response - that includes the same job ID and asks basic HR/hiring questions, but no info on the role. So I hop on the call and am blindsided by the interviewer talking about how the role is heavily focused on Offensive Security. The interviewer said "I know you don't have any offensive testing experience and it is not your wheelhouse" (My background is primarily threat modeling/Architecture/vuln assessment). He said they look for more security general people. I thought that would be ok, since I would be able to express a wide range of my knowledge and talk basic concepts in offensive security.
The Interviewer then ONLY asked specific questions about complex pen testing topics, and nothing from any other realm of security. Of course I didn't do well! I feel like Amazon needs to step up on either communication or preparing their interviewers for non-biased interviews in the future (interviewer worked in offensive security). Also "Hire the Best" - I think they need to audit their recruiter's inboxes because they are the worst I've ever had.
Interview questions [1]
Question 1
Walk me through the javascript of the communication channel a stored XXS attack uses to relay info back to the attacker.
First meeting with recruiter collected all information. then meeting scheduled with Hiring Manager: Asked questions from the job description but it was vague in which domain they were looking for.
Interview questions [1]
Question 1
Experience in Threat Detection and Application Security
It's been described that I will have secure code review task and threat modelling related tasks on the technical interview, followed by Amazon's leadership principles and the star method regarding past experiences.
Online Assessment — likely a technical assessment testing security/coding fundamentals
Phone Screening — an initial conversation, probably with a recruiter or hiring manager
Loop — the full set of one-on-one interviews combining behavioral (Leadership Principles/STAR method) and technical questions