Security Vulnerability Testing/Assessment Engineer
AMD · Bangalore, India
Job description
ADVANCE YOUR CAREER. ADVANCE THE WORLD. At AMD, we believe technology has the power to solve the world’s most important challenges. From advancing healthcare and scientific discovery to powering AI and the technologies people rely on every day, innovation at AMD is shaping the future. Whether you’re designing next-gen processors, enabling AI breakthroughs, or bringing leading edge products to market, every role at AMD contributes to something bigger — technology that moves the world forward. Join us and, together, we’ll advance your career. SDE/MTS SOFTWARE SYSTEM DESIGN ENGINEER THE ROLE: The right engineer will drive the success of power IP (intellectual property) and features in AMD (Advanced Micro Devices) products through leadership & coordination, resolution of technical dependencies, and achievement of schedule commits. This is a high-visibility and widely multi-functional role, spanning pre-silicon architecture to post-silicon implementation & product delivery. THE PERSON: Your curiosity will drive your learning and innovation to improve how we as a group and an organisation can get better every day. Your peers will provide you a results-orientated and encouraging environment for your career growth, fuelling your opportunity to be a part of Delighting Our Customers. Key Responsibilities Conduct black-box and grey-box security assessments across web applications, REST APIs, single-page applications (SPAs), browser-based management consoles, and thick-client/desktop applications, including Windows-based management utilities, agents, and configuration tools. Test modern web attack surfaces, including authentication and session management, access control (IDOR/BOLA), CORS, SSRF, injection vulnerabilities, and LLM/AI-assisted features (e.g., prompt injection, sensitive data disclosure). Evaluate thick-client applications for insecure IPC, local privilege escalation, DLL hijacking, insecure storage of credentials and configuration data, unsafe deserialisation, and client-server trust boundary weaknesses. Perform static and dynamic analysis of Windows drivers (KMDF/WDM), firmware interfaces, and IOCTL attack surfaces. Identify and document vulnerabilities such as broken access control, injection flaws, sensitive information disclosure, privilege escalation, memory corruption, arbitrary kernel write, and insecure IOCTLs. Develop proof-of-concept (PoC) exploits — ranging from HTTP request chains and API abuse scripts to thick-client exploitation chains and kernel-level triggers — to validate findings and demonstrate their severity. Build custom tooling and automation scripts (Python, PowerShell, C/C++) to accelerate reconnaissance, fuzzing, IOCTL enumeration, and repeatable exploit validation across engagements. Contribute to internal threat models and security architecture reviews for new product features. Stay current on emerging CVEs, web/API exploitation techniques (OWASP Top 10, OWASP API Top 10, OWASP LLM Top 10), publicly disclosed driver exploits, and other attack trends relevant to AMD products. Preferred Experience 3–10 years of experience in application or product security, with substantial hands-on assessment work. Strong foundation in web application security, including the OWASP Top 10, API security testing, authentication/authorisation bypass, injection, insecure deserialisation, and misconfigurations (CORS, security headers, exposed documentation or endpoints). End-to-end experience assessing REST APIs, web management interfaces, and thick-client/desktop applications—from reconnaissance and manual testing through reporting. Solid scripting and automation skills (Python, PowerShell, or C/C++) for building custom test harnesses, PoC exploits, and repeatable assessment tooling, going beyond reliance on off-the-shelf tools like Burp Suite or Nmap. Familiarity with Windows internals, including the driver model, kernel/user boundary, privilege levels, and IOCTL handling. Experience developing and reviewing threat models. Working knowledge of digital certificates, symmetric and asymmetric encryption, authentication, and authorisation concepts. Experience with security-related hardware such as ARM TrustZone and RISC-V WorldGuard is a plus. ACADEMIC CREDENTIALS: Bachelor’s or master's degree in computer or electrical engineering or equivalent #LI-RR1 #LI-Hybrid Benefits offered are described: AMD benefits at a glance . AMD does not accept unsolicited resumes from headhunters, recruitment agencies, or fee-based recruitment services. AMD and its subsidiaries are equal opportunity, inclusive employers and will consider all applicants without regard to age, ancestry, color, marital status, medical condition, mental or physical disability, national origin, race, religion, political and/or third-party affiliation, sex, pregnancy, sexual orientation, gender identity, military or veteran status, or any other characteristic protected by law. We encourage applications from all qualified candidates and will accommodate applicants’ needs under the respective laws throughout all stages of the recruitment and selection process. AMD may use Artificial Intelligence to help screen, assess or select applicants for this position. AMD’s “Responsible AI Policy” is available here. This posting is for an existing vacancy.
Verified and listed by ActiveJobs. Applications are made directly on AMD's own career page — we never sit in the middle.