Security Engineer II
Job Description
Security Engineer II on Amazon HealthSec's AI team focused on securing GenAI applications and enabling secure AI adoption across Amazon Health Services.
Responsibilities
- Define and lead the rollout of proactive security controls for AHS AI apps, including GenAI chatbots, agentic systems, and LLM powered tools
- Establish AI secure development lifecycle controls to ensure builders across AHS deliver secure AI applications by default
- Evaluate AI specific risks such as prompt injection, model misuse, data exfiltration, and unauthorized tool invocation at scale, and drive mitigations
- Create and promote AI enabled security tooling like automated threat modeling, code scanning, and security test generation to scale protection across AHS
- Promote AI security guardrails, testing frameworks, and monitoring across GenAI applications within AHS
- Partner with AHS development teams to embed security guidance into AI workflows, reducing late stage findings
- Produce and maintain security documentation including AI threat models, risk assessments, and guidelines for secure AI development
- Support investigations of AI related incidents, including prompt injection and model misuse analyses
Requirements
- At least 3 years of programming experience in Python, Ruby, Go, Swift, Java, .NET, C++ or other object oriented languages
- Bachelor's degree in a STEM field or equivalent experience in IT security
- Experience with AI/ML technologies
- Experience applying threat modeling or related risk identification techniques
- Knowledge of common AI security risks such as prompt injection, data poisoning, model extraction, and insecure tool usage
Technologies
- Python
- Ruby
- Go
- Swift
- Java
- .NET
- C++
- AWS
Benefits
- Comprehensive health coverage including medical, dental, vision, prescription, Basic Life and AD&D with optional supplemental life plans, EAP, mental health support, medical advice line, flexible spending accounts, and adoption or surrogacy reimbursement
- 401(k) matching
- Paid time off
- Parental leave
- Sign-on payments
- Restricted stock units (RSUs)
About the Team
The HealthSec AI team secures Amazon's healthcare AI applications and builds AI powered security tooling to scale protection across AHS. We operate in two domains: Security for AI, which secures GenAI applications and the AI-SDLC, and AI for Security, which builds AI tools that automate security guidance, testing, and workflows.
Diverse Experiences
Amazon Security welcomes diverse backgrounds. If you do not meet every listed qualification, we encourage you to apply. Whether you are early in your career, nontraditional, or bring alternative experiences, your application is welcome.
Why Amazon Security
Security is central to earning customer trust and delivering exceptional experiences. The team maintains a high standard for security across all Amazon products and services and offers opportunities to gain exposure across cloud, devices, retail, entertainment, healthcare, operations, and more.
Inclusive Team Culture
We value curiosity and ongoing learning. DEI events and inclusive experiences help us welcome a range of ideas and perspectives as we tackle security challenges.
Training & Career Growth
We aim to raise the performance bar continuously, with abundant knowledge sharing, training, and career development resources to help you grow as a well-rounded security professional.
Work/Life Balance
Flexible work hours and arrangements are part of our culture to support harmony between professional and personal life.