Security Engineer II, StoreSec Application Security
Job Description
Security Engineer II on the HealthSec AI team at Amazon, focused on securing GenAI applications and delivering AI-powered security tooling across Amazon Health Services, including AI-SDLC hardening and HIPAA-compliant practices. Location: Seattle, WA (onsite). Salary: USD 159,300 - 202,400 per year.
Responsibilities
- Define and drive implementation of proactive security controls for AHS AI applications including GenAI chatbots, agentic systems, and LLM-powered tools
- Develop and implement security controls for the AI-SDLC, ensuring AHS builders build secure AI applications by default
- Assess and drive mitigation of AI-specific security risks including prompt injection, model abuse, data exfiltration, and unauthorized tool invocation at scale
- Build and/or drive adoption of AI-powered security tooling (e.g., automated threat modeling, code scanning, security test generation) to scale security across AHS
- Drive adoption of AI security guardrails, testing frameworks, and monitoring across AHS GenAI applications
- Collaborate with AHS builder teams to integrate security guidance into AI development workflows, reducing late-stage security findings
- Develop and maintain security documentation including AI threat models, risk assessments, and secure AI development guidelines
- Support security incident investigations related to AI systems, including prompt injection attacks and model misuse
Requirements
- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
- Bachelor's degree in a STEM field (Science, Technology, Engineering, Mathematics), or experience in IT Security
- Experience with AI/ML technologies
- Experience applying threat modeling or other risk identification techniques or equivalent
- Knowledge of common AI security risks (prompt injection, data poisoning, model extraction, insecure tool use)
Technologies
- Python
- Ruby
- Go
- Swift
- Java
- .NET
- C++
- AWS
Benefits
- Health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage)
- 401(k) matching
- Paid time off
- Parental leave
- Sign-on payments
- Restricted stock units (RSUs)
About the Team
The HealthSec AI team secures Amazon's healthcare AI applications and builds AI-powered security tooling to scale protection across AHS. We operate in two domains: Security for AI, which focuses on securing GenAI applications and the AI-SDLC, and AI for Security, which builds AI tools that automate security guidance, testing, and workflows.
Diverse Experiences
Amazon Security values diverse experiences. If you do not meet all listed qualifications, we encourage you to apply. If your career is just starting, has not followed a traditional path, or includes alternative experiences, your background may still be a fit.
Why Amazon Security?
At Amazon, security is central to maintaining customer trust and delivering delightful experiences. The organization upholds a high security bar across all products and services, offering opportunities to accelerate careers with experience across cloud, devices, retail, entertainment, healthcare, operations, and more.
Inclusive Team Culture
In Amazon Security, learning and curiosity are valued. Ongoing DEI events and learning experiences encourage growth and celebration of diverse ideas, perspectives, and voices.
Training & Career Growth
We continuously raise the performance bar and provide knowledge-sharing, training, and resources to help professionals develop into well-rounded experts.
Work/Life Balance
We prioritize work-life harmony with flexible work hours and arrangements, supporting employees at home and at work to achieve success.