EngineerJobs.io
← Back to all jobs

Job Description

This senior security engineering role concentrates on AI application security within Amazon Leo Security, guiding AI security reviews, policy decisions, and guardrails across AI-enabled systems.

Responsibilities

  • Act as the organization’s AI security subject matter expert, overseeing AI tool approval reviews, conducting security assessments for AI-integrated systems, and shaping policy decisions on AI adoption.
  • Represent security in cross-Amazon AI security working groups and align policy direction across teams.
  • Mentor AI leads across teams by providing consultations and reviews.
  • Define and implement proactive security controls for AI applications, including GenAI-powered tools, agentic systems, and LLM-integrated services; guide teams toward secure-by-default solutions and propose new ones when gaps exist.
  • Develop security controls for the AI software development lifecycle to ensure builders create secure AI applications by default.
  • Assess and mitigate AI-specific risks such as prompt injection, model abuse, data exfiltration, unauthorized tool invocation, and autonomy boundary violations at scale.
  • Establish environment-specific security bars, threat models, and defense priorities for AI systems.
  • Construct security frameworks, rubrics, and runbooks for AI domains to enable repeatable application of your work.
  • Collaborate with builder teams to evaluate technical debt and risk in AI systems.
  • Provide strategic direction to address vulnerabilities and strengthen product security.
  • Lead efforts to reduce long-term AI security risk and drive adoption of guardrails, testing frameworks, and monitoring across the organization.
  • Work with business leaders to define AI security priorities and act as a trusted advisor to make security approachable.
  • Help leaders measure their organization’s security execution and ensure builders use appropriate security tooling and testing for AI, including linting, static analysis, and AI-specific testing.
  • Foster a security-conscious culture among builder teams and mentor engineers aspiring to security roles through one-on-one sessions and office hours.
  • Assist Red Teams in identifying AI security testing priorities and scope penetration tests for AI systems, contributing to incident investigations.
  • Investigate emerging AI security issues, determine root causes, and devise preventive mechanisms; advocate for new testing tools and detection mechanisms.
  • Pursue advanced, bleeding-edge security technologies to enhance capabilities.

Requirements

  • 5+ years of combined experience in areas such as application security frameworks, identity and access controls, incident response, mobile security, cloud security, AI security, threat intelligence, and penetration testing.
  • Proven experience security-reviewing or architecting at least three of the following: AWS hosted inference components (Bedrock, IAM scoping, KMS, region/partition constraints), agentic systems (autonomy boundaries, prompt injection, tool-use mediation), MCP servers (data access patterns, registration/compliance, agentic MCP risk), model hosting infrastructure, or third-party AI tool security reviews (data flow analysis, ingress/egress control, ECI/ITAR scoping).
  • 3+ years of hands-on AI/ML security work, including security reviews of AI-integrated systems and threat modeling for AI tools.
  • Experience leading formal security reviews (ASR or equivalent) of complex AI systems through to certification, with comfort in risk-based prioritization.
  • Knowledge of common AI security risks such as prompt injection, data poisoning, model extraction, insecure tool use, and autonomy boundary violations.
  • Proven ability to drive security policy decisions in cross-team or cross-organizational settings, with the ability to achieve consensus among technical and non-technical stakeholders.
  • 5+ years of experience communicating complex technical concepts to non-technical audiences, with strong written and verbal communication and collaboration skills.

Technologies

  • Bedrock
  • IAM
  • KMS

Benefits

  • Sign-on payments
  • Restricted stock units (RSUs)
  • Health insurance (medical, dental, vision, prescription)
  • Basic Life and AD&D insurance
  • Supplemental life plans
  • Employee Assistance Program (EAP)
  • Mental health support
  • Medical Advice Line
  • Flexible Spending Accounts
  • Adoption and surrogacy reimbursement
  • 401(k) matching
  • Paid time off and parental leave

Location

Redmond, Washington, onsite

Compensation

USD 178,400 to 226,700 per year

Export Control Requirement

Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

A Day in the Life

  • Accountable for prioritizing time to maximize value in a dynamic environment, balancing proactive and reactive work.
  • Teams seek guidance on a broad range of security challenges and decisions.
  • When integrating a third-party AI tool, assess security, privacy, compliance, and export control implications.
  • When deploying an agentic system that invokes MCP tools, define autonomy boundaries and guard against prompt injection.
  • Scope IAM permissions for Bedrock inference endpoints with cross-partition data access.
  • Perform root-cause analysis after AI related incidents to determine which controls failed.
  • Explore secure development of AI-powered security tooling, such as automated threat modeling and code scanning.

About the Team

Diverse experiences are valued in Amazon Security. Even if you do not meet every qualification, we encourage you to apply. If your career is just starting, or has taken nontraditional paths, your background can still be a fit.

Why Amazon Security? Security is central to protecting customer trust and delivering excellent experiences. The organization sets a high standard for security across Amazon's products and services, offering opportunities to grow across cloud, devices, retail, entertainment, healthcare, operations, and physical stores.

Inclusive team culture and ongoing DEI events foster curiosity and a willingness to learn, embracing diverse ideas and perspectives.

Training and career growth are emphasized, with resources to help professionals expand their expertise in a wide range of domains.

Work life balance is valued, with flexible hours and arrangements to support personal and family needs.

Preferred Qualifications

  • Knowledge of cloud computing services and deployment architecture.
  • Experience developing security controls and tooling across the AI-SDLC, including secure design reviews, threat modeling, code scanning, and security testing of LLM-based applications; programming or scripting skills to build or drive adoption of automated security tools at scale.

Similar Jobs