Amazon

Senior Security Engineer, AWS Security Verification & Validation Team

Amazon
Apply
1 day ago
Remote, United KingdomSenior

Responsibilities

  • Own security strategy and testing engagements across interconnected AWS services, microservice architectures, launch iterations, and partner organizations.
  • Perform penetration testing and AI-augmented source code reviews, focusing on trust boundaries, abuse cases, attack paths, and realistic impact.
  • Investigate risk hypotheses to documented conclusions using proof-of-concept code, sufficient evidence, and analysis of shared mechanisms or detections.
  • Trace compound attack paths across chained components, organizational boundaries, and ownership boundaries.
  • Document testing scope, rationale, findings, ruled-out risks, limitations, and residual risk for technical and non-technical audiences.
  • Lead communications with developers, AppSec engineers, stakeholders, Senior Managers, and Principal Engineers; validate fixes and drive escalations to closure.
  • Build reusable frameworks, runbooks, rubrics, fuzzers, integration security tests, detection rules, and security-testing methodologies.
  • Tune AI security-testing harnesses, measure false positives and missed attack patterns, and generalize effective mechanisms for team adoption.
  • Set peer-review standards, review test plans and reports, identify coverage gaps, and ensure solutions remain extensible and low-cost to adopt.
  • Lead multi-engineer engagements, mentor engineers across teams, and participate in promotion assessments.

Requirements

  • Experience developing software in one or more programming languages such as Java or Python.
  • Knowledge of security design review, threat modeling, risk analysis, software testing, authentication, authorization, single sign-on, and cryptography.
  • Experience assessing risk, enabling security decisions, communicating impacts with operations and business teams, and working with enterprise software.
  • Bachelor's degree or higher in Computer Science, Computer Engineering, Cybersecurity, or a related discipline.
  • At least 5 years of professional experience in penetration testing, source code auditing, bug hunting, or competitive CTF.
  • Demonstrated ability to find non-trivial vulnerabilities through offensive testing of web applications and services and source code review.
  • Mastery of at least two complex security domains, such as networking, workload and tenant isolation, web application and API security, IAM, or cryptography.
  • Experience building and steering AI agents for security work and reasoning about attacks against agentic systems.
  • Preferred experience includes agentic AI harnesses, agent graphs or swarms, A2A protocols, LLM and agentic application security, Red Team engagements, web service assessment, serverless and virtualization security, microservices, APIs, Linux or Unix architectures, distributed systems, CI/CD, and division-level security controls.

Benefits

  • Knowledge-sharing, mentorship, training, and career-advancement resources.
  • Flexible work-life harmony culture.
  • Inclusive culture with DEI events and learning experiences.

Categories

Amazon

About Amazon

10,000+ employees

Amazon builds and operates a global e-commerce marketplace, logistics network, and consumer devices, and provides cloud computing via AWS for businesses and developers. The company earns revenue from online retail, third‑party seller services, subscriptions like Prime, advertising, and AWS usage. Founded in 1994 and headquartered in Seattle, it is publicly traded on NASDAQ (AMZN) and serves customers in dozens of countries.

Contact me